IP Library Granted Patent US 9,660,879
Granted Patent B1
US 9,660,879 · App. 15/219,016 · Granted May 23, 2017

Flow deduplication across a cluster of network monitoring devices

Inventors: Jesse Abraham Rothstein (Seattle, WA); Kevin Michael Seguin (Seattle, WA); William Henry Mortensen (Seattle, WA); Alexander Christian Leone (Seattle, WA)
Assignee: ExtraHop Networks, Inc.
H04L43/026H04L67/28H04L69/161H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,660,879
App. No.
15/219,016
Granted
May 23, 2017
Kind
B1
Abstract

Embodiments are directed to monitoring flows of packets over a network. If a network monitoring computer (NMC) in a cluster of NMCs observes a new network flow, the NMC may perform a variety of actions to determine the NMC that is responsible for monitoring the new network flow. Network traffic associated with the new network flow may be buffered in a non-transitory processor readable media. The new network flow may be registered with the plurality of NMCs, providing an identifier that corresponds to one NMC. Registering may include, assigning the NMC a responsibility to monitor the new network flow. If the identifier corresponds to the NMC that observed the new network flow, the network traffic associated with the new network flow is processed using that NMC. If the identifier corresponds to another NMC, the buffered network traffic is forwarded to the other NMC.

Claims (60)

1. A method for monitoring flows of packets over a network, wherein one or more processors in a network computer execute instructions to perform actions, comprising:

employing a network monitoring computer (NMC) in a plurality of NMCs, that is provided a new network flow, to perform further actions, including:

buffering network traffic information associated with the new network flow in a non-transitory processor readable media;

registering the new network flow with the plurality of NMCs, wherein registration provides an identifier that corresponds to one or more of the plurality of NMCs and provides an indication that the one or more NMCs that correspond to the identifier have registered an interest in one or more network flows that are related to the new network flow;

forwarding network traffic information that is associated with the one or more related network flows to the one or more NMCs that correspond to the identifier;

employing the identifier, which corresponds to the NMC that was provided the new network flow, to process network traffic associated with the new network flow using the NMC that was provided the new network flow; and

employing the identifier, which corresponds to another NMC, to forward the buffered network traffic information to the other NMC.

2. The method of claim 1 , wherein registering the new network flow with the plurality of NMCs, further comprises, assigning the one or more NMCs to monitor the new network flow, wherein the one or more NMCs correspond to the identifier.

3. The method of claim 1 , further comprising, when a provided network flow is absent from a network flow table of the NMC, classifying the provided network flow is the new network flow.

4. The method of claim 1 , wherein registering the new network flow with the plurality of NMCs, further comprises providing the identifier based on a hashing of some or all of the tuple information that is associated with the new network flow.

5. The method of claim 1 , further comprising, storing information associated with the new network flow in a network flow table, wherein the information includes, one or more of tuple information, the identifier, or a timeout value.

6. The method of claim 1 , wherein registering the new network flow with the plurality of NMCs, further comprises, providing the identifier based on an execution of one or more defined static policies.

7. A system for monitoring flows of packets over a network comprising:

a network computer, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

employing a network monitoring computer (NMC) in a plurality of NMCs, that is provided a new network flow, to perform further actions, including:

buffering network traffic information associated with the new network flow in a non-transitory processor readable media;

registering the new network flow with the plurality of NMCs, wherein registration provides an identifier that corresponds to one or more of the plurality of NMCs and provides an indication that the one or more NMCs that correspond to the identifier have registered an interest in one or more network flows that are related to the new network flow;

forwarding network traffic information that is associated with the one or more related network flows to the one or more NMCs that correspond to the identifier;

employing the identifier, which corresponds to the NMC that was provided the new network flow, to process network traffic associated with the new network flow using the NMC that was provided the new network flow; and

employing the identifier, which corresponds to another NMC, to forward the buffered network traffic information to the other NMC; and

a client computer, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing the new network flow to the NMC in the plurality of NMCs.

8. The system of claim 7 , wherein registering the new network flow with the plurality of NMCs, further comprises, assigning the one or more NMCs to monitor the new network flow, wherein the one or more NMCs correspond to the identifier.

9. The system of claim 7 , further comprising, when a provided network flow is absent from a network flow table of the NMC, classifying the provided network flow is the new network flow.

10. The system of claim 7 , wherein registering the new network flow with the plurality of NMCs, further comprises, providing the identifier based on a hashing of some or all of the tuple information that is associated with the new network flow.

11. The system of claim 7 , further comprising, storing information associated with the new network flow in a network flow table, wherein the information includes, one or more of tuple information, the identifier, or a timeout value.

12. The system of claim 7 , wherein registering the new network flow with the plurality of NMCs, further comprises, providing the identifier based on an execution of one or more defined static policies.

13. A processor readable non-transitory storage media that includes instructions for monitoring flows of packets over a network, wherein execution of the instructions by one or more processors performs actions, comprising:

employing a network monitoring computer (NMC) in a plurality of NMCs, that is provided a new network flow, to perform further actions, including:

buffering network traffic information associated with the new network flow in a non-transitory processor readable media;

registering the new network flow with the plurality of NMCs, wherein registration provides an identifier that corresponds to one or more of the plurality of NMCs and provides an indication that the one or more NMCs that correspond to the identifier have registered an interest in one or more network flows that are related to the new network flow;

forwarding network traffic information that is associated with the one or more related network flows to the one or more NMCs that correspond to the identifier;

employing the identifier, which corresponds to the NMC that was provided the new network flow, to process network traffic associated with the new network flow using the NMC that was provided the new network flow; and

employing the identifier, which corresponds to another NMC, to forward the buffered network traffic information to the other NMC.

14. The media of claim 13 , wherein registering the new network flow with the plurality of NMCs, further comprises, assigning the one or more NMCs to monitor the new network flow, wherein the one or more NMCs correspond to the identifier.

15. The media of claim 13 , further comprising, when a provided network flow is absent from a network flow table of the NMC, classifying the provided network flow is the new network flow.

16. The media of claim 13 , wherein registering the new network flow with the plurality of NMCs, further comprises, providing the identifier based on a hashing of some or all of the tuple information that is associated with the new network flow.

17. The media of claim 13 , further comprising, storing information associated with the new network flow in a network flow table, wherein the information includes, one or more of tuple information, the identifier, or a timeout value.

18. The media of claim 13 , wherein registering the new network flow with the plurality of NMCs, further comprises, providing the identifier based on an execution of one or more defined static policies.

19. A network computer for monitoring flows of packets over a network, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

employing a network monitoring computer (NMC) in a plurality of NMCs, that is provided a new network flow, to perform further actions, including:

buffering network traffic information associated with the new network flow in a non-transitory processor readable media;

registering the new network flow with the plurality of NMCs, wherein registration provides an identifier that corresponds to one or more of the plurality of NMCs and provides an indication that the one or more NMCs that correspond to the identifier have registered an interest in one or more network flows that are related to the new network flow;

forwarding network traffic information that is associated with the one or more related network flows to the one or more NMCs that correspond to the identifier;

employing the identifier, which corresponds to the NMC that was provided the new network flow, to process network traffic associated with the new network flow using the NMC that was provided the new network flow; and

employing the identifier, which corresponds to another NMC, to forward the buffered network traffic information to the other NMC.

20. The network computer of claim 19 , wherein registering the new network flow with the plurality of NMCs, further comprises, assigning the one or more NMCs to monitor the new network flow, wherein the one or more NMCs correspond to the identifier.

21. The network computer of claim 19 , further comprising, when a provided network flow is absent from a network flow table of the NMC, classifying the provided network flow is the new network flow.

22. The network computer of claim 19 , wherein registering the new network flow with the plurality of NMCs, further comprises, providing the identifier based on a hashing of some or all of the tuple information that is associated with the new network flow.

23. The network computer of claim 19 , further comprising, storing information associated with the new network flow in a network flow table, wherein the information includes, one or more of tuple information, the identifier, or a timeout value.

24. The network computer of claim 19 , wherein registering the new network flow with the plurality of NMCs, further comprises, providing the identifier based on an execution of one or more defined static policies.

Assignments (6)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0488 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0530 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 053756/0739 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK, AS AGENT
Reel/Frame 053756/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2016
From: ROTHSTEIN, JESSE ABRAHAM; SEGUIN, KEVIN MICHAEL; MORTENSEN, WILLIAM HENRY; LEONE, ALEXANDER CHRISTIAN
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 039461/0324 →