Misconfigured mirror port detection

US2024179043A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2024179043-A1
Application numberUS-202218071132-A
CountryUS
Kind codeA1
Filing dateNov 29, 2022
Priority dateNov 29, 2022
Publication dateMay 30, 2024
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method includes monitoring a plurality of packets received by a network sensor associated with a port of a network, determining a ratio of unicast, multicast or broadcast packets to a total number of packets for the plurality of packets, determining that the ratio is outside the bounds of a threshold range, detecting that a port is misconfigured based on the determination that the ratio is outside the bounds of a threshold range, and automatically notifying a network administrator that the port is misconfigured based on the determination that the ratio is outside the bounds of a threshold range. Further disclosed is a computer system and computer program product configured to perform the method.

First claim

Opening claim text (preview).

1 . A method for detecting a misconfigured port in a packet forwarding configuration comprising: monitoring, by one or more processors of a computer system, a plurality of packets received by a network sensor associated with a port of a network; determining, by the one or more processors of the computer system, a ratio of unicast, multicast or broadcast packets from the plurality of packets received to the total number of all of the plurality of packets received; determining, by the one or more processors of the computer system, that the ratio is outside the bounds of a threshold range; detecting, by the one or more processors of the computer system, that a port is misconfigured for the packet forwarding configuration based on the determination that the ratio is outside the bounds of the threshold range; and automatically notifying, by the one or more processors of the computer system, a network administrator that the port is misconfigured based on the determination that the ratio is outside the bounds of the threshold range. 2 . The method of claim 1 , wherein the determining the ratio of unicast, multicast or broadcast packets to a total number of packets for the plurality of packets comprises determining the ratio of unicast packets to a total number of packets, and wherein the determining that the ratio is outside the bounds of the threshold range includes determining that the ratio is less than a threshold. 3 . The method of claim 2 , wherein the threshold is less than one percent. 4 . The method of claim 1 , further comprising: triggering, by the one or more processors of the computer system, an automated response after the detection that the port is misconfigured. 5 . The method of claim 4 , wherein the automated response includes: inspecting, by the one or more processors of the computer system, a unicast packet received by the port; determining, by the one or more processors of the computer system, a switch port number associated with the unicast packet; and using, by the one or more processors of the computer system, one or more application programming interfaces to change a configuration associated with the port of the network. 6 . The method of claim 1 , further comprising: providing, by the one or more processors of the computer system, a sensitivity option for the threshold range to a user; and receiving, by the one or more processors of the computer system, a sensitivity from the user after the sensitivity option is provided. 7 . The method of claim 1 , wherein the automatically notifying includes providing a warning to a user interface of an application associated with the network sensor. 8 . The method of claim 1 , wherein the port of the network is a virtual port on a virtual switch. 9 . The method of claim 1 , wherein the port of the network is a physical port on a physical switch. 10 . A computer system, comprising: one or more processors; one or more computer readable storage media; and computer readable code stored collectively in the one or more computer readable storage media, with the computer readable code including data and instructions to cause the one or more computer processors to perform a method for detecting a misconfigured port in a packet forwarding configuration comprising: monitoring, by the one or more processors of the computer system, a plurality of packets received by a network sensor associated with a port of a network; determining, by the one or more processors of the computer system, a ratio of unicast, multicast or broadcast packets from the plurality of packets received to the total number of all of the plurality of packets received; determining, by the one or more processors of the computer system, that the ratio is outside the bounds of a threshold range; detecting, by the one or more processors of the computer system, that a port is misconfigured for the packet forwarding configuration based on the determination that the ratio is outside the bounds of the threshold range; and automatically notifying, by the one or more processors of the computer system, a network administrator that the port is misconfigured based on the determination that the ratio is outside the bounds of the threshold range. 11 . The computer system of claim 10 , wherein the determining the ratio of unicast, multicast or broadcast packets to a total number of packets for the plurality of packets comprises determining the ratio of unicast packets to a total number of packets, and wherein the determining that the ratio is outside the bounds of the threshold range includes determining that the ratio is less than a threshold. 12 . The computer system of claim 11 , wherein the threshold is less than one percent. 13 . The computer system of claim 10 , the method further comprising: triggering, by the one or more processors of the computer system, an automated response after the detection that the port is misconfigured. 14 . The computer system of claim 13 , wherein the automated response of the method further includes: inspecting, by the one or more processors of the computer system, a unicast packet received by the port; determining, by the one or more processors of the computer system, a switch port number associated with the unicast packet; and using, by the one or more processors of the computer system, one or more application programming interfaces to change a configuration associated with the port of the network. 15 . The computer system of claim 10 , wherein the method further comprises: providing, by the one or more processors of the computer system, a sensitivity option for the threshold range to a user; and receiving, by the one or more processors of the computer system, a sensitivity from the user after the sensitivity option is provided. 16 . The computer system of claim 10 , wherein the automatically notifying includes providing a warning to a user interface of an application associated with the network sensor. 17 . The computer system of claim 10 , wherein the port of the network is a virtual port on a virtual switch. 18 . The computer system of claim 10 , wherein the port of the network is a physical port on a physical switch. 19 . A computer program product comprising: one or more non-transitory computer readable storage media having computer readable program instructions collectively stored on the one or more computer readable storage media, the computer readable program instructions being executed by one or more processors of a computer system to cause the computer system to perform a method for detecting a misconfigured port in a packet forwarding configuration comprising: monitoring, by the one or more processors of the computer system, a plurality of packets received by a network sensor associated with a port of a network; determining, by the one or more processors of the computer system, a ratio of unicast, multicast or broadcast packets from the plurality of packets received to the total number of all of the plurality of packets received; determining, by the one or more processors of the computer system, that the ratio is outside the bounds of a threshold range; detecting, by the one or more processors of the computer system, that a port is misconfigured for the packet forwarding configuration based on the determination that the ratio is outside the bounds of the threshold range; and automatically notifying, by the one or more processors of the computer system, a network administrator that the port is misconfigured based on the determination t

Assignees

Inventors

Classifications

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2024179043A1 cover?
A method includes monitoring a plurality of packets received by a network sensor associated with a port of a network, determining a ratio of unicast, multicast or broadcast packets to a total number of packets for the plurality of packets, determining that the ratio is outside the bounds of a threshold range, detecting that a port is misconfigured based on the determination that the ratio is ou…
Who is the assignee on this patent?
Sophos Ltd
What technology area does this patent fall under?
Primary CPC classification H04L43/16. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu May 30 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).