×

Correlating network traffic that crosses opaque endpoints

  • US 10,742,530 B1
  • Filed: 08/05/2019
  • Issued: 08/11/2020
  • Est. Priority Date: 08/05/2019
  • Status: Active Grant
First Claim
Patent Images

1. A method for monitoring network traffic using one or more network monitoring computers, comprising:

  • monitoring two or more network segments that are coupled by one or more bridge devices, wherein the one or more bridge devices modify network traffic passed from one network segment to another network segment;

    determining one or more flows in one or more network segments based on network traffic associated with the one or more network segments;

    determining one or more other flows in one or more other network segments based on other network traffic associated with the one or more other network segments;

    providing a correlation score for two or more flows that are in different network segments based on one or more of a correlation model, a characteristic of the one or more flows, or another characteristic of the one or more other flows;

    modifying one or more timing characteristics associated with the one or more flows in the one or more network segments;

    determining the one or more other flows in the one or more other network segments based on the one or more timing characteristics;

    updating the correlation score for the two or more flows based on the timing characteristics;

    determining two or more related flows based on a value of the correlation score of the two or more related flows, wherein the two or more related flows are located in different network segments; and

    providing a report that includes information about the two or more related flows.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×