IP Library Granted Patent US 12,489,773
Granted Patent B2
US 12,489,773 · App. 18/310,486 · Granted Dec 2, 2025

On-premises network traffic monitoring via security agent configured port mirroring of router device

Inventors: Yossef Basha (Kadima, IL); Benyamin Farshteindiker (Petah Tikwa, IL); Ran Albagli (Rishon Lezion, IL)
Assignee: Microsoft Technology Licensing, LLC
H04L63/1425H04L43/062H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,489,773
App. No.
18/310,486
Granted
Dec 2, 2025
Kind
B2
Abstract

A computing system is provided, including a server computing device configured to execute a security service that communicates with a security agent on a client computing device via a wide area network and an on-premises network on which the client computing device is provisioned, and receive and store, at the server computing device, administrator login credentials for a router device on the on-premises network. The processor is further configured to send a monitoring command to the security agent to cause the security agent to access the router device using the administrator login credentials and configure the router device to forward network traffic received by the router device to the security agent at the client computing device via port mirroring, and receive an on-premises network traffic monitoring report from the security agent based on the network traffic forwarded to the client computing device.

Claims (51)

1 . A computing system comprising:

a server computing device comprising a processor configured to:

execute a security service configured to communicate with a security agent on a client computing device via a wide area network and an on-premises network on which the client computing device is provisioned;

receive and store, at the server computing device, administrator login credentials for a router device having a network address on the on-premises network;

send a monitoring command to the security agent to cause the security agent, on the on-premises network, to establish a secure session with the router device at the network address using the administrator login credentials and configure the router device to forward network traffic received by the router device to the security agent at the client computing device via port mirroring; and

receive an on-premises network traffic monitoring report from the security agent based on the network traffic forwarded to the client computing device.

2 . The computing system of claim 1 , wherein the monitoring command comprises an on-premises network traffic monitoring policy comprising the administrator login credentials and port mirroring configuration settings, which upon implementation at the security agent, causes the security agent to access the router device using the administrator login credentials and configure the router device according to the port mirroring configuration settings to forward network traffic received by the router device to the security agent at the client computing device via port mirroring.

3 . The computing system of claim 2 , wherein the port mirroring configuration settings designate one or a plurality of destination ports on the client computing device where the network traffic is to be forwarded by the router device.

4 . The computing system of claim 2 , wherein the on-premises network traffic monitoring policy further comprises one or more trigger conditions, the one or more trigger conditions comprising a condition that the client computing device has a shortest network distance to the router device in the on-premises network.

5 . The computing system of claim 1 , wherein the router device is a hub or a bridge.

6 . The computing system of claim 1 , wherein the on-premises network traffic monitoring report comprises aggregated network traffic statistics based on the network traffic forwarded to the security agent and processed at the security agent to produce the aggregated network traffic statistics.

7 . The computing system of claim 6 , wherein the server computing device is configured to correlate the network traffic to specific network devices among a plurality of network devices within the on-premises network.

8 . The computing system of claim 6 , wherein

the server computing device is configured to generate a network map using distributed discovery to classify a plurality of network devices in the on-premises network; and

the server computing device is configured to correlate the network traffic to specific network devices among the plurality of network devices within the on-premises network using the network map.

9 . The computing system of claim 6 , wherein the aggregated network traffic statistics comprises at least one selected from the group of event logs, security logs, Virtual Private Network (VPN) logs, Active Directory information, and entity information.

10 . The computing system of claim 1 , wherein the router device is a gateway router device.

11 . The computing system of claim 10 , wherein

the client computing device is a first client computing device;

the gateway router device is a first gateway router device;

the on-premises network is a first on-premises network having a first plurality of network devices comprising the first client computing device; and

the computing system further comprising:

a second gateway router device configured to receive network traffic in a second on-premises network having a second plurality of network devices comprising a second client computing device; and

the security service of the server computing device is further configured to:

communicate with a second security agent on the second client computing device via the wide area network and the second on-premises network;

receive and store, at the server computing device, second administrator login credentials for the second gateway router device having a second network address on the second on-premises network;

send a second monitoring command to the second security agent to cause the second security agent to access the second gateway router device at the second network address using the second administrator login credentials and configure the second gateway router device to forward network traffic received by the second gateway router device to the second security agent at the second client computing device via port mirroring; and

receive a second on-premises network traffic monitoring report from the second security agent based on the network traffic forwarded to the second client computing device.

12 . A computerized method comprising:

executing a security service at a server computing device, the security service being configured to communicate with a security agent on a client computing device via a wide area network and an on-premises network on which the client computing device is provisioned;

receiving and storing, at the server computing device, administrator login credentials for a router device having a network address on the on-premises network;

sending a monitoring command to the security agent to cause the security agent, on the on-premises network, to establish a secure session with the router device at the network address using the administrator login credentials and configure the router device to forward network traffic received by the router device to the security agent at the client computing device via port mirroring; and

receiving an on-premises network traffic monitoring report from the security agent based on the network traffic forwarded to the client computing device.

13 . The computerized method of claim 12 , wherein the monitoring command comprises an on-premises network traffic monitoring policy comprising the administrator login credentials and port mirroring configuration settings, which upon implementation at the security agent, causes the security agent to access the router device using the administrator login credentials and configure the router device according to the port mirroring configuration settings to forward network traffic received by the router device to the security agent at the client computing device via port mirroring.

14 . The computerized method of claim 13 , wherein the port mirroring configuration settings designate:

one or a plurality of destination ports on the client computing device where the network traffic is to be forwarded by the router device.

15 . The computerized method of claim 12 , wherein the on-premises network traffic monitoring report comprises aggregated network traffic statistics based on the network traffic forwarded to the security agent and processed at the security agent to produce the aggregated network traffic statistics.

16 . The computerized method of claim 15 , further comprising correlating the network traffic to specific network devices among a plurality of network devices within the on-premises network.

17 . The computerized method of claim 16 , further comprising:

generating a network map using distributed discovery to classify the plurality of network devices in the on-premises network; and

correlating the network traffic to the specific network devices among the plurality of network devices within the on-premises network using the network map.

18 . The computerized method of claim 15 , wherein the aggregated network traffic statistics comprises at least one selected from the group of event logs, security logs, Virtual Private Network (VPN) logs, Active Directory information, entity information.

19 . A computing system, comprising:

a client computing device comprising a processor configured to:

execute a security agent configured to communicate with a security service on a server computing device via a wide area network and an on-premises network on which the client computing device is provisioned; and

via the executed security agent executed at the client computing device on the on-premises network:

receive a monitoring command from the security service;

establish a secure session with a router device provisioned at a network address on the on-premises network using administrator login credentials received from the security service, and configure the router device to forward network traffic received by the router device to the security agent at the client computing device via port mirroring;

receive and process the forwarded network traffic to generate an on-premises network traffic monitoring report; and

send the on-premises network traffic monitoring report to the security service of the server computing device.

20 . The computing system of claim 19 , wherein the monitoring command comprises an on-premises network traffic monitoring policy comprising the administrator login credentials and port mirroring configuration settings, which upon implementation at the security agent causes the security agent to access the router device using the administrator login credentials and configure the router device according to the port mirroring configuration settings to forward network traffic received by the router device to the security agent at the client computing device via port mirroring.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2023
From: BASHA, YOSSEF; FARSHTEINDIKER, BENYAMIN; ALBAGLI, RAN
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 063498/0968 →
Continuity (1)
Related Publication 20240372881A1 · Nov 7, 2024
References Cited (25)
US 7224668B1 · Smethurst · 2007 [cited by examiner]
US 9686296B1 · Murchison · 2017 [cited by examiner]
US 10623283B2 · Yadav · 2020 [cited by examiner]
US 20060277603A1 · Kelso · 2006 [cited by applicant]
US 20080130497A1 · Sang Wan · 2008 [cited by examiner]
US 20090249440A1 · Platt · 2009 [cited by examiner]
US 20160294731A1 · McDaniel · 2016 [cited by examiner]
US 20190205511A1 · Zhan · 2019 [cited by examiner]
US 20200403826A1 · Dawani et al. · 2020 [cited by applicant]
US 20210273953A1 · Fellows · 2021 [cited by examiner]
US 20230110265A1 · Fainberg · 2023 [cited by examiner]
US 20230208879A1 · Thomas · 2023 [cited by examiner]
CN 107409069A · 2017 [cited by examiner]
CN 115314392A · 2022 [cited by examiner]
WO WO0199002A2 · 2001 [cited by examiner]
WO 2018044876A1 · 2018 [cited by applicant]
WO WO2022066910A1 · 2022 [cited by examiner]
Anonymous, “macos-SSSH tunnel to home network, and access router web interface—Super User,” Retrieved from the Internet URL:—https://web.archive.org/web/20201205232025/https://superuser.com/questions/330131/ssh-tunnel-t… [cited by applicant]
International Search Report and Written Opinion received for PCT Application No. PCT/US2024/025620, Jul. 9, 2024, 13 pages. [cited by applicant]
“Device Discovery Overview”, Retrieved From: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-discovery?view=o365-worldwide, Feb. 7, 2023, 7 Pages. [cited by applicant]
“Enable Corelight as Data Source in Microsoft Defender for Endpoint”, Retrieved From: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/corelight-integration?view=o365-worldwide, Feb. 7, 2023, 4… [cited by applicant]
“Port Mirroring”, Retrieved From: https://en.wikipedia.org/wiki/Port_mirroring#, May 8, 2022, 1 Page. [cited by applicant]
“Virtual Network TAP”, Retrieved From: https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-tap-overview, Feb. 22, 2023, 4 Pages. [cited by applicant]
“Why IT and Security Teams Trust Axonius”, Retrieved From: https://www.axonius.com/, Retrieved From: Mar. 7, 2023, 11 Pages. [cited by applicant]
Solomon, et al., “New Network-based Detections and Improved Device Discovery using Zeek”, Retrieved From: https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/new-network-based-detections-and-improved-… [cited by applicant]