IP Library › Granted Patent US 12,732,517
Granted Patent B1
US 12,732,517 · App. 19/459,910 · Granted Sep 8, 2026

Network data traffic monitor and analyzer

Inventor: Aubrey Grant Chernick (Brentwood, CA)
Assignee: Celerium Inc.
H04L63/1416H04L63/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,517
App. No.
19/459,910
Granted
Sep 8, 2026
Kind
B1
Abstract

A network data traffic monitor and analyzer including at least one digital processor, a network interface coupled to the digital processor, and digital memory including code segments for: (a) receiving north-south network flow telemetry; (b) resolving the destination network identifiers into domain or organizational identifiers, (c) developing and storing persistent domain-centric relationship records, (d) establishing baseline relationship profiles between network sources and destinations over at least one observation window; (e) comparing current network flow telemetry against the baseline relationship profiles to identify structural relationship deviations, and (f) reporting at least one of the domain-centric relationship records and the structural relationship deviations.

Claims (63)

1 . A network data traffic monitor and analyzer comprising:

at least one digital processor;

a network interface coupled to the digital processor; and

digital memory including code segments executable by the at least one digital processor for

(a) receiving north-south network flow telemetry via the network interface, the north-south network flow telemetry including metadata derived from at least one of a firewall, a router, or a cloud flow logging service without packet payload inspection, the north-south network flow telemetry including source and destination network identifiers;

(b) resolving the destination network identifiers into domain or organizational identifiers using one or more resolution techniques including at least one of: (i) domain name system (DNS) data, (ii) cloud-provider metadata, or (iii) registry-based attribution data;

(c) constructing, from the received telemetry, persistent domain-centric relationship records that represent observed communication pairings between network sources and destinations, aggregated over an observation window, as first-class analytical objects independent of individual network flow events;

(d) storing the persistent domain-centric relationship records in a data structure logically separate from the received telemetry such that the relationship records persist independently of retention of the telemetry;

(e) establishing baseline relationship profiles based upon the persistent domain-centric relationship records, the baseline relationship profiles comprising structural connectivity representations of relationships between network sources and destinations independent of packet-level or flow-level metrics;

(f) comparing subsequently received network flow telemetry, via corresponding persistent relationship records, against the baseline relationship profiles to identify structural relationship deviations including at least one of,

(i) an emergence of a previously unobserved relationship,

(ii) a disappearance of a previously established relationship, or

(iii) a change in one or more structural attributes of a relationship; and

(g) reporting at least one of the domain-centric relationship records and the structural relationship deviations.

2 . The network data traffic monitor and analyzer of claim 1 , wherein at least one of the firewall or router is a cloud-based virtual firewall or router.

3 . The network data traffic monitor and analyzer of claim 1 , wherein developing and storing persistent domain-centric relationship records comprises generating pairings using one or more pairing types selected from domain-to-domain, Internet Protocol (IP)-to-domain, domain-to-IP, or IP-to-IP.

4 . The network data traffic monitor and analyzer of claim 1 , wherein the persistent domain-centric relationship records include directional metadata indicating initiation or predominant data flow direction to support analysis of asymmetric communication patterns.

5 . The network data traffic monitor and analyzer of claim 1 , wherein baseline relationship profiles are represented as source-to-destination matrices encoding structural communication patterns.

6 . The network data traffic monitor and analyzer of claim 1 , wherein baseline relationship profiles are represented as destination-to-source matrices to identify shared external dependencies across multiple internal systems.

7 . The network data traffic monitor and analyzer of claim 1 , wherein identifying structural relationship deviations comprises detecting an emergence of a previously unobserved relationship pairing.

8 . The network data traffic monitor and analyzer of claim 1 , wherein identifying structural relationship deviations comprises detecting a disappearance of a previously established relationship pairing.

9 . The network data traffic monitor and analyzer of claim 1 , wherein identifying structural relationship deviations comprises detecting a change in one or more attributes of a relationship including frequency, volume, duration, or temporal distribution.

10 . The network data traffic monitor and analyzer of claim 1 , wherein baseline relationship profiles are maintained as evolving reference states that preserve historical structural context while incorporating newly observed stable relationships.

11 . The network data traffic monitor and analyzer of claim 10 , wherein baseline states are retained as historical baseline states to enable comparison to current relationship structures.

12 . The network data traffic monitor and analyzer of claim 1 , wherein comparing current network flow telemetry against baseline relationship profiles is performed using deterministic or statistical techniques.

13 . The network data traffic monitor and analyzer of claim 1 , wherein comparing current network flow telemetry against baseline relationship profiles optionally employs a machine-learning model applied to relationship metadata.

14 . The network data traffic monitor and analyzer of claim 1 , further comprising aggregating identified structural relationship deviations across multiple independent organizations associated with respective network environments.

15 . The network data traffic monitor and analyzer of claim 14 , wherein aggregating structural relationship deviations comprises identifying correlated deviation patterns associated with shared external domains or services.

16 . The network data traffic monitor and analyzer of claim 1 , wherein identifying structural relationship deviations further comprises detecting negative deviations characterized by reduction, degradation, suppression, or sustained absence of expected communications relative to baseline relationship profiles.

17 . The network data traffic monitor and analyzer of claim 16 , wherein negative deviations are evaluated relative to learned variability envelopes associated with each relationship rather than fixed thresholds.

18 . The network data traffic monitor and analyzer of claim 16 , wherein confidence of negative deviation identification is weighted based on historical reliability, predictability, and variance of the relationship.

19 . The network data traffic monitor and analyzer of claim 16 , wherein negative deviation detection supports identification of operational disruption, supplier outage, maintenance conditions, or ransomware-related encryption events independent of malicious attribution.

20 . The network data traffic monitor and analyzer of claim 1 , wherein one or more identified relationships are reconstructed based on metadata obtained from application workflow engines that coordinate distributed execution across multiple systems or services.

21 . The network data traffic monitor and analyzer of claim 20 , wherein the workflow engine metadata comprises logs, audit records, control-plane traces, or execution identifiers that enable inference of actual communication targets.

22 . A computer-implemented method comprising:

(a) receiving north-south network flow telemetry via a network interface of a computer, the north-south network flow telemetry including metadata derived from at least one of a firewall, a router, or a cloud flow logging service without packet payload inspection, the north-south network flow telemetry including source and destination network identifiers;

(b) resolving the destination network identifiers into domain or organizational identifiers on the computer using one or more resolution techniques including at least one of: (i) domain name system (DNS) data, (ii) cloud-provider metadata, or (iii) registry-based attribution data;

(c) constructing, from the received telemetry, persistent domain-centric relationship records that represent observed communication pairings between network sources and destinations, aggregated over an observation window, as first-class analytical objects independent of individual network flow events on the computer;

(d) storing the persistent domain-centric relationship records in a data structure logically separate from the received telemetry such that the relationship records persist independently of retention of the telemetry;

(e) establishing baseline relationship profiles based upon the persistent domain-centric relationship records, the baseline relationship profiles comprising structural connectivity representations of relationships between network sources and destinations independent of packet-level or flow-level metrics;

(f) comparing subsequently received network flow telemetry, via corresponding persistent relationship records, against the baseline relationship profiles to identify structural relationship deviations on the computer including at least one of,

(i) an emergence of a previously unobserved relationship,

(ii) a disappearance of a previously established relationship, or

(iii) a change in one or more structural attributes of a relationship; and

(g) reporting at least one of the domain-centric relationship records and the structural relationship deviations by the computer.

23 . The computer-implemented method of claim 22 , wherein at least one of the firewall or router is a cloud-based virtual firewall or router.

24 . The computer-implemented method of claim 22 , wherein developing and storing persistent domain-centric relationship records comprises generating pairings using one or more pairing types selected from domain-to-domain, Internet Protocol (IP)-to-domain, domain-to-IP, or IP-to-IP.

25 . The computer-implemented method of claim 22 , wherein the persistent domain-centric relationship records include directional metadata indicating initiation or predominant data flow direction to support analysis of asymmetric communication patterns.

26 . The computer-implemented method of claim 22 , wherein baseline relationship profiles are represented as source-to-destination matrices encoding structural communication patterns.

27 . The computer-implemented method of claim 22 , wherein baseline relationship profiles are represented as destination-to-source matrices to identify shared external dependencies across multiple internal systems.

28 . The computer-implemented method of claim 22 , wherein identifying structural relationship deviations comprises detecting an emergence of a previously unobserved relationship pairing.

29 . The computer-implemented method of claim 22 , wherein identifying structural relationship deviations comprises detecting a disappearance of a previously established relationship pairing.

30 . A non-transitory computer-readable medium storing code segments that, when executed by one or more processors, cause performance of operations comprising:

(a) receiving north-south network flow telemetry via a network interface of a computer, the north-south network flow telemetry including metadata derived from at least one of a firewall, a router, or a cloud flow logging service without packet payload inspection, the north-south network flow telemetry including source and destination network identifiers;

(b) resolving the destination network identifiers into domain or organizational identifiers using one or more resolution techniques including at least one of: (i) domain name system (DNS) data, (ii) cloud-provider metadata, or (iii) registry-based attribution data;

(c) constructing, from the received telemetry, persistent domain-centric relationship records that represent observed communication pairings between network sources and destinations, aggregated over an observation window, as first-class analytical objects independent of individual network flow events;

(d) storing the persistent domain-centric relationship records in a data structure logically separate from the received telemetry such that the relationship records persist independently of retention of the telemetry;

(e) establishing baseline relationship profiles based upon the persistent domain-centric relationship records, the baseline relationship profiles comprising structural connectivity representations of relationships between network sources and destinations independent of packet-level or flow-level metrics;

(f) comparing subsequently received network flow telemetry, via corresponding persistent relationship records, against the baseline relationship profiles to identify structural relationship deviations including at least one of,

(i) an emergence of a previously unobserved relationship,

(ii) a disappearance of a previously established relationship, or

(iii) a change in one or more structural attributes of a relationship; and

(g) reporting at least one of the domain-centric relationship records and the structural relationship deviations.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2026
From: CHERNICK, AUBREY GRANT, MR.
To: CELERIUM INC.
Reel/Frame 073585/0514 →
References Cited (10)
US 12353383B1 · Bao · 2025 [cited by examiner]
US 12598158B2 · Kaligotla · 2026 [cited by examiner]
US 20200334540A1 · Borra · 2020 [cited by examiner]
US 20220239634A1 · Woodberg · 2022 [cited by examiner]
US 20230076130A1 · Wen · 2023 [cited by examiner]
US 20230164043A1 · Sirov · 2023 [cited by examiner]
US 20240184857A1 · Volkovich · 2024 [cited by examiner]
US 20250286899A1 · Shriver · 2025 [cited by examiner]
US 20260075063A1 · Kulakowski · 2026 [cited by examiner]
US 20260081932A1 · Mohamed et al. · 2026 [cited by examiner]