IP Library Granted Patent US 10,797,973
Granted Patent B2
US 10,797,973 · App. 16/707,756 · Granted Oct 6, 2020

Server-client determination

Inventors: Ali Parandehgheibi (Sunnyvale, CA); Abhishek Ranjan Singh (Pleasanton, CA); Omid Madani (San Carlos, CA); Vimalkumar Jeyakumar (Los Altos, CA); Ellen Christine Scheib (Mountain View, CA); Navindra Yadav (Cupertino, CA); Mohammadreza Alizadeh Attar (Santa Clara, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L43/045G06F3/0482G06F3/04842G06F3/04847G06F9/45558G06F16/122G06F16/137G06F16/162G06F16/17G06F16/173G06F16/174G06F16/1744G06F16/1748G06F16/235G06F16/2322G06F16/2365G06F16/248G06F16/24578G06F16/285G06F16/288G06F16/29G06F16/9535G06F21/53G06F21/552G06F21/566G06N20/00G06N99/00G06T11/206H04J3/0661H04J3/14H04L1/242H04L9/0866H04L9/3239H04L9/3242H04L41/046H04L41/0668H04L41/0803H04L41/0806H04L41/0816H04L41/0893H04L41/12H04L41/16H04L41/22H04L43/02H04L43/04H04L43/062H04L43/08H04L43/0805H04L43/0811H04L43/0829H04L43/0841H04L43/0858H04L43/0864H04L43/0876H04L43/0882H04L43/0888H04L43/10H04L43/106H04L43/12H04L43/16H04L45/306H04L45/38H04L45/46H04L45/507H04L45/66H04L45/74H04L47/11H04L47/20H04L47/2441H04L47/2483H04L47/28H04L47/31H04L47/32H04L61/2007H04L63/0227H04L63/0263H04L63/06H04L63/0876H04L63/145H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/1458H04L63/1466H04L63/16H04L63/20H04L67/10H04L67/1002H04L67/12H04L67/16H04L67/36H04L67/42H04L69/16H04L69/22H04W72/08H04W84/18G06F2009/4557G06F2009/45587G06F2009/45591G06F2009/45595G06F2221/033G06F2221/2101G06F2221/2105G06F2221/2111G06F2221/2115G06F2221/2145H04L67/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,797,973
App. No.
16/707,756
Granted
Oct 6, 2020
Kind
B2
Abstract

Systems, methods, and computer-readable media are provided for determining whether a node in a network is a server or a client. In some examples, a system can collect, from one or more sensors that monitor at least part of data traffic being transmitted via a pair of nodes in a network, information of the data traffic. The system can analyze attributes of the data traffic such as timing, port magnitude, degree of communication, historical data, etc. Based on analysis results and a predetermined rule associated with the attributes, the system can determine which node of the pair of nodes is a client and which node is a server.

Claims (48)

1. A method comprising:

receiving, from a sensor that monitors at least part of data traffic exchanged between a pair of nodes in a network, information of the data traffic, the pair of nodes comprising a first node and a second node;

determining, based on the information, that the first node is a client and that the second node is a server;

creating one or more classifiers of servers and clients in the network from the result of the determining;

generating at least a first communication graph for the network, the first communication graph comprising the first node, the second node, and one or more other nodes; and

based on the one or more classifiers of servers and clients in the network, assigning one or more of the one or more classifiers of servers or clients to the one or more other nodes.

2. The method of claim 1 , wherein the determining is further based on one or more rules associated with timing, port magnitude, degree of communication, or historical data obtained from the information.

3. The method of claim 1 , further comprising:

associating a weight with the sensor, the weight based on one or more of accuracy, margin of error, length of time of observation, or amount of information collected by the sensor, wherein the information of the data traffic reported by the sensor is weighted using the weight.

4. The method of claim 1 , further comprising:

generating at least a second communication graph for the network, the first communication graph and the second communication graph associated with a first time period and a second time period, respectively.

5. The method of claim 4 , further comprising:

determining combined influences between the first communication graph and the second communication graph.

6. The method of claim 1 , further comprising:

determining confidence levels associated with the classifiers of servers and clients in the network; and

propagating the confidence levels to one or more of the first node, the second node, or the one or more other nodes.

7. A system, comprising:

one or more processors; and

a non-transitory computer-readable storage medium containing instructions which, when executed on the one or more processors, cause the one or more processors to perform operations including:

receiving, from a sensor that monitors at least part of data traffic exchanged between a pair of nodes in a network, information of the data traffic, the pair of nodes comprising a first node and a second node;

determining, based on the information, that the first node is a client and that the second node is a server;

creating one or more classifiers of servers and clients in the network from the result of the determining;

generating at least a first communication graph for the network, the first communication graph comprising the first node, the second node, and one or more other nodes; and

based on the one or more classifiers of servers and clients in the network, assigning one or more of the one or more classifiers of servers or clients to the one or more other nodes.

8. The system of claim 7 , wherein the determining is further based on one or more rules associated with timing, port magnitude, degree of communication, or historical data obtained from the information.

9. The system of claim 7 , wherein the operations further comprise:

associating a weight with the sensor, the weight based on one or more of accuracy, margin of error, length of time of observation, or amount of information collected by the sensor, wherein the information of the data traffic reported by the sensor is weighted using the weight.

10. The system of claim 7 , wherein the operations further comprise:

generating at least a second communication graph for the network, the first communication graph and the second communication graph associated with a first time period and a second time period, respectively.

11. The system of claim 10 , wherein the operations further comprise:

determining combined influences between the first communication graph and the second communication graph.

12. The system of claim 7 , wherein the operations further comprise:

determining confidence levels associated with the classifiers of servers and clients in the network; and

propagating the confidence levels to one or more of the first node, the second node, or the one or more other nodes.

13. A non-transitory machine-readable storage medium, including instructions configured to cause a data processing apparatus to perform operations including:

receiving, from a sensor that monitors at least part of data traffic exchanged between a pair of nodes in a network, information of the data traffic, the pair of nodes comprising a first node and a second node;

determining, based on the information, that the first node is a client and that the second node is a server;

creating one or more classifiers of servers and clients in the network from the result of the determining;

generating at least a first communication graph for the network, the first communication graph comprising the first node, the second node, and one or more other nodes; and

based on the one or more classifiers of servers and clients in the network, assigning one or more of the one or more classifiers of servers or clients to the one or more other nodes.

14. The non-transitory machine-readable storage medium of claim 13 , wherein the determining is further based on one or more rules associated with timing, port magnitude, degree of communication, or historical data obtained from the information.

15. The non-transitory machine-readable storage medium of claim 14 , wherein the operations further comprise:

associating a weight with the sensor, the weight based on one or more of accuracy, margin of error, length of time of observation, or amount of information collected by the sensor, wherein the information of the data traffic reported by the sensor is weighted using the weight.

16. The non-transitory machine-readable storage medium of claim 13 , wherein the operations further comprise:

generating at least a second communication graph for the network, the first communication graph and the second communication graph associated with a first time period and a second time period, respectively.

17. The non-transitory machine-readable storage medium of claim 13 , wherein the operations further comprise:

determining confidence levels associated with the classifiers of servers and clients in the network; and

propagating the confidence levels to one or more of the first node, the second node, or the one or more other nodes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2019
From: PARANDEHGHEIBI, ALI; SINGH, ABHISHEK RANJAN; MADANI, OMID; JEYAKUMAR, VIMALKUMAR; SCHEIB, ELLEN CHRISTINE; YADAV, NAVINDRA; ATTAR, MOHAMMADREZA ALIZADEH
To: CISCO TECHNOLOGY, INC.
Reel/Frame 051220/0209 →
Continuity (3)
Continuation 15140395 · Apr 27, 2016
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20200112494A1 · Apr 9, 2020
Cited By (1)
US 12,659,324