×

Methods and systems for identifying data sessions at a VPN gateway

  • US 9,674,316 B2
  • Filed: 03/27/2014
  • Issued: 06/06/2017
  • Est. Priority Date: 03/27/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method for identifying Internet Protocol (IP) data sessions at a VPN gateway comprising:

  • (a) receiving encapsulating packets, wherein the encapsulating packets encapsulate IP packets;

    (b) identifying a corresponding VPN connection;

    (c) decapsulating encapsulating packets to retrieve IP packets;

    (d) performing deep packet inspection (DPI) on the IP packets to identify one or more data sessions the IP packets belong to; and

    (e) updating a DPI database based, at least in part, on the one or more data sessions;

    wherein the DPI database comprises information corresponding to the one or more data sessions, wherein the information comprises source IP address, destination IP address, starting time, application, protocol, user identity, source port, destination port, security information, VPN connection information, computing resource usage, bandwidth usage and statistical information, wherein statistical information comprises network performance of a VPN connection, number of data sessions, duration of data sessions, and monetary cost of data sessions;

    (f) displaying information corresponding to the one or more data sessions at a user interface, wherein the information is retrieved from the DPI database;

    wherein the user interface comprises a plurality of items, wherein the items are selected from a group consisting of au IP address of a node, application, protocol of an encapsulating packet or IP packet, a policy, a location of an IP address, performance range through a network interface, range of size of data being downloaded or uploaded, and a user-identity;

    wherein the information displayed at the user interface comprises correlation between the plurality of items;

    wherein the plurality of items are categorized and displayed according to a plurality of categories;

    wherein a specific correlation is indicated to a user by changing a line color of a line representing the specific correlation or by flashing the line representing the specific correlation.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×