Streaming Method and System for Processing Network Metadata

a network metadata and streaming technology, applied in the field of network monitoring and event management, can solve the problems of inability to analyze and store massive amounts of machine-generated data that often exists in different formats and structures, inability to correlate data from different device types in real time, and inability to analyze and store massive amounts of machine-generated data, etc., to achieve the effect of increasing system throughput and enhancing system performance and throughpu

Inactive Publication Date: 2014-03-13
NETFLOW LOGIC
View PDF18 Cites 109 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Benefits of technology

[0028]According to another embodiment of the present invention, the method and system may be implemented in a streaming fashion, i.e., processing the input network metadata as it arrives (“in real-time or near-real-time”) without the need to resort to persistent storage of the network metadata. This embodiment of the invention allows deployment of the system and method on a computer with limited memory and storage capacity, which makes the embodiment especially well suited for deployments in a computing cloud.
[0029]After processing a class member instance according to a policy or a plurality of policies, an embodiment of the present invention may provide an efficient method for converting the results of the policies' application into zero, one or more representations (“converter”) suitable for further processing by recipients of the converted network metadata or the original network metadata. As a result, the system and method disclosed herein is exceptionally well suited for deployments in existing environments where its output may be directed towards existing diverse components such as SIEM systems adapted for use with syslog metadata.
[0030]An embodiment of the invention provides a plurality of converters that may be customized for a particular class or classes of network metadata and / or output format, thereby increasing throughput of the system to better enable real-time or near-real-time services on the network. Further, in response to a heavy volume of a particular class or subclass of network metadata, multiple instances of the customized working thread and / or conversion modules can be instantiated to operate in parallel to further enhance system performance and throughput.
[0031]Furthermore, an embodiment of the present invention is able to ensure integrity of the converted network metadata by appending message authentication codes. This embodiment of the invention enables sophisticated network metadata recipients to verify authenticity of the received information.
[0032]Yet another embodiment of this invention is the ability to deploy the system and method in a fashion transparent to the existing network ecosystem. This embodiment does not require any change in the existing network components' configuration.
[0033]Another embodiment of the present invention provides a method and apparatus for describing network metadata processing and conversion rules either in visual or in textual terms or a combination thereof. Once the policies' description is complete and verified to be non-contradicting, the policies and converters applicable to a class member subject to the rules may be instantiated as one or a plurality of executable modules simultaneously derived from one or a plurality of the network metadata processing and conversion rules definitions. As a result, systemic policy consistency is achieved across a plurality of modules. Furthermore, the binary nature of the modules implementing the policies and conversion rules makes the system capable of handling the input network metadata at rates significantly exceeding processing rates in environments which interpret comparable processing rules.

Problems solved by technology

Some of the issues created by the Big Data problem include an inability to analyze and store massive amounts of machine-generated data that often exists in different formats and structures.
1. Too much data to analyze in real time to acquire timely insight into network conditions.
2. Data arrives in different formats from different device types on a network, making correlation of data from different device types difficult and slow; and
3. Too much data to store (e.g., for later analysis and / or for compliance with data retention requirements).

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Streaming Method and System for Processing Network Metadata
  • Streaming Method and System for Processing Network Metadata
  • Streaming Method and System for Processing Network Metadata

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0043]In general the present invention relates to network monitoring and event management. More specifically it relates to processing network metadata obtained as a result of network monitoring activities and subsequent processing of the metadata, which may result in useful information being reported to an event management entity in a timely manner.

[0044]In the following description, the invention is disclosed in the context of network metadata processing for the purposes of illustration only. However, it will be appreciated that the invention is suitable for a broader variety of applications and uses and certain embodiments of the invention are applicable in contexts other than network metadata processing. For example, in an OpenFlow compliant environment, the system may receive NetFlow information from the network and output instructions to an OpenFlow Controller.

[0045]In one embodiment of this invention, the method and system may be implemented using a NetFlow to Syslog Converter...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

An improved method and system for processing network metadata is described. Network metadata may be processed by dynamically instantiated executable software modules which make policy-based decisions about the character of the network metadata and about presentation of the network metadata to consumers of the information carried by the network metadata. The network metadata may be type classified and each subclass within a type may be mapped to a definition by a unique fingerprint value. The fingerprint value may be used for matching the network metadata subclasses against relevant policies and transformation rules. For template-based network metadata such as NetFlow v9, an embodiment of the invention can constantly monitor network traffic for unknown templates, capture template definitions, and informs administrators about templates for which custom policies and conversion rules do not exist. Conversion modules can efficiently convert selected types and/or subclasses of network metadata into alternative metadata formats.

Description

CROSS REFERENCE TO RELATED APPLICATIONS[0001]This non-provisional application claims the benefit of provisional application No. 61 / 751,243 filed on Jan. 10, 2013, entitled “An Improved Streaming Method and System for Processing Network Metadata”, which application is incorporated herein in its entirety by this reference.[0002]This application is related to provisional application No. 61 / 556,817 filed on Nov. 7, 2011, entitled “A Streaming Method and System for Processing Network Metadata”, which application is incorporated herein in its entirety by this reference.[0003]This application also claims the benefit of provisional application No. 61 / 699,823, filed Sep. 11, 2012, entitled “A Streaming Method and System for Processing Network Metadata”, which application is incorporated herein in its entirety by this reference.[0004]This continuation-in-part application also claims the benefit of application Ser. No. 13 / 669,235, filed Nov. 5, 2012, entitled “A Streaming Method and System for...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(United States)
IPC IPC(8): H04L29/08G06F21/55H04L47/2475
CPCG06F21/55H04L67/02H04L63/102H04L63/1425H04L2463/144H04L63/20H04L41/069H04L43/04H04L43/18H04L47/2475
Inventor BALABINE, IGORVELEDNITSKY, ALEXANDER
Owner NETFLOW LOGIC
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products