IP Library Granted Patent US 11,683,343
Granted Patent B2
US 11,683,343 · App. 16/664,684 · Granted Jun 20, 2023

Distributed network and security operations platform

Inventors: Barrett Lyon (Truckee, CA); Daniel Murphy (Miami, FL)
Assignee: Netography, Inc.
H04L63/20G06F9/453H04L12/4641H04L45/02H04L51/02H04L63/0218H04L63/0263H04L63/101H04L63/1441H04L67/10H04L12/66
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,683,343
App. No.
16/664,684
Granted
Jun 20, 2023
Kind
B2
Abstract

A distributed network and security operations platform is disclosed. The disclosed platform comprises an external service that facilitates network and security operations for a private network. Data from nodes of the private network is received and analyzed by the service, and an output is automatically generated by the service in response to analyzing received data that facilitates modifying the routing performed by at least one or more of the nodes of the private network.

Claims (65)

1. A method, comprising:

receiving data from edge nodes of a private network at an external service that is external to the private network, wherein the data includes information defining communication sessions but not packet payload information, wherein the edge nodes of the private network collectively form a border of the private network, and wherein the external service is configured to automatically adjust sampling rates of data received from the edge nodes of the private network via communication with the edge nodes of the private network;

analyzing the received data at the external service; and

automatically generating an output from the external service in response to analyzing the data that is communicated to at least one or more edge nodes of the private network and that facilitates modifying routing by the at least one or more edge nodes of the private network.

2. The method of claim 1 , wherein the data comprises a data stream.

3. The method of claim 1 , wherein the data comprises sampled data.

4. The method of claim 1 , wherein the data comprises flow data.

5. The method of claim 1 , wherein the data comprises log data.

6. The method of claim 1 , wherein edge nodes of the private network comprise routers, switches, or both.

7. The method of claim 1 , wherein edge nodes of the private network comprise virtual private cloud services.

8. The method of claim 1 , wherein the external service provides network and security operations for the private network.

9. The method of claim 1 , wherein the external service facilitates managing and optimizing the private network.

10. The method of claim 1 , wherein the external service facilitates defending the private network from threats and attacks.

11. The method of claim 1 , further comprising tagging the data at the external service.

12. The method of claim 1 , further comprising storing the data at the external service.

13. The method of claim 1 , wherein analyzing the received data at the external service comprises detecting a network performance or security event.

14. The method of claim 1 , wherein the output is generated by a rules engine of the external service that is configured to map a detected event to an action.

15. The method of claim 1 , wherein the output comprises a routing filter or block list.

16. The method of claim 1 , wherein the output is communicated to the at least one or more edge nodes of the private network via Border Gateway Protocol (BGP) or FlowSpec.

17. The method of claim 1 , wherein the output is communicated to the at least one or more edge nodes of the private network via an application programming interface (API).

18. The method of claim 1 , further comprising providing a portal to the external service that is accessible to an operator of the private network.

19. A system, comprising:

one or more databases of an external service that is external to a private network configured to store data associated with the private network; and

one or more processors of the external service configured to:

receive data from edge nodes of the private network, wherein the data includes information defining communication sessions but not packet payload information, wherein the edge nodes of the private network collectively form a border of the private network, and wherein the external service is configured to automatically adjust sampling rates of data received from the edge nodes of the private network via communication with the edge nodes of the private network;

analyze the received data at the external service; and

automatically generate an output from the external service in response to analyzing the data that is communicated to at least one or more edge nodes of the private network and that facilitates modifying routing by the at least one or more e nodes of the private network.

20. The system of claim 19 , wherein the data comprises a data stream.

21. The system of claim 19 , wherein the data comprises sampled data.

22. The system of claim 19 , wherein the data comprises flow data.

23. The system of claim 19 , wherein the data comprises log data.

24. The system of claim 19 , wherein edge nodes of the private network comprise routers, switches, or both.

25. The system of claim 19 , wherein edge nodes of the private network comprise virtual private cloud services.

26. The system of claim 19 , wherein the external service provides network and security operations for the private network.

27. The system of claim 19 , wherein the external service facilitates managing and optimizing the private network.

28. The system of claim 19 , wherein the external service facilitates defending the private network from threats and attacks.

29. The system of claim 19 , wherein the processor is further configured to tag the data at the external service.

30. The system of claim 19 , wherein the processor is further configured to store the data at the external service.

31. The system of claim 19 , wherein to analyze the received data at the external service comprises to detect a network performance or security event.

32. The system of claim 19 , wherein the output is generated by a rules engine of the external service that is configured to map a detected event to an action.

33. The system of claim 19 , wherein the output comprises a routing filter or block list.

34. The system of claim 19 , wherein the output is communicated to the at least one or more edge nodes of the private network via Border Gateway Protocol (BGP) or FlowSpec.

35. The system of claim 19 , wherein the output is communicated to the at least one or more edge nodes of the private network via an application programming interface (API).

36. The system of claim 19 , wherein the processor is further configured to provide a portal to the external service that is accessible to an operator of the private network.

37. A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

receiving data from edge nodes of a private network, wherein the computer program product is associated with an external service that is external to the private network, wherein the data includes information defining communication sessions but not packet payload information, wherein the edge nodes of the private network collectively form a border of the private network, and wherein the external service is configured to automatically adjust sampling rates of data received from the edge nodes of the private network via communication with the edge nodes of the private network;

analyzing the received data at the external service; and

automatically generating an output from the external service in response to analyzing the data that is communicated to at least one or more edge nodes of the private network and that facilitates modifying routing by the at least one or more edge nodes of the private network.

38. The computer program product of claim 37 , wherein the data comprises a data stream.

39. The computer program product of claim 37 , wherein the data comprises sampled data.

40. The computer program product of claim 37 , wherein the data comprises flow data.

41. The computer program product of claim 37 , wherein the data comprises log data.

42. The computer program product of claim 37 , wherein edge nodes of the private network comprise routers, switches, or both.

43. The computer program product of claim 37 , wherein edge nodes of the private network comprise virtual private cloud services.

44. The computer program product of claim 37 , wherein the external service provides network and security operations for the private network.

45. The computer program product of claim 37 , wherein the external service facilitates managing and optimizing the private network.

46. The computer program product of claim 37 , wherein the external service facilitates defending the private network from threats and attacks.

47. The computer program product of claim 37 , further comprising computer instructions for tagging the data at the external service.

48. The computer program product of claim 37 , further comprising computer instructions for storing the data at the external service.

49. The computer program product of claim 37 , wherein analyzing the received data at the external service comprises detecting a network performance or security event.

50. The computer program product of claim 37 , wherein the output is generated by a rules engine of the external service that is configured to map a detected event to an action.

51. The computer program product of claim 37 , wherein the output comprises a routing filter or block list.

52. The computer program product of claim 37 , wherein the output is communicated to the at least one or more edge nodes of the private network via Border Gateway Protocol (BGP) or FlowSpec.

53. The computer program product of claim 37 , wherein the output is communicated to the at least one or more edge nodes of the private network via an application programming interface (API).

54. The computer program product of claim 37 , further comprising computer instructions for providing a portal to the external service that is accessible to an operator of the private network.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2025
From: NETOGRAPHY, INC.
To: VECTRA AI, INC.
Reel/Frame 072610/0011 →
RELEASE OF SECURITY INTEREST Recorded Sep 29, 2025
From: SYN VENTURES FUND LP
To: NETOGRAPHY, INC.
Reel/Frame 072401/0691 →
SECURITY INTEREST Recorded Jul 3, 2025
From: NETOGRAPHY, INC.
To: SYN VENTURES FUND LP
Reel/Frame 071607/0593 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2020
From: LYON, BARRETT; MURPHY, DANIEL
To: NETOGRAPHY, INC.
Reel/Frame 051513/0931 →
Continuity (2)
Provisional Application 62751437 · Oct 26, 2018
Related Publication 20200137117A1 · Apr 30, 2020
Cited By (1)
US 12,273,380