TIMESTAMPING DATA RECEIVED BY MONITORING SYSTEM IN NFV

    公开(公告)号:US20190056972A1

    公开(公告)日:2019-02-21

    申请号:US16083421

    申请日:2016-03-11

    发明人: Tianlin Zhou Yang He

    IPC分类号: G06F9/455 H04L12/26

    摘要: A network traffic monitoring system is provided. The system includes a host computer executing a plurality of virtual machines (VMs), including a monitoring VM and a virtual switch (vSwitch). The vSwitch includes a plurality of virtual Network Interface Cards (vNICs) associated with the plurality of VMs. The monitoring VM is coupled to the vSwitch and executed by the host computer. The vSwitch is configured to mirror a plurality of data packets exchanged between two communicating VMs to a vNIC associated with the monitoring VM. The monitoring VM is configured to retrieve the plurality of mirrored data packets from the vNIC associated with the monitoring VM. The monitoring VM is further configured to generate timestamps indicative of packet arrival time at the vSwitch for each data packet in the retrieved plurality based, at least in part, on a computed base time.

    MULTI CAUSE CORRELATION IN WIRELESS PROTOCOLS

    公开(公告)号:US20170207948A1

    公开(公告)日:2017-07-20

    申请号:US15001931

    申请日:2016-01-20

    IPC分类号: H04L12/24 H04L12/26

    摘要: A network monitoring system is provided that includes a processor, a memory coupled to the processor and a database that includes session data of one or more transactions in a multiprotocol wireless communication system. The network monitoring system further includes a rule engine configured and operable to store rules associated with at least one rule set. The network monitoring system also includes an analysis engine configured to identify a root cause of a failure for one or more of the transactions based on at least one rule in the rule set.

    ESTIMATING NETWORK LATENCY FOR TRAFFIC TRANSPORTED WITH ENCRYPTED INTERNET TRANSPORT PROTOCOL

    公开(公告)号:US20220329508A1

    公开(公告)日:2022-10-13

    申请号:US17226468

    申请日:2021-04-09

    IPC分类号: H04L12/26

    摘要: A method of estimating network latency including receiving intercept data (representing observations of requests sent by a client node and responses to the respective requests from a host node), detecting a burst of network traffic bounded by a first idle interval and/or second idle interval, and estimating download and/or upload latencies associated with the burst, wherein the download latency is estimated to be an amount of time between observation of an inferred first request of the burst from the client node until observation of a first response from the host node following the inferred first request, and the upload latency is estimated to be an amount of time between observation of a last inferred data packet of the burst from the host node to the client node until observation of a last inferred ACK packet from the client node following the last inferred data packet from the host node.

    Timestamping data received by monitoring system in NFV

    公开(公告)号:US10908941B2

    公开(公告)日:2021-02-02

    申请号:US16083421

    申请日:2016-03-11

    发明人: Tianlin Zhou Yang He

    摘要: A network traffic monitoring system is provided. The system includes a host computer executing a plurality of virtual machines (VMs), including a monitoring VM and a virtual switch (vSwitch). The vSwitch includes a plurality of virtual Network Interface Cards (vNICs) associated with the plurality of VMs. The monitoring VM is coupled to the vSwitch and executed by the host computer. The vSwitch is configured to mirror a plurality of data packets exchanged between two communicating VMs to a vNIC associated with the monitoring VM. The monitoring VM is configured to retrieve the plurality of mirrored data packets from the vNIC associated with the monitoring VM. The monitoring VM is further configured to generate timestamps indicative of packet arrival time at the vSwitch for each data packet in the retrieved plurality based, at least in part, on a computed base time.

    Self-localizing data distribution network

    公开(公告)号:US09813317B2

    公开(公告)日:2017-11-07

    申请号:US14791116

    申请日:2015-07-02

    IPC分类号: H04L12/26 H04L29/08 G06F15/16

    CPC分类号: H04L43/08 H04L67/10

    摘要: To adaptively self-localize distributed data processing and data distribution and reduce data transfer costs in a network monitoring system, data has a corresponding ownership association. For each data access, an ownership association value for the accessed data may be modified based on whether the access originated with a current owner processing node or a second most-frequently accessing processing node. The ownership association value indicates a strength of the ownership association between the data and the owner and is based on at least a recent history of accesses of the data by the current owner and the second most-frequently accessing node. When the ownership association value traverses a selected cutoff, ownership association of the data is transferred from the current owner to the second most-frequently accessing node. The ownership association transfer contributes to self-localizing data processing based on a source of input regarding the data.

    Estimating network latency for traffic transported with encrypted internet transport protocol

    公开(公告)号:US11509558B2

    公开(公告)日:2022-11-22

    申请号:US17226468

    申请日:2021-04-09

    摘要: A method of estimating network latency including receiving intercept data (representing observations of requests sent by a client node and responses to the respective requests from a host node), detecting a burst of network traffic bounded by a first idle interval and/or second idle interval, and estimating download and/or upload latencies associated with the burst, wherein the download latency is estimated to be an amount of time between observation of an inferred first request of the burst from the client node until observation of a first response from the host node following the inferred first request, and the upload latency is estimated to be an amount of time between observation of a last inferred data packet of the burst from the host node to the client node until observation of a last inferred ACK packet from the client node following the last inferred data packet from the host node.

    Multi cause correlation in wireless protocols

    公开(公告)号:US10601639B2

    公开(公告)日:2020-03-24

    申请号:US15001931

    申请日:2016-01-20

    IPC分类号: H04L12/24 H04L12/26

    摘要: A network monitoring system is provided that includes a processor, a memory coupled to the processor and a database that includes session data of one or more transactions in a multiprotocol wireless communication system. The network monitoring system further includes a rule engine configured and operable to store rules associated with at least one rule set. The network monitoring system also includes an analysis engine configured to identify a root cause of a failure for one or more of the transactions based on at least one rule in the rule set.

    Method and system for dynamic handling in real time of data streams with variable and unpredictable behavior

    公开(公告)号:US10284650B2

    公开(公告)日:2019-05-07

    申请号:US15189782

    申请日:2016-06-22

    摘要: A computer-implemented method for supervising data stream storage including communicating with a probe that captures network data and outputs a plurality of data streams to a plurality of data repository units, receiving registration data associated with respective data streams that identifies the associated probes, selecting at least one of the data repository units to store the first data stream in real time based on a storage capacity of the data repository units to receive and store data, determining that storage capacity is not sufficient for the data stream in response to a change in the storage capacity of the data repository units to receive and store data, determining a corrective action in response to the determination that the storage capacity is not sufficient, and notifying the probe identified in association with the first data stream about the corrective action.