Technologies for independent service level agreement monitoring
US-2017250892-A1 · Aug 31, 2017 · US
US12052273B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-12052273-B2 |
| Application number | US-202218066446-A |
| Country | US |
| Kind code | B2 |
| Filing date | Dec 15, 2022 |
| Priority date | Oct 28, 2019 |
| Publication date | Jul 30, 2024 |
| Grant date | Jul 30, 2024 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Techniques for providing network traffic security in a virtualized environment are described. A threat aware controller uses a threat feed provided by a threat intelligence service to establish a threat detection engine on virtual switches. The threat aware controller and threat detection engine work together to detect any anomalous or malicious behavior of network traffic on the virtual switch and established virtual network functions to quickly detect, verify, and isolate network threats.
Opening claim text (preview).
We claim: 1. A method comprising: receiving, at a threat detection engine on a virtual network switch (vSwitch) a threat feed comprising a plurality of network threat properties from a threat aware controller; inspecting network traffic associated with one or more virtual network functions (VNFs) on the vSwitch; detecting a threat anomaly in the inspected network traffic using the plurality of network threat properties; transmitting a request to initiate a threat analysis VNF to the threat aware controller; receiving a threat analysis VNF configuration from the threat aware controller upon initiation of a threat analysis VNF; isolating network traffic associated with the threat anomaly to the threat analysis VNF; monitoring traffic at the threat analysis VNF; generating a threat analysis report based on the monitored traffic; and transmitting the threat analysis report to the threat aware controller. 2. The method of claim 1 , further comprising: detecting a malicious operation at the threat analysis VNF; dropping network traffic associated with the malicious operation at the threat analysis VNF; and including an identification of malicious operation in the threat analysis report. 3. The method of claim 1 , further comprising: upon detection of the threat anomaly in the inspected network traffic, dropping network traffic associated with the threat anomaly. 4. The method of claim 1 , wherein the plurality of network threat properties comprises line rate signatures for known network traffic threats; and wherein inspecting network traffic associated with the one or more VNFs comprises: comparing the line rate signatures for known network traffic threats to network traffic on the vSwitch. 5. The method of claim 1 , further comprising: transmitting telemetry data for network traffic to the threat aware controller. 6. The method of claim 1 , wherein the threat analysis VNF is initiated at an alternate host, wherein the threat detection engine isolates traffic to the threat analysis VNF on the alternate host. 7. The method of claim 1 , wherein the threat analysis VNF is configured to generate a threat analysis report and transmit traffic to the threat aware controller. 8. A system, comprising: a processor; and a memory comprising instructions which, when executed on the processor, performs an operation, the operation comprising: receiving, at a threat detection engine on a virtual network switch (vSwitch) a threat feed comprising a plurality of network threat properties from a threat aware controller; inspecting network traffic associated with one or more virtual network functions (VNFs) on the vSwitch; detecting a threat anomaly in the inspected network traffic using the plurality of network threat properties; transmitting a request to initiate a threat analysis VNF to the threat aware controller; receiving a threat analysis VNF configuration from the threat aware controller upon initiation of a threat analysis VNF; isolating network traffic associated with the threat anomaly to the threat analysis VNF; monitoring traffic at the threat analysis VNF; generating a threat analysis report based on the monitored traffic; and transmitting the threat analysis report to the threat aware controller. 9. The system of claim 8 , wherein the operation further comprises: detecting a malicious operation at the threat analysis VNF; dropping network traffic associated with the malicious operation at the threat analysis VNF; and including an identification of malicious operation in the threat analysis report. 10. The system of claim 8 , wherein the operation further comprises: upon detection of the threat anomaly in the inspected network traffic, dropping network traffic associated with the threat anomaly. 11. The system of claim 8 , wherein the plurality of network threat properties comprises line rate signatures for known network traffic threats; and wherein inspecting network traffic associated with the one or more VNFs comprises: comparing the line rate signatures for known network traffic threats to network traffic on the vSwitch. 12. The system of claim 8 , wherein the operation further comprises: transmitting telemetry data for network traffic to the threat aware controller. 13. The system of claim 8 , wherein the threat analysis VNF is initiated at an alternate host, wherein the threat detection engine isolates traffic to the threat analysis VNF on the alternate host. 14. The system of claim 8 , wherein the threat analysis VNF is configured to generate a threat analysis report and transmit traffic to the threat aware controller. 15. A computer program product, the computer program product comprising: a non-transitory computer-readable storage medium having computer-readable program code embodied therewith, the computer-readable program code executable by one or more computer processors to perform an operation comprising: receiving, at a threat detection engine on a virtual network switch (vSwitch) a threat feed comprising a plurality of network threat properties from a threat aware controller; inspecting network traffic associated with one or more virtual network functions (VNFs) on the vSwitch; detecting a threat anomaly in the inspected network traffic using the plurality of network threat properties; transmitting a request to initiate a threat analysis VNF to the threat aware controller; receiving a threat analysis VNF configuration from the threat aware controller upon initiation of a threat analysis VNF; isolating network traffic associated with the threat anomaly to the threat analysis VNF; monitoring traffic at the threat analysis VNF; generating a threat analysis report based on the monitored traffic; and transmitting the threat analysis report to the threat aware controller. 16. The computer program product of claim 15 , wherein the operation further comprises: detecting a malicious operation at the threat analysis VNF; dropping network traffic associated with the malicious operation at the threat analysis VNF; and including an identification of malicious operation in the threat analysis report. 17. The computer program product of claim 15 , wherein the operation further comprises: upon detection of the threat anomaly in the inspected network traffic, dropping network traffic associated with the threat anomaly. 18. The computer program product of claim 15 , wherein the plurality of network threat properties comprises line rate signatures for known network traffic threats; and wherein inspecting network traffic associated with the one or more VNFs comprises: comparing the line rate signatures for known network traffic threats to network traffic on the vSwitch. 19. The computer program product of claim 15 , wherein the operation further comprises: transmitting telemetry data for network traffic to the threat aware controller. 20. The computer program product of claim 15 , wherein the threat analysis VNF is initiated at an alternate host, wherein the threat detection engine isolates traffic to the threat analysis VNF on the alternate host.
Vulnerability analysis · CPC title
involving long-term monitoring or reporting · CPC title
by executing in a restricted environment, e.g. sandbox or secure virtual machine · CPC title
Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title
Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.