IP Library Granted Patent US 7,760,653
Granted Patent B2
US 7,760,653 · App. 10/974,386 · Granted Jul 20, 2010

Stackable aggregation for connection based anomaly detection

Assignee: Riverbed Technology, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,760,653
App. No.
10/974,386
Granted
Jul 20, 2010
Kind
B2
Abstract

A system includes a plurality of collector devices that are disposed to collect statistical information on packets that are sent between nodes on a network. The system also includes a stackable aggregator that receives network data from the plurality of collector devices, and which produces a connection table that maps each node on the network to a record that stores information about traffic to or from the node. The stackable aggregator includes a manager blade, a database blade, and two or more, analyzer blades.

Claims (39)

1. A system, comprising:

a plurality of collector devices that are disposed to collect statistical information on packets sent between nodes on a network;

a stackable aggregator that receives network data from the plurality of collector devices, the aggregator producing a connection table that maps each node on the network to a record that stores information about traffic to or from the node, the stackable aggregator comprising:

a manager blade,

a database blade, and

two or more analyzer blades.

2. The system of claim 1 wherein the manager blade includes an event manager to correlate and report events to an operator console.

3. The system of claim 2 wherein each analyzer blade is responsible for storing and analyzing approximately 1/N of network data, where N corresponds to number of analyzer blades in the aggregator.

4. The system of claim 1 wherein one of the analyzer blades, comprises:

a dispatcher that receives flow records and traffic counters from network sensors and forwards flow records and statistical data on network traffic to a specific one of the two or more analyzer blades.

5. The system of claim 4 wherein the dispatcher produces a hash of source and destination host identification values in the flow records or statistic records received, and uses the hash of the source and destination host identification values to distribute the flow records or statistic records to particular analyzer blades.

6. The system of claim 1 wherein each of the analyzer blades comprises:

local storage for storing flow records.

7. The system of claim 1 wherein each of the analyzer blades produces statistical data for its fraction of the network traffic.

8. The system of claim 2 wherein each of the analyzer blades examines statistical data to determine the presence of anomalies, and as anomalies are determined by the analyzer blades, data regarding the anomalies are forwarded to the event manager.

9. The system of claim 1 wherein each of the analyzer blades receives flow records from a dispatcher in the one of the analyzer blades comprising a dispatcher process.

10. The system of claim 1 wherein the database blade manages a database that stores the connection table.

11. The system of claim 10 wherein the connection table includes a plurality of records indexed by source address, destination address and time.

12. The system of claim 11 wherein the connection table includes a plurality of connection sub-tables to track data at different time scales.

13. The system of claim 1 wherein each analyzer blade of the aggregator includes:

at least two processors; and

memory associated with the at least two processors.

14. A method, comprises:

collecting statistical information on packets that are sent between nodes on a network;

dispatching statistical information via a reliable protocol to one of two or more analyzer blades in an aggregator to produce a connection table that maps each node on the network to a record that stores information about traffic to or from the node wherein the aggregator comprises a manager blade, a database blade, and the two or more analyzer blades.

15. The method of claim 14 wherein each analyzer blade is responsible for storing and analyzing approximately 1/N of network data, where N corresponds to a number of analyzer blades in the aggregator.

16. The method of claim 14 further comprising:

assembling flow records and traffic counters from network sensors; and

forwarding flow records and statistical data on network traffic to a specific one of two or more analyzer blades to assemble the connection table.

17. A non-transitory computer-readable storage device storing instructions that when executed by a computer cause the computer to:

receive network data from a plurality of collector devices that collect statistical information on packets that are sent between nodes on a network; and

dispatch received network data from a plurality of collector devices via a reliable protocol to a specific one of the two or more analyzer blades, in an aggregator to produce multiple connection tables each table storing a portion of the collect statistical information on packets sent on the network to a record wherein the aggregator comprises a manager blade, a database blade, and the two or more analyzer blades.

18. The storage device of claim 17 further comprising instructions cause a computer to: correlate and report events to an operator console.

19. The storage device of claim 17 further comprising instructions to cause a computer to:

hash source and destination host identification values in the flow records or statistic records received; and

distribute the flow records or statistic records to particular analyzer blades according to the hash of the source and destination host identification values.

20. The storage device of claim 18 further comprising instructions to cause a computer to:

examine statistical data to determine the presence of anomalies; and

forward anomalies to an event manager process.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2009
From: MAZU NETWORKS, LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 022542/0800 →
CHANGE OF NAME Recorded Mar 30, 2009
From: MAZU NETWORKS, INC.
To: MAZU NETWORKS, LLC
Reel/Frame 022460/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2004
From: POLETTO, MASSIMILIANO ANTONIO
To: MAZU NETWORKS, INC.
Reel/Frame 015935/0590 →
Continuity (1)
Related Publication 20060089985A1 · Apr 27, 2006