GENERATING NETWORK FLOW PROFILES FOR COMPUTING ENTITIES

    公开(公告)号:US20230327967A1

    公开(公告)日:2023-10-12

    申请号:US18335658

    申请日:2023-06-15

    申请人: VMware, Inc.

    摘要: A method for creating a flow profile is provided. The method identifies a first plurality of flow measurements, each of which corresponding to one of a plurality of flows exchanged between a computing entity and a service during a first time period. The method, for each of a first plurality of buckets each of which has a pair of lower and upper bounds, increments a counter of the corresponding bucket for each of the plurality of flow measurements that falls within the pair of bounds of that bucket. The method generates a second plurality of buckets by merging and splitting at least some of the first plurality of buckets, identifies a second plurality of flow measurements for the computing entity during a second time period, and distributes these measurements into the second plurality of buckets. The method generate the flow profile by aggregating the first and second pluralities of buckets.

    METHODS, SYSTEMS, AND COMPUTER READABLE MEDIA FOR SELECTIVELY PROCESSING A PACKET FLOW USING A FLOW INSPECTION ENGINE

    公开(公告)号:US20230300045A1

    公开(公告)日:2023-09-21

    申请号:US17695759

    申请日:2022-03-15

    摘要: A method for selectively processing a packet flow using a flow inspection engine is disclosed. The method includes receiving, by at least one hardware data plane processor component in a network packet broker, a plurality of packets associated with a packet flow, and forwarding, by the at least one hardware data plane processor component to at least one flow inspection engine, a copy of at least a portion of one or more of the initial packets of the packet flow. The method further includes providing, by the at least one hardware data plane processor component to the at least one flow inspection engine, packet flow statistical data resulting from a high throughput processing of the plurality of packets by the at least one hardware data plane processor component and generating, by the at least one flow inspection engine, metadata records using the copy at least a portion of the of the one or more of the initial packets and the packet flow statistical data, wherein the at least one hardware data plane processor component generates the statistical data from the plurality of packets independent of any instruction from the at least one flow inspection engine.