Automatic configuration discovery based on traffic flow data
Abstract
Systems, methods, and computer-readable media for flow stitching network traffic flow segments at a middlebox in a network environment. In some embodiments, flow records of traffic flow segments at a middlebox in a network environment are collected. The flow records can include transaction identifiers assigned to the traffic flow segments. Sources and destinations of the traffic flow segments with respect to the middlebox can be identified using the flow records. Further, the traffic flow segments can be stitched together to form a plurality of stitched traffic flows at the middlebox based on the transaction identifiers and the sources and destinations of the traffic flow segments in the network environment with respect to the middlebox. A configuration of the middlebox operating in the network environment can be identified based on the stitched traffic flows at the middlebox in the network environment.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
collecting flow records of traffic flow segments of traffic passing through a middlebox in a network environment, the flow records including transaction identifiers assigned to the traffic flow segments; identifying whether the traffic flow segments originate at or end at the middlebox using the flow records; stitching together the traffic flow segments about the middlebox, based on whether the traffic flow segments originate at or end at the middlebox and the transaction identifiers assigned to the traffic flow segments, to form a stitched traffic flow at the middlebox in the network environment; and automatically identifying a configuration of the middlebox operating to perform operations on the traffic based on the stitched traffic flow.
2 . The method of claim 1 , wherein the stitched traffic flow forms at least part of a cross-middlebox stitched traffic flow that passes through multiple middleboxes including the middlebox.
3 . The method of claim 1 , further comprising:
identifying a service type of a network service provisioned through the stitched traffic flow; and identifying the configuration of the middlebox operating to perform operations on the traffic based on the service type.
4 . The method of claim 3 , wherein the service type includes at least one of a web-based service, a databased service, and a storage service.
5 . The method of claim 3 , wherein the service type is identified based on a specific server at which a traffic flow segment of the stitched traffic flow begins.
6 . The method of claim 1 , further comprising:
identifying the configuration of the middlebox as a load balancer; and identifying a type of load balancer of the middlebox.
7 . The method of claim 6 , further comprising:
determining whether each subsequent outbound stitched traffic flow at the middlebox is destined from the middlebox to a different server from each previous outbound stitched traffic flow at the middlebox; and identifying the configuration of the middlebox as a round-robin load balancing configuration if it is determined that each subsequent outbound stitched traffic flow at the middlebox is destined from the middlebox to a different server from each previous outbound stitched traffic flow.
8 . The method of claim 6 , further comprising:
determining whether each stitched traffic flow at the middlebox and originating from a specific client is destined to a same server; and identifying the configuration of the middlebox as a persistent load balancing configuration if it is determined that each stitched traffic flow at the middlebox and originating from the specific client is destined to the same server.
9 . The method of claim 1 , further comprising identifying specific ports of the middlebox that are used to transmit data associated with specific protocols as part of identifying the configuration of the middlebox.
10 . A system comprising:
one or more processors; and a computer-readable medium comprising instructions stored therein, which when executed by the one or more processors, cause the one or more processors to:
collect flow records of traffic flow segments of traffic passing through a middlebox in a network environment, the flow records including transaction identifiers assigned to the traffic flow segments;
identify whether the traffic flow segments originate at or end at the middlebox using the flow records;
stitch together the traffic flow segments about the middlebox, based on whether the traffic flow segments originate at or end at the middlebox and the transaction identifiers assigned to the traffic flow segments, to form a stitched traffic flow at the middlebox in the network environment; and
automatically identify a configuration of the middlebox operating to perform operations on the traffic based on the stitched traffic flow.
11 . The system of claim 10 , wherein the stitched traffic flow forms at least part of a cross-middlebox stitched traffic flow that passes through multiple middleboxes including the middlebox.
12 . The system of claim 10 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to:
identify a service type of a network service provisioned through the stitched traffic flow; and identify the configuration of the middlebox operating to perform operations on the traffic based on the service type.
13 . The system of claim 12 , wherein the service type includes at least one of a web-based service, a databased service, and a storage service.
14 . The system of claim 12 , wherein the service type is identified based on a specific server at which a traffic flow segment of the stitched traffic flow begins.
15 . The system of claim 10 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to:
identify the configuration of the middlebox as a load balancer; and identify a type of load balancer of the middlebox.
16 . The system of claim 15 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to:
determine whether each subsequent outbound stitched traffic flow at the middlebox is destined from the middlebox to a different server from each previous outbound stitched traffic flow at the middlebox; and identify the configuration of the middlebox as a round-robin load balancing configuration if it is determined that each subsequent outbound stitched traffic flow at the middlebox is destined from the middlebox to a different server from each previous outbound stitched traffic flow.
17 . The system of claim 15 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to:
determine whether each stitched traffic flow at the middlebox and originating from a specific client is destined to a same server; and identify the configuration of the middlebox as a persistent load balancing configuration if it is determined that each stitched traffic flow at the middlebox and originating from the specific client is destined to the same server.
18 . The system of claim 10 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to identify specific ports of the middlebox that are used to transmit data associated with specific protocols as part of identifying the configuration of the middlebox.
19 . A non-transitory computer-readable storage medium comprising instructions stored therein, which when executed by one or more processors, cause the one or more processors to:
collect flow records of traffic flow segments of traffic passing through a middlebox in a network environment, the flow records including transaction identifiers assigned to the traffic flow segments; identify whether the traffic flow segments originate at or end at the middlebox using the flow records; stitch together the traffic flow segments about the middlebox, based on whether the traffic flow segments originate at or end at the middlebox and the transaction identifiers assigned to the traffic flow segments, to form a stitched traffic flow at the middlebox in the network environment; and automatically identify a configuration of the middlebox operating to perform operations on the traffic based on the stitched traffic flow.
20 . The non-transitory computer-readable storage medium of claim 19 , wherein the instructions further cause the one or more processors to:
identify a service type of a network service provisioned through the stitched traffic flow; and identify the configuration of the middlebox operating to perform operations on the traffic based on the service type.Join the waitlist — get patent alerts
Track US2021218638A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.