US2009168648A1PendingUtilityA1

Method and System for Annotating Network Flow Information

Assignee: ARBOR NETWORKS INCPriority: Dec 29, 2007Filed: Dec 29, 2007Published: Jul 2, 2009
Est. expiryDec 29, 2027(~1.4 yrs left)· nominal 20-yr term from priority
H04L 41/12H04L 43/0876H04L 43/026Y02D30/50H04L 63/1408H04L 43/00
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A scalable flow monitoring solution takes in standard flow records exported from network devices such as routers, switches, firewalls, hubs, etc., and annotates the flow with additional information. This information is derived from a number of sources, including Border Gateway Protocol (BGP), Simple Network Management Protocol (SNMP), user configuration, and other, intelligent flow analysis. These annotations add information to the flow data, and can be used to perform value-added flow analysis. The annotated flow is then resent to a configurable set of destinations using standard flow formatting, e.g., Cisco System Inc.'s NetFlow, in one implementation. This allows the annotated flow to be processed and the enhanced information to be used by other flow analysis tools and existing flow analysis infrastructure.

Claims

exact text as granted — not AI-modified
1 . A method of processing network flow information, comprising:
 receiving a flow record exported from a network device; and   annotating the flow with additional information.   
   
   
       2 . The method of  claim 1 , wherein the network device is any of: a router, a switch, a firewall and a packet scanner/analyzer. 
   
   
       3 . The method of  claim 1 , further comprising sending the annotated flow to a configurable set of destinations. 
   
   
       4 . The method of  claim 1 , wherein the additional information is derived, at least in part, from a BGP source. 
   
   
       5 . The method of  claim 4  wherein source and destination addresses identified in the received flow record are looked up in BGP routing information and BGP attributes for the matching routes are added to the flow. 
   
   
       6 . The method of  claim 1 , wherein the additional information is derived, at least in part, from a SNMP source. 
   
   
       7 . The method of  claim 6  wherein the flow record is annotated with information describing interfaces which saw the flow, including interface name and description, and a unique identifier that maps into a database of additional interface information. 
   
   
       8 . The method of  claim 1 , wherein the additional information is derived, at least in part, from user configuration information. 
   
   
       9 . The method of  claim 8  wherein the flow record is annotated with information about traffic attributes which match user configuration. 
   
   
       10 . The method of  claim 1 , wherein the additional information is derived, at least in part, from raw packet analysis. 
   
   
       11 . The method of  claim 10  wherein the flow record is annotated with information derived from raw traffic. 
   
   
       12 . The method of  claim 11 , wherein the information about raw traffic comprises at least one of: an application identifier based on payload analysis; and VLAN identifiers. 
   
   
       13 . The method of  claim 1 , further comprising:
 performing flow analysis;   annotating the received flow record, based on the flow analysis, with at least one of network topology information and signature detection.   
   
   
       14 . The method of  claim 1 , wherein the method is performed in real-time. 
   
   
       15 . A flow annotator comprising:
 a flow analysis engine which receives flow data from a network device, and which selects information from at least one source to be added to the flow data; and   a flow encoding and distribution engine which annotates the flow data with the selected data to create an annotated flow, and which transmits the annotated flow to a configurable set of destinations comprising at least one of an additional flow annotator and a flow consumer.   
   
   
       16 . The flow annotator of  claim 15 , wherein the network device is any of: a router, a switch, a firewall and a packet scanner/analyzer. 
   
   
       17 . The flow annotator of  claim 15 , wherein the additional information is derived, at least in part, from a BGP source. 
   
   
       18 . The flow annotator of  claim 17  wherein source and destination addresses identified in the received flow record are looked up in BGP routing information and BGP attributes for the matching routes are added to the flow. 
   
   
       19 . The flow annotator of  claim 15 , wherein the additional information is derived, at least in part, from a SNMP source. 
   
   
       20 . The flow annotator of  claim 19 , wherein the flow record is annotated with information about interfaces which saw the flow, including interface name and description, and a unique identifier that maps into a database of additional interface information. 
   
   
       21 . The flow annotator of  claim 15 , wherein the additional information is derived, at least in part, from user configuration information. 
   
   
       22 . The flow annotator of  claim 21  wherein the flow record is annotated with information about traffic attributes which match user configuration. 
   
   
       23 . The flow annotator of  claim 15 , wherein the additional information is derived, at least in part, from raw packet analysis. 
   
   
       24 . The flow annotator of  claim 23  wherein the flow record is annotated with information derived from raw traffic. 
   
   
       25 . The flow annotator of  claim 24 , wherein the information about raw traffic comprises at least one of: an application identifier based on layer  4 - 7  payload analysis; and VLAN identifiers. 
   
   
       26 . The flow annotator of  claim 15 , wherein the received flow record is annotated, based on the flow analysis, with at least one of network topology information and signature detection. 
   
   
       27 . The flow annotator of  claim 15 , wherein flow analysis and annotation are performed in real-time.

Join the waitlist — get patent alerts

Track US2009168648A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.