IP Library › Granted Patent US 12,289,349
Granted Patent B2
US 12,289,349 · App. 18/500,351 · Granted Apr 29, 2025

Network traffic monitoring based on content data

Inventor: Sheeja J S (Bangalore, IN)
Assignee: Juniper Networks, Inc.
H04L63/306H04L43/026H04L43/028H04L43/12H04L63/08H04L63/102H04L41/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,289,349
App. No.
18/500,351
Granted
Apr 29, 2025
Kind
B2
Abstract

A network monitoring device may receive, from a mediation device, flow-tap content data (generated by the mediation device based on current and/or previous investigation reports associated with flow tapping) that needs to be monitored. The network monitoring device may map the content data to a flow-tap content destination address of a content destination device in an entry of a flow-tap content filter. The network monitoring device may analyze, using the flow-tap content filter, network traffic of the network to detect a traffic flow that includes the content data. The network monitoring device may generate, based on successfully detecting a traffic flow that includes the content data, a traffic flow copy and may provide the traffic flow copy to the flow-tap content destination address, wherein the traffic flow copy is to be accessible to the content destination device to enable a context analysis of the content data.

Claims (73)

1. A method, comprising:

receiving, by a network device of a network, flow-tap content information that identifies content data that is to be monitored by a content destination device;

storing, by the network device, the flow-tap content information in a flow-tap content filter,

wherein an entry of the flow-tap content filter identifies the content data;

detecting, by the network device and using the flow-tap content filter, a traffic flow that includes a packet having the content data;

sending, by the network device and to the content destination device, a message indicating that the traffic flow has been detected;

extracting, by the network device, payload data of the traffic flow based on a structure of the traffic flow,

wherein a traffic flow copy is generated to include the payload data, and

wherein the content data is a subset of the payload data;

generating, by the network device and based on receiving a response from the content destination device to perform a flow tapping process on the traffic flow, the traffic flow copy that corresponds to the traffic flow; and

providing, by the network device, the traffic flow copy to the content destination device to permit the content destination device to perform a context analysis of the content data.

2. The method of claim 1 , wherein receiving the flow-tap content information comprises:

receiving, from a mediation device, credentials of the mediation device; and

verifying, based on receiving the credentials of the mediation device, that the mediation device is authorized to utilize the flow-tap content filter.

3. The method of claim 1 , wherein the content data is associated with a set of keywords or a set of key phrases that are configured to trigger the content destination device to perform the context analysis.

4. The method of claim 1 , wherein the flow-tap content information further identifies:

destination information that is associated with a destination that is to receive the content data,

wherein the traffic flow is detected based on identifying that the traffic flow is to be forwarded to the destination.

5. The method of claim 1 , wherein the flow-tap content information further identifies:

source information that is associated with a source that is to provide the content data,

wherein the traffic flow is detected based on identifying that the traffic flow is associated with the source.

6. The method of claim 1 , further comprising:

forwarding, and without indicating to a traffic flow destination that the traffic flow copy has been generated, the traffic flow to the traffic flow destination.

7. The method of claim 1 , wherein the content destination device is associated with a law enforcement authority.

8. A network device, comprising:

one or more memories; and

one or more processors to:

receive flow-tap content information that identifies content data that is to be monitored by a content destination device;

store the flow-tap content information in a flow-tap content filter,

wherein an entry of the flow-tap content filter identifies the content data;

detect, using the flow-tap content filter, a traffic flow that includes a packet having the content data;

send, to the content destination device, a message indicating that the traffic flow has been detected;

extract payload data of the traffic flow based on a structure of the traffic flow,

wherein a traffic flow copy is generated to include the payload data, and

wherein the content data is a subset of the payload data;

generate, based on receiving a response from the content destination device to perform a flow tapping process on the traffic flow, the traffic flow copy of the traffic flow;

provide the traffic flow copy to the content destination device; and

transmit the traffic flow to a traffic flow destination.

9. The network device of claim 8 , wherein the flow-tap content information is received from a mediation device; and

wherein the one or more processors, prior to detecting the traffic flow, are to:

verify, based on credentials of the mediation device, that the mediation device is an authorized device.

10. The network device of claim 8 , wherein the one or more processors, prior to detecting the traffic flow, are to:

identify, from the flow-tap content information, the traffic flow destination or a traffic flow source associated with the traffic flow,

wherein the traffic flow is identified based on the traffic flow being associated with the at least one of the traffic flow destination or the traffic flow source.

11. The network device of claim 8 , wherein the one or more processors, prior to generating the traffic flow copy, are to:

generate routing data for transmission of the traffic flow to the traffic flow destination,

wherein the traffic flow destination is associated with a destination address identified in the traffic flow.

12. The network device of claim 8 , wherein the content data is associated with at least one of a set of keywords, a set of key phrases, or a set of word patterns that are configured to trigger the flow tapping process.

13. The network device of claim 8 , wherein the one or more processors, when transmitting the traffic flow to the traffic flow destination, are to:

provide the traffic flow to the traffic flow destination without notifying the traffic flow destination that the traffic flow copy was generated.

14. The network device of claim 8 , wherein the content destination device is associated with a law enforcement authority.

15. A non-transitory computer-readable medium storing instructions, the instructions comprising:

one or more instructions that, when executed by one or more processors of a network device, cause the one or more processors to:

receive flow-tap content information that identifies content data that is to be monitored by a content destination device;

store the flow-tap content information in a flow-tap content filter,

wherein an entry of the flow-tap content filter identifies the content data;

detect, using the flow-tap content filter, a traffic flow that includes a packet having the content data;

send, to the content destination device, a message indicating that the traffic flow has been detected;

extract payload data of the traffic flow based on a structure of the traffic flow,

wherein a traffic flow copy is generated to include the payload data, and

wherein the content data is a subset of the payload data; and

generate, based on receiving a response from the content destination device to perform a flow tapping process on the traffic flow, the traffic flow copy of the traffic flow; and

provide the traffic flow copy to the content destination device.

16. The non-transitory computer-readable medium of claim 15 , wherein the traffic flow is associated with at least one of:

a particular source, of the traffic flow, that is identified in the entry, or

a particular destination, of the traffic flow, that is identified in the entry.

17. The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

transmit, without indicating to a traffic flow destination that the traffic flow copy was generated, the traffic flow to the traffic flow destination.

18. The non-transitory computer-readable medium of claim 15 , wherein the flow-tap content information is received from a mediation device; and

wherein the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

verify, based on credentials of the mediation device, that the mediation device is an authorized device.

19. The non-transitory computer-readable medium of claim 15 , wherein the content data is associated with at least one of a set of keywords, a set of key phrases, or a set of word patterns that are configured to trigger the flow tapping process.

20. The non-transitory computer-readable medium of claim 15 , wherein the content destination device is associated with a law enforcement authority.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2024
From: J S, SHEEJA
To: JUNIPER NETWORKS, INC.
Reel/Frame 066332/0484 →
Continuity (2)
Continuation 16915285 · Jun 29, 2020
Related Publication 20240073112A1 · Feb 29, 2024
References Cited (33)
US 7251215B1 · Turner et al. · 2007 [cited by applicant]
US 7633944B1 · Chang et al. · 2009 [cited by applicant]
US 7747737B1 · Apte et al. · 2010 [cited by applicant]
US 7809827B1 · Apte · 2010 [cited by examiner]
US 8537818B1 · Thesayi · 2013 [cited by examiner]
US 8605629B1 · S et al. · 2013 [cited by applicant]
US 9444683B2 · Kakadia et al. · 2016 [cited by applicant]
US 9736051B2 · Nachum · 2017 [cited by applicant]
US 9877210B1 · Hildner et al. · 2018 [cited by applicant]
US 10187400B1 · Castro · 2019 [cited by examiner]
US 11115346B2 · Stolarchuk et al. · 2021 [cited by applicant]
US 11811627B2 · J S · 2023 [cited by examiner]
US 20060059163A1 · Frattura et al. · 2006 [cited by applicant]
US 20060179141A1 · John et al. · 2006 [cited by applicant]
US 20070157306A1 · Elrod et al. · 2007 [cited by applicant]
US 20100199189A1 · Ben-Aroya et al. · 2010 [cited by applicant]
US 20110179479A1 · Tsai et al. · 2011 [cited by applicant]
US 20110258702A1 · Olney et al. · 2011 [cited by applicant]
US 20120096145A1 · Le et al. · 2012 [cited by applicant]
US 20130188635A1 · Park et al. · 2013 [cited by applicant]
US 20140269269A1 · Kovvali et al. · 2014 [cited by applicant]
US 20140321278A1 · Cafarelli et al. · 2014 [cited by applicant]
US 20160142304A1 · Alawani et al. · 2016 [cited by applicant]
US 20170063786A1 · Pettit et al. · 2017 [cited by applicant]
US 20170187587A1 · Keppel et al. · 2017 [cited by applicant]
US 20170237645A1 · Shanbhag et al. · 2017 [cited by applicant]
US 20190149518A1 · Sevinc et al. · 2019 [cited by applicant]
US 20190303385A1 · Ching et al. · 2019 [cited by applicant]
US 20200137024A1 · Janakiraman · 2020 [cited by applicant]
US 20200137115A1 · Janakiraman et al. · 2020 [cited by applicant]
US 20210076260A1 · Albasheir · 2021 [cited by examiner]
US 20210226887A1 · Mereddy · 2021 [cited by applicant]
US 20220103525A1 · Shribman et al. · 2022 [cited by applicant]