×

Hierarchical navigation through network flow data

  • US 10,728,109 B1
  • Filed: 03/15/2017
  • Issued: 07/28/2020
  • Est. Priority Date: 03/15/2017
  • Status: Active Grant
First Claim
Patent Images

1. A method for hierarchical navigation of network flow data, the method comprising:

  • receiving, over a network, network flow data describing communications between servers;

    receiving multi-dimensional labels for each of the different servers, wherein each multi-dimensional label comprises a set of values corresponding to a set of respective server dimensions, wherein a server dimension describes a characteristic of the server;

    annotating the network flow data with the multi-dimensional labels describing the servers associated with the communications;

    storing the annotated network flow data to a database;

    configuring a user interface to display the annotated network flow data from the database using a parallel coordinate graph having a plurality of axes, the configuring comprising;

    configuring the parallel coordinate graph to have a first axis associated with a first set of server dimensions of the multi-dimensional labels;

    identifying a first set of servers each having a first set of label values assigned to the first set of server dimensions associated with the first axis;

    representing the first set of servers as a first data point on the first axis;

    configuring the parallel coordinate graph to have a second axis associated with a second set of server dimensions of the multi-dimensional labels;

    identifying a second set of servers each having a second set of label values assigned to the second set of server dimensions associated with the second axis;

    representing the second set of servers as a second data point on the second axis;

    configuring the parallel coordinate graph to have a third axis associated with a third set of server dimensions of the multi-dimensional labels;

    identifying a third set of servers each having a third set of label values assigned to the third set of server dimensions associated with the third axis;

    representing the third set of servers as a third data point on the third axis;

    determining, based on the network flow data, if at least one of the first set of servers communicates with at least one of the second set servers;

    responsive to determining that at least one of the first set of servers communicates with at least one of the second set of servers, generating a representation of a connection between the first set of servers and the second set of servers as a line connecting the first data point on the first axis to the second data point on the second axis;

    determining, based on the network flow data, if a connection between at least one of the first set of servers and at least one of the third set servers is blocked by a domain wide administrative policy;

    responsive to that the connection is blocked, generating a representation of a blocked connection between the first set of servers and the third set of servers as a line connecting the first data point on the first axis to the third data point on the third axis that is visually distinguished from the line connecting the first data point to the second data point; and

    sending the configured user interface for display via a client device.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×