IP Library › Granted Patent US 12,732,440
Granted Patent B2
US 12,732,440 · App. 18/759,013 · Granted Sep 8, 2026

Observing network behavior using characteristics of network protocols

Inventors: Thomas Benjamin Emmons (Sunnyvale, CA); Hugh Weber Holbrook (Palo Alto, CA)
Assignee: ARISTA NETWORKS, INC.
H04L43/026G06F15/17331H04L41/16H04L43/0852
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,440
App. No.
18/759,013
Granted
Sep 8, 2026
Kind
B2
Abstract

Network monitoring systems and methods that utilize packet characteristics to perform network monitoring by capturing a limited subset of packets are disclosed. These captured packets can be correlated to monitor flows within the network and determine performance characteristics of the applications or the network with respect to those flows using the captured packets.

Claims (65)

1 . A network device comprising:

one or more processors configured for:

receiving, at the network device, a set of packets communicated from a first host to a second host over the network, wherein the network device is an intermediary network device situated in the network between the first and second hosts, and wherein the set of packets include a first packet;

determining the first packet indicates a start of a data transfer;

capturing the first packet at the network device based on the determination the first packet indicates the start of the data transfer;

receiving a second packet at the network device;

determining the second packet indicates an end of the data transfer;

capturing the second packet at the network device based on the determination the second packet indicates the end of the data transfer;

determining the second packet indicates the end of the data transfer corresponding to the first packet indicating the start of the data transfer;

associating the first packet and the second packet with a flow; and

determining data associated with the network or the flow based on the first packet and the second packet,

wherein data packets received by the network device that do not indicate a start or an end of a data transfer are not captured.

2 . The network device of claim 1 , wherein the one or more processors are further configured for:

determining, before capturing the first packet, that a first packet sequence number of the first packet is within a range of packet sequence numbers; and

determining, before capturing the second packet, that a second packet sequence number of the second packet is within the range of packet sequence numbers.

3 . The network device of claim 2 , wherein determining the first packet sequence number and the second packet number are within the range is based on matching a set of bits of the first packet sequence number and the second packet sequence number.

4 . The network device of claim 3 , wherein the set of bits are a set of middle bits or a set of most significant bits.

5 . The network device of claim 2 , wherein the determination that the second packet is the write last packet corresponding to the first packet is made based on a first packet sequence number of the first packet and a second packet sequence number of the second packet or on a message size associated with the first packet.

6 . The network device of claim 1 , wherein the first packet is a write first packet and the second packet is a write last packet.

7 . The network device of claim 6 , wherein the determination that the first packet is a write first packet is made based on a first opcode of the first packet and the determination that the second packet is a write last packet is made based on a second opcode of the second packet.

8 . The network device of claim 6 , wherein the flow is determined based on a source IP address, a destination IP address, and a destination queue pair (QP) associated with the first packet and second packet.

9 . The network device of claim 6 , wherein the one or more processors are further configured for:

determining a first latency associated with the first packet;

determining second latency associated with the second packet; and

determining network data associated with the network and the first data write based on a comparison of the first latency and the second latency.

10 . The network device of claim 6 , wherein the one or more processors are further configured for:

receiving a third packet communicated from the first host to the second host over the network;

determining the third packet is a write first packet;

capturing the third packet based on the determination the third packet is the write first packet associated with a second data write;

receiving a fourth packet;

determining the fourth packet is a write last packet;

capturing the fourth packet based on the determination the fourth packet is a write last packet;

determining the fourth packet corresponds to the second data write associated with the third packet;

determining the third packet and the fourth packet are associated with the flow;

determining the second write is subsequent to the first data write; and

determining data associated with the host based on the second packet that is the write last packet for the first write and the third packet which is the write first packet that is the write first packet for the second write.

11 . The network device of claim 1 , wherein the data transfer is an accelerated data transfer.

12 . The network device of claim 1 , wherein the flow is associated with a set of data transfers.

13 . The network device of claim 1 , wherein the data associated with the network or the flow comprises performance characteristics of the network or the flow.

14 . The network device of claim 1 , wherein the capturing of the first and second packets comprises:

creating a copy of the first and second packets in a buffer maintained in a control plane of the network device; and

forwarding the first and second packets onward towards the second host.

15 . A method performed by a network device for monitoring a network, comprising:

receiving a set of packets communicated from a first host to a second host over the network, wherein the network device is an intermediary network device situated in the network between the first and second hosts, and wherein the set of packets include a first packet;

determining the first packet should be captured based on determination that the first packet is a write first packet or a write last packet;

capturing the first packet at the network device based on the determination the first packet is the write first packet associated with a first data write;

determining a flow associated with the first packet;

when there is an entry associated with the determined flow in network monitoring data, associating the captured first packet with the entry for the flow;

when there is no entry associated with the determined flow in the network monitoring data, creating the entry associated with the determined flow and associating the captured first packet with the created entry for the flow;

when the first packet is a write last packet, determining a second packet associated with the flow where the second packet is the write first packet corresponding to the first packet and associating the first packet with the second packet in the network monitoring data; and

determining data associated with the network or the flow based on the first packet or the second packet,

wherein packets in the set of packets that are neither the write first packet or the write last packet are not captured.

16 . The method of claim 15 , wherein the flow comprises a source IP address, a destination address, and a QP.

17 . The method of claim 15 , wherein the determination that the first packet should be captured is based on a packet sequence number associated with the first packet.

18 . The method of claim 15 , further comprising associating the flow with one or more other flows to determine a collective including the flow, wherein the network data includes network data associated with the collective.

19 . A non-transitory computer readable medium, comprising instructions executable by a network device for:

obtaining a captured first ROCE packet associated with a data write, wherein the first ROCE packet was captured from a set of packets at the network device based on a determination that the first ROCE packet is a write first packet;

obtaining a captured second ROCE packet, wherein the second ROCE packet was captured from the set of packets at the network device based on a determination that the second ROCE packet is a write last packet;

determining the second ROCE packet is the write last packet corresponding to the first ROCE packet that is the write first packet associated with the data write;

associating the first ROCE packet and the second ROCE packet with a flow; and

determining network data associated with the network or the flow based on the first ROCE packet and the second ROCE packet,

wherein the set of packets are communicated from a first host to a second host over the network, and wherein the network device is an intermediary network device situated in the network between the first and second hosts,

wherein packets in the set of packets that are neither the write first packet or the write last packet are not captured.

20 . The non-transitory computer readable medium of claim 19 , wherein the first ROCE packet and the second ROCE packet were captured by a data plane of the network device.

21 . The non-transitory computer readable medium of claim 20 , wherein the first ROCE packet and the second ROCE packet were captured by matching an opcode in the data plane or by matching a packet sequence number in the data plane.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2024
From: EMMONS, THOMAS BENJAMIN; HOLBROOK, HUGH WEBER
To: ARISTA NETWORKS, INC.
Reel/Frame 067968/0923 →
Continuity (2)
Provisional Application 63634207 · Apr 15, 2024
Related Publication 20250323847A1 · Oct 16, 2025
References Cited (22)
US 9191290B2 · Ding · 2015 [cited by examiner]
US 9658782B2 · Romem · 2017 [cited by examiner]
US 10509764B1 · Izenberg · 2019 [cited by examiner]
US 10728109B1 · Hu · 2020 [cited by examiner]
US 11620254B2 · Miller · 2023 [cited by examiner]
US 12531806B2 · Goyal · 2026 [cited by examiner]
US 20170171075A1 · Sajeepa · 2017 [cited by examiner]
US 20170187629A1 · Shalev · 2017 [cited by examiner]
US 20190361743A1 · Magro · 2019 [cited by examiner]
US 20200104275A1 · Sen · 2020 [cited by examiner]
US 20220232074A1 · Scaglione · 2022 [cited by examiner]
US 20230064845A1 · Srinivasan · 2023 [cited by examiner]
US 20230239244A1 · Tian · 2023 [cited by examiner]
US 20230269148A1 · Foo · 2023 [cited by examiner]
US 20230336490A1 · Arslan · 2023 [cited by examiner]
US 20230421463A1 · Hatta · 2023 [cited by examiner]
US 20240220347A1 · Han · 2024 [cited by examiner]
US 20240275700A1 · Hatta · 2024 [cited by examiner]
US 20250184260A1 · Yin · 2025 [cited by examiner]
European Patent Office, Extended European Search Report, Ep App. No. 25170322.9, dated Aug. 26, 2025, 8 pgs. [cited by applicant]
Liu Yao et al: “Scalable Fully Pipelined Hardware Architecture for In-Network Aggregated AllReduce Communication”, IEEE Transactions on Circuits and Systems I: Regular Papers, IEEE, US, vol. 68, No. 10, Jul. 29, 2021 (J… [cited by applicant]
Talpey Microsoft T Hurson Intel G Agarwal Marvell T Reu Chelsio T: “RDMA Extensions for Enhanced Memory Placement; draft-talpey-rdma-commit-01.txt”, RDMA Extensions for Enhanced Memory Placement; Draft-Talpeyrdma-Commit… [cited by applicant]