Method and System for Annotating Network Flow Information
Abstract
A scalable flow monitoring solution takes in standard flow records exported from network devices such as routers, switches, firewalls, hubs, etc., and annotates the flow with additional information. This information is derived from a number of sources, including Border Gateway Protocol (BGP), Simple Network Management Protocol (SNMP), user configuration, and other, intelligent flow analysis. These annotations add information to the flow data, and can be used to perform value-added flow analysis. The annotated flow is then resent to a configurable set of destinations using standard flow formatting, e.g., Cisco System Inc.'s NetFlow, in one implementation. This allows the annotated flow to be processed and the enhanced information to be used by other flow analysis tools and existing flow analysis infrastructure.
Claims
exact text as granted — not AI-modified1 . A method of processing network flow information, comprising:
receiving a flow record exported from a network device; and annotating the flow with additional information.
2 . The method of claim 1 , wherein the network device is any of: a router, a switch, a firewall and a packet scanner/analyzer.
3 . The method of claim 1 , further comprising sending the annotated flow to a configurable set of destinations.
4 . The method of claim 1 , wherein the additional information is derived, at least in part, from a BGP source.
5 . The method of claim 4 wherein source and destination addresses identified in the received flow record are looked up in BGP routing information and BGP attributes for the matching routes are added to the flow.
6 . The method of claim 1 , wherein the additional information is derived, at least in part, from a SNMP source.
7 . The method of claim 6 wherein the flow record is annotated with information describing interfaces which saw the flow, including interface name and description, and a unique identifier that maps into a database of additional interface information.
8 . The method of claim 1 , wherein the additional information is derived, at least in part, from user configuration information.
9 . The method of claim 8 wherein the flow record is annotated with information about traffic attributes which match user configuration.
10 . The method of claim 1 , wherein the additional information is derived, at least in part, from raw packet analysis.
11 . The method of claim 10 wherein the flow record is annotated with information derived from raw traffic.
12 . The method of claim 11 , wherein the information about raw traffic comprises at least one of: an application identifier based on payload analysis; and VLAN identifiers.
13 . The method of claim 1 , further comprising:
performing flow analysis; annotating the received flow record, based on the flow analysis, with at least one of network topology information and signature detection.
14 . The method of claim 1 , wherein the method is performed in real-time.
15 . A flow annotator comprising:
a flow analysis engine which receives flow data from a network device, and which selects information from at least one source to be added to the flow data; and a flow encoding and distribution engine which annotates the flow data with the selected data to create an annotated flow, and which transmits the annotated flow to a configurable set of destinations comprising at least one of an additional flow annotator and a flow consumer.
16 . The flow annotator of claim 15 , wherein the network device is any of: a router, a switch, a firewall and a packet scanner/analyzer.
17 . The flow annotator of claim 15 , wherein the additional information is derived, at least in part, from a BGP source.
18 . The flow annotator of claim 17 wherein source and destination addresses identified in the received flow record are looked up in BGP routing information and BGP attributes for the matching routes are added to the flow.
19 . The flow annotator of claim 15 , wherein the additional information is derived, at least in part, from a SNMP source.
20 . The flow annotator of claim 19 , wherein the flow record is annotated with information about interfaces which saw the flow, including interface name and description, and a unique identifier that maps into a database of additional interface information.
21 . The flow annotator of claim 15 , wherein the additional information is derived, at least in part, from user configuration information.
22 . The flow annotator of claim 21 wherein the flow record is annotated with information about traffic attributes which match user configuration.
23 . The flow annotator of claim 15 , wherein the additional information is derived, at least in part, from raw packet analysis.
24 . The flow annotator of claim 23 wherein the flow record is annotated with information derived from raw traffic.
25 . The flow annotator of claim 24 , wherein the information about raw traffic comprises at least one of: an application identifier based on layer 4 - 7 payload analysis; and VLAN identifiers.
26 . The flow annotator of claim 15 , wherein the received flow record is annotated, based on the flow analysis, with at least one of network topology information and signature detection.
27 . The flow annotator of claim 15 , wherein flow analysis and annotation are performed in real-time.Join the waitlist — get patent alerts
Track US2009168648A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.