IP Library Granted Patent US 10,243,811
Granted Patent B1
US 10,243,811 · App. 15/410,755 · Granted Mar 26, 2019

Lattice-based inference of network services and their dependencies from header and flow data

Inventors: Karim El Defrawy (Santa Monica, CA); Michael J. O'Brien (Culver City, CA); James Benvenuto (Beverly Hills, CA)
Assignee: HRL Laboratories, LLC
H04L41/5058H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,243,811
App. No.
15/410,755
Granted
Mar 26, 2019
Kind
B1
Abstract

Described is system for automatically detecting network services and their dependencies. The system generates a first context table having rows of packet headers and columns of header field values. A first concept lattice is generated from the first context table, and network services and corresponding packet headers are identified. A second context table is generated using the networks services data, and a second concept lattice is generated from the second context table. Network service dependencies are identified using the second concept lattice. The context tables are used to monitor the plurality of network service dependencies.

Claims (29)

1. A system for automatically detecting network services and their dependencies, the system comprising:

one or more processors having associated memory with executable instructions encoded thereon such that when executed, the one or more processors perform operations of:

generating a first context table having a plurality of rows and columns representing objects and attributes, respectively, wherein the objects are packet headers and the attributes are a set of values of header fields;

generating a first concept lattice having a plurality of nodes using the first context table, wherein the first concept lattice is used to identify relationships between the packet headers and the set of values of header fields;

identifying a set of network services and a set of corresponding packet headers using the first concept lattice, wherein the set of network services comprises a tuple of network services, and wherein the set of network services is identified by classifying the plurality of nodes in the first concept lattice;

generating a second context table using the set of corresponding packet headers and a set of attributes related to the set of corresponding packet headers;

generating a second concept lattice having a plurality of nodes using the second context table, wherein the second concept lattice indicates relationships between network services and their temporal network service dependencies;

identifying a plurality of network service dependencies using the plurality of nodes in the second concept lattice; and

using at least one of the first context table and the second context table to monitor the plurality of network service dependencies.

2. The system as set forth in claim 1 , wherein the set of attributes related to the set of corresponding packet headers comprises a temporal relationship.

3. A computer-implemented method for automatically detecting network services and their dependencies, the computer-implemented method using one or more processors to perform operations of:

generating, with the one or more processors, a first context table having a plurality of rows and columns representing objects and attributes, respectively, wherein the objects are packet headers and the attributes are a set of values of header fields;

generating, with the one or more processors, a first concept lattice having a plurality of nodes using the first context table, wherein the first concept lattice is used to identify relationships between the packet headers and the set of values of header fields;

identifying, with the one or more processors, a set of network services and a set of corresponding packet headers using the first concept lattice, wherein the set of network services comprises a tuple of network services, and wherein the set of network services is identified by classifying the plurality of nodes in the first concept lattice;

generating, with the one or more processors, a second context table using the set of corresponding packet headers and a set of attributes related to the set of corresponding packet headers;

generating, with the one or more processors, a second concept lattice having a plurality of nodes using the second context table, wherein the second concept lattice indicates relationships between network services and their temporal network service dependencies;

identifying, with the one or more processors, a plurality of network service dependencies using the plurality of nodes in the second concept lattice; and

using at least one of the first context table and the second context table to monitor the plurality of network service dependencies.

4. The method as set forth in claim 3 , wherein the set of attributes related to the set of corresponding packet headers comprises a temporal relationship.

5. A computer program product for automatically detecting network services and their dependencies, the computer program product comprising:

computer-readable instructions stored on a non-transitory computer-readable medium that are executable by a computer having one or more processors for causing the one or more processors to perform operations of:

generating a first context table having a plurality of rows and columns representing objects and attributes, respectively, wherein the objects are packet headers and the attributes are a set of values of header fields;

generating a first concept lattice having a plurality of nodes using the first context table, wherein the first concept lattice is used to identify relationships between the packet headers and the set of values of header fields;

identifying a set of network services and a set of corresponding packet headers using the first concept lattice, wherein the second concept lattice indicates relationships between network services and their temporal network service dependencies;

generating a second context table using the set of corresponding packet headers and a set of attributes related to the set of corresponding packet headers;

generating a second concept lattice having a plurality of nodes using the second context table, wherein the second concept lattice indicates relationships between network services and their temporal network service dependencies;

identifying a plurality of network service dependencies using the plurality of nodes in the second concept lattice; and

using at least one of the first context table and the second context table to monitor the plurality of network service dependencies.

6. The computer program product as set forth in claim 5 , wherein the set of attributes related to the set of corresponding packet headers comprises a temporal relationship.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2017
From: EL DEFRAWY, KARIM; O'BRIEN, MICHAEL J.; BENVENUTO, JAMES
To: HRL LABORATORIES, LLC
Reel/Frame 041784/0587 →
Continuity (1)
Provisional Application 62286306 · Jan 22, 2016
Cited By (1)
US 12,664,216