System for monitoring and managing datacenters

US10142353B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10142353-B2
Application numberUS-201615134100-A
CountryUS
Kind codeB2
Filing dateApr 20, 2016
Priority dateJun 5, 2015
Publication dateNov 27, 2018
Grant dateNov 27, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An example method includes detecting, using sensors, packets throughout a datacenter. The sensors can then send packet logs to various collectors which can then identify and summarize data flows in the datacenter. The collectors can then send flow logs to an analytics module which can identify the status of the datacenter and detect an attack.

First claim

Opening claim text (preview).

The invention claimed is: 1. A system within a datacenter, comprising: two or more sensors configured to: capture a packet; describe the packet in a packet log; send the packet log to a collector; the collector being configured to: receive the packet logs from the two or more sensors; determine that the packet logs describe a connection between two endpoints in a datacenter; describe the connection in a flow log; and an analytics module configured to: determine a status of the datacenter, using any connections in the flow log; detect an attack that originated from within the datacenter from at least the determined status of the datacenter; and modify, in response to the detected attack, a security policy of the datacenter. 2. The system of claim 1 , wherein one of the two or more sensors is installed on a hypervisor. 3. The system of claim 2 , wherein one of the two or more sensors is installed on a virtual machine. 4. The system of claim 1 , wherein one of the two or more sensors is installed on a switch. 5. The system of claim 1 , wherein access to the datacenter is limited by a firewall. 6. The system of claim 1 , wherein the analytics module is further configured to: present a report describing flows in the datacenter. 7. A method executed within a datacenter, comprising: receiving, a first packet log from a first sensor and a second packet log from a second sensor, the first packet log and the second packet log describing packets that are captured by the respective sensors; determining that the first packet log and the second packet log describes a connection between two endpoints in a datacenter; describing any connections within the first packet log and the second packet log in a flow log; and sending the flow log to an analytics module determining a status of the datacenter, using any connections in the flow log; detect an attack that originated from within the datacenter from at least the determined status of the datacenter; and modify, in response to the detected attack, a security policy of the datacenter. 8. The method of claim 7 , wherein the first sensor is installed on a hypervisor. 9. The method of claim 8 , wherein access to the datacenter is limited by a firewall. 10. The method of claim 7 , wherein the first sensor is installed on a switch. 11. The method of claim 7 , wherein the first sensor is installed on a virtual machine. 12. A non-transitory computer-readable medium having computer readable instructions stored thereon that, when executed by a processor of a computer, cause the computer to: receive, from a collector, a flow log describing a connection between two endpoints in a datacenter; and determine a status of a datacenter, using the flow log, using any connections in the flow log; detect an attack that originated from within the datacenter from at least the determined status of the datacenter; and modify, in response to the detected attack, a security policy of the datacenter. 13. The non-transitory computer-readable medium of claim 12 , wherein the instructions further cause the computer to: present a report describing flows in the datacenter. 14. The non-transitory computer-readable medium of claim 12 , wherein the instructions further cause the computer to: configure a sensor to send a packet log to the collector.

Assignees

Inventors

Classifications

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • for separating internal from external traffic, e.g. firewalls · CPC title

  • H04L43/04Primary

    Processing captured monitoring data, e.g. for logfile generation · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • related to network traffic · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10142353B2 cover?
An example method includes detecting, using sensors, packets throughout a datacenter. The sensors can then send packet logs to various collectors which can then identify and summarize data flows in the datacenter. The collectors can then send flow logs to an analytics module which can identify the status of the datacenter and detect an attack.
Who is the assignee on this patent?
Cisco Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1408. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Nov 27 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).