US2021218638A1PendingUtilityA1

Automatic configuration discovery based on traffic flow data

Assignee: CISCO TECH INCPriority: Jan 25, 2018Filed: Mar 26, 2021Published: Jul 15, 2021
Est. expiryJan 25, 2038(~11.5 yrs left)· nominal 20-yr term from priority
H04L 41/0895H04L 41/12H04L 43/026H04L 41/0853H04L 43/12
57
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems, methods, and computer-readable media for flow stitching network traffic flow segments at a middlebox in a network environment. In some embodiments, flow records of traffic flow segments at a middlebox in a network environment are collected. The flow records can include transaction identifiers assigned to the traffic flow segments. Sources and destinations of the traffic flow segments with respect to the middlebox can be identified using the flow records. Further, the traffic flow segments can be stitched together to form a plurality of stitched traffic flows at the middlebox based on the transaction identifiers and the sources and destinations of the traffic flow segments in the network environment with respect to the middlebox. A configuration of the middlebox operating in the network environment can be identified based on the stitched traffic flows at the middlebox in the network environment.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 collecting flow records of traffic flow segments of traffic passing through a middlebox in a network environment, the flow records including transaction identifiers assigned to the traffic flow segments;   identifying whether the traffic flow segments originate at or end at the middlebox using the flow records;   stitching together the traffic flow segments about the middlebox, based on whether the traffic flow segments originate at or end at the middlebox and the transaction identifiers assigned to the traffic flow segments, to form a stitched traffic flow at the middlebox in the network environment; and   automatically identifying a configuration of the middlebox operating to perform operations on the traffic based on the stitched traffic flow.   
     
     
         2 . The method of  claim 1 , wherein the stitched traffic flow forms at least part of a cross-middlebox stitched traffic flow that passes through multiple middleboxes including the middlebox. 
     
     
         3 . The method of  claim 1 , further comprising:
 identifying a service type of a network service provisioned through the stitched traffic flow; and   identifying the configuration of the middlebox operating to perform operations on the traffic based on the service type.   
     
     
         4 . The method of  claim 3 , wherein the service type includes at least one of a web-based service, a databased service, and a storage service. 
     
     
         5 . The method of  claim 3 , wherein the service type is identified based on a specific server at which a traffic flow segment of the stitched traffic flow begins. 
     
     
         6 . The method of  claim 1 , further comprising:
 identifying the configuration of the middlebox as a load balancer; and   identifying a type of load balancer of the middlebox.   
     
     
         7 . The method of  claim 6 , further comprising:
 determining whether each subsequent outbound stitched traffic flow at the middlebox is destined from the middlebox to a different server from each previous outbound stitched traffic flow at the middlebox; and   identifying the configuration of the middlebox as a round-robin load balancing configuration if it is determined that each subsequent outbound stitched traffic flow at the middlebox is destined from the middlebox to a different server from each previous outbound stitched traffic flow.   
     
     
         8 . The method of  claim 6 , further comprising:
 determining whether each stitched traffic flow at the middlebox and originating from a specific client is destined to a same server; and   identifying the configuration of the middlebox as a persistent load balancing configuration if it is determined that each stitched traffic flow at the middlebox and originating from the specific client is destined to the same server.   
     
     
         9 . The method of  claim 1 , further comprising identifying specific ports of the middlebox that are used to transmit data associated with specific protocols as part of identifying the configuration of the middlebox. 
     
     
         10 . A system comprising:
 one or more processors; and   a computer-readable medium comprising instructions stored therein, which when executed by the one or more processors, cause the one or more processors to:
 collect flow records of traffic flow segments of traffic passing through a middlebox in a network environment, the flow records including transaction identifiers assigned to the traffic flow segments; 
 identify whether the traffic flow segments originate at or end at the middlebox using the flow records; 
 stitch together the traffic flow segments about the middlebox, based on whether the traffic flow segments originate at or end at the middlebox and the transaction identifiers assigned to the traffic flow segments, to form a stitched traffic flow at the middlebox in the network environment; and 
 automatically identify a configuration of the middlebox operating to perform operations on the traffic based on the stitched traffic flow. 
   
     
     
         11 . The system of  claim 10 , wherein the stitched traffic flow forms at least part of a cross-middlebox stitched traffic flow that passes through multiple middleboxes including the middlebox. 
     
     
         12 . The system of  claim 10 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to:
 identify a service type of a network service provisioned through the stitched traffic flow; and   identify the configuration of the middlebox operating to perform operations on the traffic based on the service type.   
     
     
         13 . The system of  claim 12 , wherein the service type includes at least one of a web-based service, a databased service, and a storage service. 
     
     
         14 . The system of  claim 12 , wherein the service type is identified based on a specific server at which a traffic flow segment of the stitched traffic flow begins. 
     
     
         15 . The system of  claim 10 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to:
 identify the configuration of the middlebox as a load balancer; and   identify a type of load balancer of the middlebox.   
     
     
         16 . The system of  claim 15 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to:
 determine whether each subsequent outbound stitched traffic flow at the middlebox is destined from the middlebox to a different server from each previous outbound stitched traffic flow at the middlebox; and   identify the configuration of the middlebox as a round-robin load balancing configuration if it is determined that each subsequent outbound stitched traffic flow at the middlebox is destined from the middlebox to a different server from each previous outbound stitched traffic flow.   
     
     
         17 . The system of  claim 15 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to:
 determine whether each stitched traffic flow at the middlebox and originating from a specific client is destined to a same server; and   identify the configuration of the middlebox as a persistent load balancing configuration if it is determined that each stitched traffic flow at the middlebox and originating from the specific client is destined to the same server.   
     
     
         18 . The system of  claim 10 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to identify specific ports of the middlebox that are used to transmit data associated with specific protocols as part of identifying the configuration of the middlebox. 
     
     
         19 . A non-transitory computer-readable storage medium comprising instructions stored therein, which when executed by one or more processors, cause the one or more processors to:
 collect flow records of traffic flow segments of traffic passing through a middlebox in a network environment, the flow records including transaction identifiers assigned to the traffic flow segments;   identify whether the traffic flow segments originate at or end at the middlebox using the flow records;   stitch together the traffic flow segments about the middlebox, based on whether the traffic flow segments originate at or end at the middlebox and the transaction identifiers assigned to the traffic flow segments, to form a stitched traffic flow at the middlebox in the network environment; and   automatically identify a configuration of the middlebox operating to perform operations on the traffic based on the stitched traffic flow.   
     
     
         20 . The non-transitory computer-readable storage medium of  claim 19 , wherein the instructions further cause the one or more processors to:
 identify a service type of a network service provisioned through the stitched traffic flow; and   identify the configuration of the middlebox operating to perform operations on the traffic based on the service type.

Join the waitlist — get patent alerts

Track US2021218638A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.