IP Library Granted Patent US 9,787,556
Granted Patent B2
US 9,787,556 · App. 14/580,138 · Granted Oct 10, 2017

Apparatus, system, and method for enhanced monitoring, searching, and visualization of network data

Inventor: Rony Kay (Cupertino, CA)
Assignee: cPacket Networks Inc.
H04L43/045H04L41/0613H04L43/028H04L43/062H04L67/22H04L67/32H04L43/026H04L43/04H04L43/0852H04L43/0888H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,787,556
App. No.
14/580,138
Granted
Oct 10, 2017
Kind
B2
Abstract

A system for monitoring and visualization of network data includes a plurality of first devices and a second device coupled to the plurality of first devices over a network. Each first device is associated with corresponding ones of a plurality of ports. Each first device is configured to determine network traffic analysis information associated with a characteristic of network data traversing each of the ports, and to push the network traffic analysis information across a network independent of a solicitation from the network. The second device is configured to generate a map of the network including a visual indicator based on the network traffic analysis information, to receive an update of the network traffic analysis information from at least one of the first devices, and to refresh the visual indicator in real time to reflect the update of the network traffic analysis information.

Claims (33)

1. A system for monitoring and visualization of network data, comprising:

a plurality of first devices, each of the plurality of first devices comprising a processor being associated with corresponding ones of a plurality of ports, each of the plurality of first devices being configured to determine network traffic analysis information associated with a characteristic of network data traversing each of the plurality of ports, and to push the network traffic analysis information across a network independent of a solicitation from the network; and

a second device coupled to the plurality of first devices over the network, the second device comprising a processor being configured to generate a map of the network including a visual indicator based on the network traffic analysis information, to receive an update of the network traffic analysis information from at least one of the plurality of first devices, and to refresh the visual indicator in real time to reflect the update of the network traffic analysis information; wherein

each of the plurality of first devices is configured to determine statistical data over each of a plurality of time intervals of a first time granularity based on the network data; and

the statistical data reduces the volume of the network traffic analysis information; and

each of the plurality of first devices is configured to determine the network traffic analysis information based on performance of a mathematical operation on the statistical data, wherein the network traffic analysis information is associated with each of a plurality of time intervals of a second time granularity, the first time granularity being finer than the second time granularity.

2. The system of claim 1 , wherein the visual indicator is based on a number of times that the characteristic has been detected in the network data over a time interval.

3. The system of claim 2 , wherein the characteristic is indicated based on an occurrence of a bit pattern in the network data.

4. The system of claim 2 , wherein the characteristic is indicated based on an occurrence of a pattern of variation in a data rate associated with the network data.

5. The system of claim 1 , wherein each of the plurality of first devices is configured to determine the network traffic analysis information based on application of at least one of a signature-based rule and a behavioral rule to the network data.

6. The system of claim 1 , wherein the mathematical operation includes at least one of a minimum, a maximum, and an average.

7. The system of claim 1 , wherein:

the network traffic analysis information includes a maximum of the statistical data over each of the plurality of time intervals of the second time granularity; and

the characteristic of the network data is indicated by the maximum of the statistical data over at least one of the plurality of time intervals of the second time granularity substantially exceeding the average of the statistical data over the at least one of the plurality of time intervals of the second time granularity.

8. The system of claim 1 , wherein each of the plurality of first devices is configured to determine the network traffic analysis information based on performance of a mathematical operation on at least one of statistics and rule-based information associated with the network data, wherein the mathematical operation includes at least one of a convolution, a moving average, a sum of squares, a linear filtering operation, and a nonlinear filtering operation.

9. The system of claim 8 , wherein the visual indicator is based on a result of the mathematical operation on the network data.

10. The system of claim 1 , wherein each of the plurality of first devices is configured to generate an alert indication associated with the corresponding ones of the plurality of ports based on detection of the characteristic in the network data traversing the corresponding ones of the plurality of ports by each of the plurality of first devices.

11. The system of claim 10 , wherein the visual indicator is based on whether the alert indication is present for each of the plurality of ports.

12. The system of claim 1 , wherein the solicitation is a poll from the second device.

13. A system for monitoring and visualization of network data, comprising:

a first device comprising a processor; and

a plurality of second devices coupled to the first device, each of the plurality of second devices comprising a processor being associated with corresponding ones of a plurality of ports, each of the plurality of second devices being configured to determine network traffic analysis information associated with a characteristic of network data traversing each of the plurality of ports in response to a communication from the first device;

the first device being configured to receive a search request implicating the characteristic, to generate the communication based on the search request, to generate a network map including a visual indicator based on the network traffic analysis information, to receive an update of the network traffic analysis information from at least one of the plurality of second devices, and to refresh the visual indicator in real time to reflect the update of the network traffic analysis information: wherein

each of the plurality of first devices is configured to determine statistical data over each of a plurality of time intervals of a first time granularity based on the network data; and

the statistical data reduces the volume of the network traffic analysis information; and

each of the plurality of first devices is configured to determine the network traffic analysis information based on performance of a mathematical operation on the statistical data, wherein the network traffic analysis information is associated with each of a plurality of time intervals of a second time granularity, the first time granularity being finer than the second time granularity.

14. The system of claim 13 , wherein each of the plurality of second devices is configured to apply at least one of a signature-based rule and a behavioral rule to the network data to determine the network traffic analysis information in response to the communication from the first device based on the search request.

15. The system of claim 13 , wherein the visual indicator is based on a number of times that the characteristic has been detected in the network data over a time interval.

16. The system of claim 15 , wherein the characteristic is indicated based on at least one of an occurrence of a bit pattern in the network data and an occurrence of a pattern of variation in a data rate associated with the network data.

17. The system of claim 13 , wherein:

the first device is coupled to the plurality of second devices over a network; and

each of the plurality of second devices is configured to push the network traffic analysis information across a network independent of a solicitation from the network.

18. The system of claim 13 , wherein each of the plurality of second devices is configured to generate an alert indication associated with the corresponding ones of the plurality of ports based on detection of the characteristic in the network data traversing the corresponding ones of the plurality of ports by each of the plurality of second devices.

Assignments (9)
SECURITY INTEREST Recorded Jan 31, 2024
From: CPACKET NETWORKS INC.
To: TRINITY CAPITAL INC., AS COLLATERAL AGENT
Reel/Frame 066313/0479 →
RELEASE OF SECURITY INTEREST Recorded Jan 30, 2024
From: NH EXPANSION CREDIT FUND HOLDINGS LP
To: CPACKET NETWORKS INC.
Reel/Frame 066296/0675 →
SECURITY INTEREST Recorded Apr 17, 2020
From: CPACKET NETWORKS INC.
To: WESTERN ALLIANCE BANK
Reel/Frame 052424/0412 →
RELEASE OF SECURITY INTEREST Recorded Nov 7, 2019
From: PARTNERS FOR GROWTH V, L.P.
To: CPACKET NETWORKS INC.
Reel/Frame 050953/0721 →
SECURITY INTEREST Recorded Nov 5, 2019
From: CPACKET NETWORKS, INC.
To: NH EXPANSION CREDIT FUND HOLDINGS LP
Reel/Frame 050924/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 18, 2019
From: SILICON VALLEY BANK
To: CPACKET NETWORKS INC.
Reel/Frame 050764/0597 →
SECURITY INTEREST Recorded Oct 27, 2017
From: CPACKET NETWORKS INC.
To: PARTNERS FOR GROWTH V, L.P.
Reel/Frame 043975/0953 →
SECURITY INTEREST Recorded Mar 22, 2017
From: CPACKET NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 041685/0251 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2014
From: KAY, RONY
To: CPACKET NETWORKS INC.
Reel/Frame 034572/0507 →
Continuity (2)
Provisional Application 61924653 · Jan 7, 2014
Related Publication 20150244594A1 · Aug 27, 2015