IP Library Patent Application 19266895
Patent Application
App. No. 19/266,895

MULTI-ACCESS EDGE COMPUTING BASED VISBILITY NETWORK

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/266,895
Abstract

Disclosed herein are system, method, and computer program product embodiments for providing traffic visibility in a network. An embodiment operates by a third-party component receiving a copy of a first data packet during a first period of time. The third-party component extracts a first network parameter associated with the first period of time from the copy of the first data packet. The third-party component then predicts a baseline of normalcy for the first network parameter during a second period of time after the first period of time based on data associated with a copy of a second data packet and the first network parameter. Thereafter, the third-party component receives a copy of a third data packet during the second period of time, and extracts a second network parameter from the copy of the third data packet. The third-party component then determines that the second network parameter of the copy of the second data packet is an anomaly based on the baseline of normalcy for the first network parameter.

Claims (62)

1 . A method for providing traffic visibility in a network, comprising:

receiving, by a third-party component from a network component, a copy of a first network packet with a first plurality of identifiers, wherein the third-party component and the network component are located at an edge of the network;

determining, by the third-party component, whether a rule exists for the copy of the first network packet;

in response to a rule existing for the copy of the first network packet, updating the rule based on the first plurality of identifiers;

in response to no rule existing for the copy of the first network packet:

generating, by the third-party component, a new rule based on determining an action to perform with the first plurality of identifiers; and

storing, by the third-party component, the new rule in a local memory;

performing, by the third-party component, a deep packet inspection of the copy of the first network packet to determine characteristics;

deriving, by the third-party component, metadata from the copy of the first network packet based on the characteristics;

exporting, by the third-party component, the metadata to a predetermined analytics tool for further analysis; and

forwarding, by the third-party component, the copy of the first network packet to the predetermined analytics tool.

2 . The method of claim 1 , wherein the first plurality of identifiers comprise a transmitted time, a source, a destination, a protocol, a length, or incorporated information.

3 . The method of claim 1 , wherein the action includes forwarding the copy of the first network packet or data derived from the copy of the first network packet to an external location for further storage or analytics.

4 . The method of claim 3 , further comprising:

determining, by the third-party component, a second action when the first plurality of identifiers is related to a predetermined type.

5 . The method of claim 1 , further comprising:

maintaining, by the third-party component, a rule table comprising the rule associated with a second plurality of identifiers; and

when the second plurality of identifiers matches the first plurality of identifiers, determining, by the third-party component, that the rule exists for the copy of the first network packet.

6 . The method of claim 1 , wherein the characteristics include at least one of a plurality of applications or a plurality of patterns.

7 . The method of claim 1 , further comprising:

modifying, by the third-party component, the copy of the first network packet, by at least one of hiding selected information with a pattern, removing header information, or slicing packet payload before forwarding the copy of the first network packet to the predetermined analytics tool.

8 . A system, comprising:

a memory; and

a processor coupled to the memory and configured to:

receive, from a network component, a copy of a first network packet with a first plurality of identifiers;

determine whether a rule exists for the copy of the first network packet;

in response to a rule existing for the copy of the first network packet, update the rule based on the first plurality of identifiers;

in response to no rule existing for the copy of the first network packet:

generate, a new rule based on determining an action to perform with the first plurality of identifiers; and

store the new rule in a local memory;

perform, a deep packet inspection of the copy of the first network packet to determine characteristics;

derive metadata from the copy of the first network packet based on the characteristics;

export the metadata to a predetermined analytics tool for further analysis; and

forward the copy of the first network packet to the predetermined analytics tool.

9 . The system of claim 8 , wherein the system and the network component are located at an edge of the network.

10 . The system of claim 8 , wherein the first plurality of identifiers comprise a transmitted time, a source, a destination, a protocol, a length, or incorporated information.

11 . The system of claim 8 , wherein the action includes forwarding the copy of the first network packet or data derived from the copy of the first network packet to an external location for further storage or analytics.

12 . The system of claim 11 , wherein the processor is further configured to:

determine a second action when the first plurality of identifiers is related to a predetermined type.

13 . The system of claim 8 , wherein the processor is further configured to:

maintain a rule table comprising the rule associated with a second plurality of identifiers; and

when the second plurality of identifiers matches the first plurality of identifiers, determine that the rule exists for the copy of the first network packet.

14 . The system of claim 8 , wherein the characteristics include at least one of a plurality of applications or a plurality of patterns.

15 . The system of claim 8 , wherein the processor is further configured to:

modify the copy of the first network packet by at least one of hiding selected information with a pattern, removing header information, or slicing packet payload before forwarding the copy of the first network packet to the predetermined analytics tool.

16 . A non-transitory computer-readable medium (CRM) having instructions stored thereon that, when executed by at least one computing device, causes the at least one computing device to perform operations comprising:

receiving, from a network component, a copy of a first network packet with a first plurality of identifiers;

determining whether a rule exists for the copy of the first network packet;

in response to a rule existing for the copy of the first network packet, updating the rule based on the first plurality of identifiers;

in response to no rule existing for the copy of the first network packet:

generating a new rule based on determining an action to perform with the first plurality of identifiers; and

storing the new rule in a local memory;

performing a deep packet inspection of the copy of the first network packet to determine characteristics;

deriving metadata from the copy of the first network packet based on the characteristics;

exporting the metadata to a predetermined analytics tool for further analysis; and

forwarding the copy of the first network packet to the predetermined analytics tool.

17 . The non-transitory CRM of claim 16 , wherein the first plurality of identifiers comprise a transmitted time, a source, a destination, a protocol, a length, or incorporated information.

18 . The non-transitory CRM of claim 16 , wherein the action includes forwarding the copy of the first network packet or data derived from the copy of the first network packet to an external location for further storage or analytics.

19 . The non-transitory CRM of claim 18 , wherein the operations further comprise:

maintaining a rule table comprising the rule associated with a second plurality of identifiers, and

when the second plurality of identifiers matches the first plurality of identifiers, determining that the rule exists for the copy of the first network packet.

20 . The non-transitory CRM of claim 16 , wherein the characteristics include at least one of a plurality of applications or a plurality of patterns.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2025
From: DASGUPTA, SHUBHARANJAN; KULKARNI, PRANESH; ACHARYA, PRASANNA KUMAR; RAMAN, MYTHIL; SINGH, RAM GOPAL
To: EXTREME NETWORKS, INC.
Reel/Frame 071695/0833 →