Augmenting flow data for improved network monitoring and management

  • US 10,177,998 B2
  • Filed: 06/03/2016
  • Issued: 01/08/2019
  • Est. Priority Date: 06/05/2015
  • Status: Active Grant
  • ×
    • Pin
First Claim
Patent Images

1. A method comprising:

  • capturing one or more packet header attributes for a first flow using a plurality of sensors that includes at least a first sensor of one of a source endpoint or a destination endpoint of the first flow and one or more second sensors of one or more networking devices along a path of the first flow;

    determining one or more additional attributes of the first flow using at least the first sensor, the one or more additional attributes including at least one of a host attribute, a virtualization attribute, a process attribute, or a user attribute of the first flow;

    normalizing at least one of the one or more additional attributes by calculating a term frequency-inverse document frequency of the at least one of the one or more additional attributes;

    calculating a first feature vector that includes at least the one or more packet header attributes and the one or more additional attributes including the at least one normalized attribute;

    determining a policy for the first flow based at least in part on a similarity between the first feature vector and a second feature vector of a second flow, the second feature vector being features or attributes of the second flow; and

    applying the policy to one or more third flows that are considered similar to the first flow based on second predefined criteria.

View all claims
    ×
    ×

    Thank you for your feedback

    ×
    ×