-
公开(公告)号:US12255794B2
公开(公告)日:2025-03-18
申请号:US17695759
申请日:2022-03-15
Applicant: Keysight Technologies, Inc.
Inventor: Jonathan Lee Harrod , Shardendu Pandey , Jonathan Glenn Stroud , Stefan Jan Johansson
IPC: H04L43/062 , H04L43/00 , H04L43/028
Abstract: A method for selectively processing a packet flow using a flow inspection engine is disclosed. The method includes receiving, by at least one hardware data plane processor component in a network packet broker, a plurality of packets associated with a packet flow, and forwarding, by the at least one hardware data plane processor component to at least one flow inspection engine, a copy of at least a portion of one or more of the initial packets of the packet flow. The method further includes providing, by the at least one hardware data plane processor component to the at least one flow inspection engine, packet flow statistical data resulting from a high throughput processing of the plurality of packets by the at least one hardware data plane processor component and generating, by the at least one flow inspection engine, metadata records using the copy at least a portion of the of the one or more of the initial packets and the packet flow statistical data, wherein the at least one hardware data plane processor component generates the statistical data from the plurality of packets independent of any instruction from the at least one flow inspection engine.
-
2.
公开(公告)号:US20230300045A1
公开(公告)日:2023-09-21
申请号:US17695759
申请日:2022-03-15
Applicant: Keysight Technologies, Inc.
Inventor: Jonathan Lee Harrod , Shardendu Pandey , Jonathan Glenn Stroud , Stefan Jan Johansson
IPC: H04L43/062 , H04L43/028 , H04L43/00
CPC classification number: H04L43/062 , H04L43/028 , H04L43/14
Abstract: A method for selectively processing a packet flow using a flow inspection engine is disclosed. The method includes receiving, by at least one hardware data plane processor component in a network packet broker, a plurality of packets associated with a packet flow, and forwarding, by the at least one hardware data plane processor component to at least one flow inspection engine, a copy of at least a portion of one or more of the initial packets of the packet flow. The method further includes providing, by the at least one hardware data plane processor component to the at least one flow inspection engine, packet flow statistical data resulting from a high throughput processing of the plurality of packets by the at least one hardware data plane processor component and generating, by the at least one flow inspection engine, metadata records using the copy at least a portion of the of the one or more of the initial packets and the packet flow statistical data, wherein the at least one hardware data plane processor component generates the statistical data from the plurality of packets independent of any instruction from the at least one flow inspection engine.
-
公开(公告)号:US20230031654A1
公开(公告)日:2023-02-02
申请号:US17390860
申请日:2021-07-30
Applicant: Keysight Technologies, Inc.
Abstract: A method for network flow metadata processing at a network packet broker is described herein. The method includes, receiving, as input at a network packet broker, network traffic flow data, aggregating the network traffic flow data over a predefined time period to generate Internet protocol (IP) flow feature vectors containing metadata parameters associated with one or more particular endpoint devices, and providing the IP flow feature vectors to a machine learning element in the network packet broker. The method further includes identifying, by the machine learning element, anomalies existing in the metadata parameters included in the IP flow feature vectors, and automatically configuring one or more filter elements in the network packet broker in response to detecting the identified anomalies of the IP flow feature vectors.
-
公开(公告)号:US11949570B2
公开(公告)日:2024-04-02
申请号:US17390860
申请日:2021-07-30
Applicant: Keysight Technologies, Inc.
IPC: H04L43/04 , G06N20/00 , H04L43/028 , H04L67/562
CPC classification number: H04L43/028 , G06N20/00 , H04L67/562
Abstract: A method for network flow metadata processing at a network packet broker is described herein. The method includes, receiving, as input at a network packet broker, network traffic flow data, aggregating the network traffic flow data over a predefined time period to generate Internet protocol (IP) flow feature vectors containing metadata parameters associated with one or more particular endpoint devices, and providing the IP flow feature vectors to a machine learning element in the network packet broker. The method further includes identifying, by the machine learning element, anomalies existing in the metadata parameters included in the IP flow feature vectors, and automatically configuring one or more filter elements in the network packet broker in response to detecting the identified anomalies of the IP flow feature vectors.
-
-
-