System and related method for network monitoring and control based on applications
Abstract
A network architecture system that expands the control network administrators have on existing networks. The system provides application identification and usage data, by user, by device and network location. Dynamic traffic mirroring of the system allows for the efficient use of a tool to identify computer applications running on the network. The system includes the ability to embed the tool where needed rather than pervasively based on the use of the dynamic mirroring to bring the packets to the tool. The architecture implemented functions allow the ability to start small with a single application identification tool added to a network management server, examine flows from throughout the network (via mirroring) and upgrade policy control based on real application identification data and usage, then grow to pervasive deployment where virtually all new flows could be identified and controlled via policy. This architecture enables substantially complete application visibility and control.
Claims
exact text as granted — not AI-modified1 .- 15 . (canceled)
16 . A method for controlling the operation of a network system including a plurality of network infrastructure devices, wherein the plurality of network infrastructure devices includes one or more packet forwarding devices, the method comprising the steps of:
a. mirroring one or more frames received at one or more of the one or more packet forwarding devices to another device of the network infrastructure; b. examining the mirrored one or more frames for one or more indications of one or more computer applications running on the one or more packet forwarding devices receiving the one or more frames mirrored for examination; c. comparing the one or more indications of the examined one or more mirrored frames to one or more computer application indicators of an application identification database; and d. identifying one or more computer applications running on the network system based on the comparing.
17 . The method of claim 16 wherein the examining and comparing steps are carried out in a single device of the plurality of network infrastructure devices.
18 . The method of claim 16 further comprising as part of the step of comparing, the step of scoring a plurality of the indications and weighting the score based on indicators to determine specific computer applications running on the network system.
19 . A network system comprising:
a. a plurality of packet forwarding devices including one or more packet forwarding devices that are arranged in the network system for receiving packets from one or more attached functions, wherein the one or more packet forwarding devices are configured to forward packets of the network system, wherein at least one of the one or more packet forwarding devices is configured to mirror frames of received packets; and b. a device for identifying one or more computer applications running or attempting to run on the network system, the device comprising a scoring analysis engine configured to:
i. receive frames mirrored from the at least one of the one or more packet forwarding devices, wherein the mirrored frames include information indicative of one or more computer applications;
ii. compare the received information of the mirrored frames with information of a computer applications identification database, wherein the information of the database includes information about a plurality of computer applications;
iii. designate one of the computer applications as being associated with the mirrored frames based on the comparison.
20 . The system of claim 19 wherein the designation of the one of the computer applications includes an indication of the confidence in the designation.
21 . The method of claim 16 wherein the step of mirroring one or more frames includes mirroring selectable ones of the one or more frames based on one or more criteria.
22 . The method of claim 21 wherein the one or more criteria include one or more of:
a. a first criterion for selecting one or more received frames for mirroring;
b. a second criterion for selecting one or more portions of the frames for mirroring;
c. a third criterion for selecting one or more portals through which to mirror the frames;
d. a fourth criterion for where to mirror the frames; and
e. a fifth criterion for selecting at least one of the one or more packet forwarding devices within which to configure a mirror for mirroring frames of its received packets.
23 . The method of claim 16 further comprising the step of adjusting the mirroring of the one or more received frames to be examined based on information associated with the network system.
24 . The system of claim 19 wherein the device is selected from:
a. one or more application identification engines;
b. one or more intrusion detection systems;
c. one or more network loggers;
d. one or more policy servers; and
e. one or more network management monitors.
25 . The system of claim 19 wherein the device is further configured to establish a score for each computer application likely to match the information of the mirrored frames.
26 . A network system comprising:
a. a plurality of packet forwarding devices including one or more packet forwarding devices that are arranged in the network system as network entry devices for receiving packets from one or more attached functions, wherein the one or more packet forwarding devices are configured to forward packets of the network system; b. one or more flow monitoring devices configured to examine and/or log information associated with flows of the network system, wherein at least one of the one or more packet forwarding devices is configured to mirror frames of received packets to at least one of the one or more flow monitoring devices; and c. a manager function of the network system configured to adjust mirroring actions of the at least one of the one or more packet forwarding devices based on information received from the one or more flow monitoring devices or other information.
27 . The system of claim 26 wherein the manager function is located within the flow monitoring device.
28 . The system of claim 26 wherein the manager function is further configured to select one or more of the one or more packet forwarding devices to mirror flows or portions of flows to the at least one of the one or more flow monitoring devices or another device of the network system.
29 . The system of claim 26 wherein the manager function is configured to do one or more of:
a. change a mirror,
b. stop a mirroring activity;
c. initiate mirroring of a flow of another packet forwarding device to the same or a different monitoring device;
d. change either or both of mirroring and monitoring activities based on one or more events associated with the network system;
e. determine a source of a flow;
f. determine a source of a response in a flow; and
g. determine a source network entry device of a response flow.
30 . The system of claim 26 wherein the one or more flow monitoring devices is selected from:
a. one or more application identification engines;
b. one or more intrusion detection systems;
c. one or more network loggers; and
d. one or more network management monitors.
31 . The system of claim 30 wherein at least one of the one or more flow monitoring devices is configured to identify computer applications running on the network system.
32 . The system of claim 31 wherein the at least one of the one or more flow monitoring devices is configured to examine one or more frames and other information mirrored to it from the one or more of the one or more packet forwarding devices for information associated with one or more computer applications and output to the manager function one or more indications of the computer application associated with the examined one or more frames.
33 . The system of claim 26 further comprising a traffic mirroring function configured to establish one or more portals for mirroring selectable ones of the frames of the received packets to the application identification engine based on one or more criteria.
34 . The system of claim 33 wherein the one or more criteria include one or more of:
a. a first criterion for selecting one or more received frames for mirroring;
b. a second criterion for selecting one or more portions of the frames for mirroring;
c. a third criterion for selecting one or more portals through which to mirror the frames;
d. a fourth criterion for where to mirror the frames; and
e. a fifth criterion for selecting at least one of the one or more packet forwarding devices within which to configure a mirror for mirroring frames of its received packets.
35 . The system of claim 26 wherein the manager function is in a policy server of the network system.Join the waitlist — get patent alerts
Track US2016191568A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.