Augmenting network flow with passive dns information

US2018077110A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2018077110-A1
Application numberUS-201615261474-A
CountryUS
Kind codeA1
Filing dateSep 9, 2016
Priority dateSep 9, 2016
Publication dateMar 15, 2018
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for encoding domain name information into flow records includes receiving a flow record. The flow record includes initial network flow information in a standard flow record format including at least a source address and a destination address. Domain name information associated with each of the source address and destination address is retrieved from a database. The domain name information is encoded into the received flow record while maintaining the initial network flow information to yield an enhanced flow record.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method for encoding domain name information in flow records, the method comprising: receiving a flow record, the flow record including initial network flow information in a flow record format comprising at least a source address and a destination address; retrieving domain name information associated with each of the source address and destination address from a database; and encoding the domain name information in the received flow record while maintaining the initial network flow information to yield an enhanced flow record. 2 . The method as recited in claim 1 , further comprising distributing the enhanced flow record having the encoded domain name information to one or more network devices and storing the enhanced flow record in a flow record repository. 3 . The method as recited in claim 1 , wherein the retrieved domain name information comprises one or more fully qualified domain names. 4 . The method as recited in claim 1 , wherein the enhanced flow record is a flow record following customized Netflow format. 5 . The method as recited in claim 2 , wherein the domain name information includes a domain name suffix string and wherein retrieving the domain name information comprises filtering the retrieved domain name information based on one or more domain name suffix strings. 6 . The method as recited in claim 5 , further comprising analyzing a plurality of the enhanced flow records stored in the flow record repository according to a user specified criteria. 7 . The method as recited in claim 2 , further comprising analyzing a plurality of the enhanced flow records stored in the flow record repository to identify one or more domain names associated with sources of network traffic growth. 8 . The method as recited in claim 6 , wherein the user specified criteria is associated with a user-specified collection of network resources or services. 9 . The method as recited in claim 2 , wherein the enhanced flow record is distributed to one or more network devices identified in a distribution list. 10 . The method as recited in claim 6 , wherein analyzing the plurality of the enhanced flow records further comprises aggregating two or more of the enhanced flow records based on one or more domain name suffix strings. 11 . A monitoring system comprising: a monitored network comprising a plurality of devices; a database for storing domain name system (DNS) information; and one or more network monitoring devices communicatively coupled to the monitored network and to the database, wherein the one or more network monitoring devices are configured and operable to: receive a flow record, the flow record including initial network flow information in a flow record format comprising at least a source address and a destination address; retrieve domain name information associated with each of the source address and destination address from the database; and encode the domain name information in the received flow record while maintaining the initial network flow information to yield an enhanced flow record. 12 . The monitoring system as recited in claim 11 , further comprising a flow record repository communicatively coupled to the one or more network monitoring devices, wherein the one or more network monitoring devices are further configured and operable to distribute the enhanced flow record having the encoded domain name information to one or more network devices and to store the enhanced flow record in the flow record repository. 13 . The monitoring system as recited in claim 11 , wherein the enhanced flow record is a flow record following customized Netflow format. 14 . The monitoring system as recited in claim 12 , further comprising a user interface communicatively coupled to the one or more monitoring devices, the user interface configured to obtain traffic analysis criteria from a user. 15 . The monitoring system as recited in claim 14 , wherein the domain name information includes a domain name suffix string and wherein the one or more network monitoring devices configured and operable to retrieve the domain name information are further configured and operable to filter the retrieved domain name information based on one or more domain name suffix strings. 16 . The monitoring system as recited in claim 15 , wherein the one or more network monitoring devices are further configured and operable to analyze a plurality of the enhanced flow records stored in the flow record repository according to the traffic analysis criteria. 17 . The monitoring system as recited in claim 12 , wherein the one or more network monitoring devices are further configured and operable to analyze a plurality of the enhanced flow records stored in the flow record repository to identify one or more domain names associated with sources of network traffic growth. 18 . The monitoring system as recited in claim 16 , wherein the traffic analysis criteria is associated with a user-specified collection of network resources or services. 19 . The monitoring system as recited in claim 11 , wherein the one or more network monitoring devices are further configured and operable to periodically distribute an annotated flow template defining a plurality of fields comprising the enhanced flow record. 20 . The monitoring system as recited in claim 16 , wherein the one or more network monitoring devices configured and operable to analyze the plurality of the enhanced flow records are further configured and operable to aggregate two or more of the enhanced flow records based on one or more domain name suffix strings.

Assignees

Inventors

Classifications

  • Protocol analysers · CPC title

  • Generation of reports · CPC title

  • related to network traffic · CPC title

  • Electricity · mapped topic

  • Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2018077110A1 cover?
A method for encoding domain name information into flow records includes receiving a flow record. The flow record includes initial network flow information in a standard flow record format including at least a source address and a destination address. Domain name information associated with each of the source address and destination address is retrieved from a database. The domain name informat…
Who is the assignee on this patent?
Arbor Networks Inc
What technology area does this patent fall under?
Primary CPC classification H04L61/1511. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Mar 15 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).