Monitoring network traffic to determine similar content

US10437829B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10437829-B2
Application numberUS-201615149741-A
CountryUS
Kind codeB2
Filing dateMay 9, 2016
Priority dateMay 9, 2016
Publication dateOct 8, 2019
Grant dateOct 8, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In an embodiment, a method monitors a plurality of data streams passing through a router in the connectivity service provider environment, and for each of the data streams, periodically samples packets at the router. The method further generates a stream signature based at least on the payload of the sampled packets. The method further includes, for each generated stream signature, attaching information to the stream signature. Such information may, for example, include time-stamp information for the stream signature, or an identification of the router. The method may further comprise storing the stream signatures corresponding to the data streams in a database. The stored stream signatures may be compared to determine matching stream signatures. Matching signatures may identify data streams that carry identical or similar content.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for identifying similar data streams in a connectivity service provider environment, the method comprising: monitoring a plurality of data streams relayed through a plurality of routers in the connectivity service provider environment; for each data stream in the plurality of data streams: periodically sampling received packets at the router; filtering the sampled packets to exclude packets out of chronological order; and generating a stream signature based at least on a payload of the filtered packets received at the router; for each generated stream signature: attaching time-stamp information to the stream signature; and attaching to the stream signature an identification of the router at which the filtered packets used to generate the stream signature were received; storing the generated stream signatures corresponding to the plurality of data streams in a database; determining, based on a plurality of stream signatures in the database and the identification of the router for each of the plurality of stream signatures, that a first data stream relayed through a first router is similar to a second data stream relayed through a second router; and rerouting, based on the determining, at least the first data stream within the connectivity service provider environment; wherein the filtering comprises discarding at least one received sampled packet based on a determination that a stream signature corresponding to the data stream does not change from its previous value after incorporating the at least one received sampled packet in the generated stream signature. 2. The method of claim 1 , wherein the stream signature is generated further based at least on source and destination address information of the filtered packets. 3. The method of claim 1 , wherein the sampling is performed on a pre-determined number of data streams with highest data rates among the plurality of data streams. 4. The method of claim 3 , wherein for each data stream, the stream signature is generated further based on statistical information about the data stream over a pre-determined period of time, the statistical information comprising at least one of mean of data rate, variance of data rate, skewness of data rate, minimum data rate, and maximum data rate. 5. The method of claim 1 , wherein for each data stream the stream signature is generated based at least on a total amount of data relayed within a pre-determined period of time. 6. The method of claim 1 , wherein the filtering further comprises discarding a sampled packet based on a determination that the sampled packet contains information similar to information contained in previously received sampled packets. 7. The method of claim 1 , further comprising: for each of the data streams, attaching information about the sampled packets to the stream signature, the information comprising at least one of: packet size information, packet protocol information, or a flag in packet header. 8. A program storage device tangibly embodying a program of instructions executable by at least one machine to perform a method for monitoring data streams in a connectivity service provider environment, the method comprising: monitoring a plurality of data streams relayed through a plurality of routers in the connectivity service provider environment; for each of the data streams: periodically sampling received packets at the router; filtering the sampled packets to exclude packets out of chronological order; and generating a stream signature based at least on a payload of the filtered packets received at the router; for each generated stream signature: attaching time-stamp information to the stream signature; and attaching to the stream signature an identification of the router at which the filtered packets used to generate the stream signature were received; storing the stream signatures corresponding to the data streams in a database; determining, based on a plurality of stream signatures in the database and the identification of the router for each of the plurality of stream signatures, that a first data stream being relayed through a first router is similar to a second data stream being relayed through a second router; and rerouting, based on the determining, at least the first data stream within the connectivity service provider environment; wherein the filtering comprises discarding at least one received sampled packet based on a determination that a stream signature corresponding to the data stream does not change from its previous value after incorporating the at least one received sampled packet in the generated stream signature.

Assignees

Inventors

Classifications

  • using hashing · CPC title

  • Packet rate · CPC title

  • Clustering or classification · CPC title

  • by tagging of packets, e.g. using discard eligibility [DE] bits · CPC title

  • Data stream processing; Continuous queries · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10437829B2 cover?
In an embodiment, a method monitors a plurality of data streams passing through a router in the connectivity service provider environment, and for each of the data streams, periodically samples packets at the router. The method further generates a stream signature based at least on the payload of the sampled packets. The method further includes, for each generated stream signature, attaching in…
Who is the assignee on this patent?
Level 3 Communications Llc
What technology area does this patent fall under?
Primary CPC classification G06F16/24568. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Oct 08 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).