IP Library Granted Patent US 11,528,283
Granted Patent B2
US 11,528,283 · App. 16/899,190 · Granted Dec 13, 2022

System for monitoring and managing datacenters

Inventors: Navindra Yadav (Cupertino, CA); Abhishek Ranjan Singh (Pleasanton, CA); Shashidhar Gandham (Fremont, CA); Ellen Christine Scheib (Mountain View, CA); Omid Madani (San Carlos, CA); Ali Parandehgheibi (Sunnyvale, CA); Jackson Ngoc Ki Pang (Sunnyvale, CA); Vimalkumar Jeyakumar (Los Altos, CA); Michael Standish Watts (Los Altos, CA); Hoang Viet Nguyen (Pleasanton, CA); Khawar Deen (Sunnyvale, CA); Rohit Chandra Prasad (Sunnyvale, CA); Sunil Kumar Gupta (Milpitas, CA); Supreeth Hosur Nagesh Rao (Cupertino, CA); Anubhav Gupta (Fremont, CA); Ashutosh Kulshreshtha (Cupertino, CA); Roberto Fernando Spadaro (Milpitas, CA); Hai Trong Vu (San Jose, CA); Varun Sagar Malhotra (Sunnyvale, CA); Shih-Chun Chang (San Jose, CA); Bharathwaj Sankara Viswanathan (Mountain View, CA); Fnu Rachita Agasthy (Sunnyvale, CA); Duane Thomas Barlow (Fremont, CA)
Assignee: Cisco Technology, Inc.
H04L63/1408H04L43/04H04L43/0894H04L63/02H04L63/1425H04L43/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,528,283
App. No.
16/899,190
Granted
Dec 13, 2022
Kind
B2
Abstract

An example method includes detecting, using sensors, packets throughout a datacenter. The sensors can then send packet logs to various collectors which can then identify and summarize data flows in the datacenter. The collectors can then send flow logs to an analytics module which can identify the status of the datacenter and detect an attack.

Claims (37)

1. A system comprising:

one or more processors; and

memory storing instructions which, when executed by the one or more processors, cause the one or more processors to:

obtain network data from sensor processes executing in a data center, the network data being at least partly based on operation system states associated with two or more operating systems in the data center;

generate a log describing a connection between endpoints associated with one or more packets in the network data;

determine a status of the data center based on the log describing the connection between endpoints associated with one or more packets in the network data;

detect, based at least partly on the status of the data center, an indication of an attack within the data center; and

in response to the indication of the attack, modify a security policy based on the status of the data center.

2. The system of claim 1 , wherein the network data comprises a respective indication of active or previously active processes on each of the two or more operating systems.

3. The system of claim 1 , wherein at least one of the log or the network data identifies files present on the two or more operating systems.

4. The system of claim 1 , wherein at least one of the log or the network data comprises data describing packets captured by the sensor processes executing in the data center.

5. The system of claim 1 , wherein at least one of the two or more operating systems comprises a first operating system of a virtual machine or a second operating system of a hypervisor.

6. The system of claim 1 , wherein detecting the indication of the attack comprises at least one of detecting a spike in an amount of resources used by at least one of the sensor processes or detecting spoofed packets.

7. The system of claim 1 , wherein detecting the indication of the attack comprises detecting a hidden process embedded in traffic between two or more reference points.

8. The system of claim 1 , wherein detecting the indication of the attack comprises detecting a scan of a network as initiated by a command from outside of the network or from an unexpected source inside the network.

9. The system of claim 1 , wherein detecting the indication of the attack comprises detecting a packet that has a packet header field that differs from an expected header pattern.

10. A method comprising:

obtaining network data from sensor processes executing in a data center, the network data being at least partly based on operation system states associated with two or more operating systems in the data center;

generating a log describing a connection between endpoints associated with one or more packets in the network data;

determining a status of the data center based on the log describing the connection between endpoints associated with one or more packets in the network data;

detecting, based at least partly on the status of the data center, an indication of an attack within the data center; and

in response to the indication of the attack, modifying a security policy based on the status of the data center.

11. The method of claim 10 , wherein at least one of the log or the network data comprises a respective indication of active or previously active processes on each of the two or more operating systems.

12. The method of claim 10 , wherein at least one of the log or the network data identifies files present on the two or more operating systems.

13. The method of claim 10 , wherein at least one of the log or the network data comprises data describing packets captured by the sensor processes executing in the data center.

14. The method of claim 10 , wherein at least one of the two or more operating systems comprises a first operating system of a virtual machine or a second operating system of a hypervisor.

15. The method of claim 10 , wherein detecting the indication of the attack comprises at least one of detecting a spike in an amount of resources used by at least one of the sensor processes or detecting spoofed packets.

16. The method of claim 10 , wherein detecting the indication of the attack comprises detecting a hidden process embedded in traffic between two or more reference points.

17. The method of claim 10 , wherein detecting the indication of the attack comprises detecting a scan of a network as initiated by a command from outside of the network or from an unexpected source inside the network.

18. A non-transitory computer-readable medium having stored thereon computer-readable instructions that, when executed by one or more processors, cause the one or more processors to:

obtain network data from sensor processes executing in a data center, the network data being at least partly based on operation system states associated with two or more operating systems in the data center;

generate a log describing a connection between endpoints associated with one or more packets in the network data;

determine a status of the data center based on the log describing the connection between endpoints associated with one or more packets in the network data;

detect, based at least partly on the status of the data center, an indication of an attack within the data center; and

in response to the indication of the attack, modify a security policy based on the status of the data center.

19. The non-transitory computer-readable medium of claim 18 , wherein_at least one of the log or the network data comprises a respective indication of active or previously active processes on each of the two or more operating systems.

20. The non-transitory computer-readable medium of claim 18 , wherein at least one of the log or the network data comprises at least one of information about files present on the two or more operating systems or information describing packets captured by the sensor processes executing in the data center.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 11, 2020
From: YADAV, NAVINDRA; SINGH, ABHISHEK RANJAN; GANDHAM, SHASHIDHAR; SCHEIB, ELLEN CHRISTINE; MADANI, OMID; PARANDEHGHEIBI, ALI; PANG, JACKSON NGOC KI; JEYAKUMAR, VIMALKUMAR; WATTS, MICHAEL STANDISH; NGUYEN, HOANG VIET; DEEN, KHAWAR; PRASAD, ROHIT CHANDRA; GUPTA, SUNIL KUMAR; RAO, SUPREETH HOSUR NAGESH; GUPTA, ANUBHAV; KULSHRESHTHA, ASHUTOSH; SPADARO, ROBERTO FERNANDO; VU, HAI TRONG; MALHOTRA, VARUN SAGAR; CHANG, SHIH-CHUN; VISWANATHAN, BHARATHWAJ SANKARA; RACHITA AGASTHY, FNU; BARLOW, DUANE THOMAS
To: CISCO TECHNOLOGY, INC.
Reel/Frame 052912/0643 →
Continuity (4)
Continuation 16179027 · Nov 2, 2018
Continuation 15134100 · Apr 20, 2016
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20200304523A1 · Sep 24, 2020
Cited By (13)
US 12,192,078 US 12,212,476 US 12,224,921 US 12,231,307 US 12,231,308 US 12,278,746 US 12,284,097 US 12,327,165 US 12,335,275 US 12,464,026 US 12,596,568 US 12,657,049 US 12,670,003