Network monitoring system and method including software agents

The network monitoring system addresses the challenge of requiring dedicated hardware by using software agents and cloud services to construct an abstract model of the network, enabling effective visualization and monitoring without dedicated hardware.

JP2025080750APending Publication Date: 2025-05-26NOZOMI NETWORKS SAGL
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024185002
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-14
Filing Date
2024-10-21
Publication Date
2025-05-26

Smart Images

  • Figure 2025080750000001_ABST
    Figure 2025080750000001_ABST
Patent Text Reader

Abstract

To implement network visibility not requiring dedicated hardware.SOLUTION: A network monitoring system 100 comprises: a communication network NT comprising a plurality of nodes N1 to NM and a plurality of node connections E1 to EP, where each node comprises an asset configured to receive / transmit packets; a plurality of software agents AG1 to AGN each installed in the plurality of nodes and configured to redirect packets from respective assets AS1 to ASF, receive packets sent by each software agent, extract source addresses and destination addresses, identify the plurality of nodes and the plurality of node connections, associate each node to a corresponding node identifier, and construct an abstract model representing the NT; and a monitoring computer CS that comprises software resources in which each node is represented by the corresponding node identifier and each node connection is represented by a corresponding link between respective nodes and configured to construct the abstract model representing the communication network.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network monitoring for network visualization.

Background Art

[0002] Network visualization refers to the process of creating visual representations of networks, performance metrics, and data flows. It is sometimes defined as the ability to monitor and analyze network traffic to identify potential problems, security threats, and performance bottlenecks. This can be done using the following functions: a topology graph, a bilayer map, a dependency graph, and a visualization chart.

[0003] These capabilities enable users to view the physical and logical relationships between routers, switches, servers, and other devices in order to immediately identify and correct performance problems. Generally, in a network, the topology allows IT staff to visualize the network and see in real time what is happening in the network, enabling the pre-identification and resolution of problems before they affect end users.

[0004] Network monitoring and visualization (including anomaly detection and asset inventory) can be achieved by packet sniffing and deep packet inspection (DPI) by attaching dedicated appliances to network switches or routers that support traffic mirroring. This type of approach is described in document US10955831.

[0005] Note that such an approach may be difficult to apply to some networks because it requires dedicated hardware and a dedicated configuration, and it is not always possible or desirable to sniff at the appropriate network level.

Prior Art Documents

Patent Documents

[0006]

Patent Document 1

Non-Patent Document

[0007]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0008] The applicant believes that it is desirable to realize network visualization by a technique that does not require dedicated hardware and replaces known techniques.

Means for Solving the Problems

[0009] According to a first aspect, the present disclosure relates to a network monitoring system, and this network monitoring system includes a communication network including a plurality of nodes and a plurality of node connections, each node including an asset configured to receive / transmit packets, a plurality of software agents each installed on at least a part of the plurality of nodes, each software agent being configured to redirect packets from its respective asset, at least one monitoring computer having software resources, the software resources being receiving packets transmitted by each software agent, extracting source addresses and destination addresses from the above packets, Identifying a plurality of nodes and a plurality of node connections from the source address and destination address, and associating each node with a corresponding node identifier; Constructing an abstract model representing the communication network, wherein each node is represented by a corresponding node identifier and each node connection is represented by a corresponding link between the respective nodes; At least one monitoring computer configured to perform the above; Including.

[0010] Specifically, the software resource is part of a cloud computing service. In one embodiment, the software resource is configured to construct an abstract model in the form of a displayable topological graph.

[0011] According to an example, the software resource is configured such that the source address and destination address include network layer addresses, and further, the software resource is configured to identify links between nodes that process the network layer addresses. According to one embodiment, the software resource is configured such that the source address and destination address include physical layer addresses, and further, the software resource is configured to identify links between nodes that process the physical layer addresses.

[0012] According to an example, the software resource has deep packet inspection capabilities.

[0013] In one embodiment, the network monitoring system is such that a plurality of nodes are associated with a management entity and the communication network further includes at least one public network device.

[0014] According to one example, among the network monitoring systems, the first node of the plurality of nodes includes a first asset including a computer that executes any version of Windows (registered trademark), Linux (registered trademark), or macOS (registered trademark).

[0015] Specifically, the plurality of software agents are configured to operate as packet sniffers. More specifically, the plurality of software agents operate as packet sniffers and are configured to extract at least one of the following technical information related to each asset, namely, host label, operating system version, firmware version in the case of an operating technology device, central processing unit usage rate, RAM (random access memory) usage rate, disk usage rate, installed software, from the above packets. According to one example, the plurality of software agents are configured to associate a time stamp indicating the extraction time with the technical information related to each asset.

[0016] In one embodiment, the above software resources are configured to execute a merging process by processing the technical information received by the plurality of software agents, and to associate the corresponding technical information related to the corresponding asset with each node of the abstract model.

[0017] Specifically, the software resource is configured to receive, from a first software agent, a first value assumed by a technical information key, where the first value is associated with a first timestamp value and is related to a selected node, and to receive, from a second software agent, a second value assumed by the technical information key, where the second value is associated with a second timestamp value and is related to the selected node, and to selectively associate the first value and the second value with an abstract model according to the first timestamp value and the second timestamp value. According to one embodiment, the software resource and / or the plurality of agents are configured to perform anomaly detection.

[0018] According to a second aspect, the present disclosure relates to a network monitoring method, which includes accessing a communication network including a plurality of nodes and a plurality of node connections, where each node includes an asset configured to receive / transmit packets, and providing a plurality of software agents each installed on at least a part of the plurality of nodes, where each software agent is configured to redirect packets from its respective asset, and providing at least one monitoring computer having a software resource, where the software resource receives packets transmitted by each software agent, and extracts source addresses and destination addresses from the packets, and identifies a plurality of nodes and a plurality of node connections from the source addresses and the destination addresses and associates each node with a corresponding node identifier, and Constructing an abstract model representing the communication network described above, wherein each node is represented by a corresponding node identifier and each node connection is represented by a corresponding link between the respective nodes, and configured to perform a step of including.

[0019] Further features and advantages will become clearer from the following description of various embodiments, given by way of example with reference to the accompanying drawings.

Brief Description of the Drawings

[0020]

Figure 1

Figure 2

Figure 3

Modes for Carrying Out the Invention

[0021] FIG. 1 shows an example of a network monitoring system 100 including a communication network NT including a plurality of nodes N 1 ~N M and a plurality of connections (i.e., links) E 1 ~E P between the nodes.

[0022] A part of the plurality of nodes (for example, the first node N 1 and the second node N 2 ) each includes an asset AS i (AS 1 ~AS F ) associated with a specific entity (for example, a private entity).

[0023] The term "asset" is used to represent a physical or virtual network - compliant device physically connected within a network. Asset AS 1 ~AS F Each of ~AS F may include hardware (e.g., computers, switches, routers), software (e.g., mission - critical applications and support systems), and may store confidential information. An asset may be a computer, tablet, printer, or other types of devices that can communicate over a network such as TCP / IP. Specifically, each of asset AS 1 ~AS F includes computers running any version of Windows, Linux, or macOS.

[0024] The term "connection" means a model representing communication between two assets through a network using some protocol. An asset can communicate with, or have the potential to communicate with, other assets. When an asset can communicate with another asset, the assets have a common link. A computer network may have several components between assets and there are different device types (routers, firewalls, application firewalls, etc.) that may suppress all or some of the protocols between two assets.

[0025] Another part of a plurality of nodes (such as a third node N 3 ) may include a public server PS (or other public device), and thus such a node is an asset not considered according to this specification.

[0026] Each of the nodes N 1 ~N M of the communication network NT follows packet - switching technology for connection E 1 ~E PIt is configured to receive and transmit packets through it. Specifically, the communication network NT operates according to the Internet protocol. As is well known, the term "packet" means a finite sequence of bytes representing a message exchanged between assets on a network, specifically between two nodes. Each protocol defines a specific structure for the set of valid packets that can be exchanged and defines the rules for managing perceivable communication.

[0027] The network monitoring system 100 further includes at least one monitoring computer with monitoring software resources connected to the network NT. Such monitoring computers and software resources are external to the assets AS 1 ~AS F and nodes N 1 ~N M and are provided, specifically, in the form of cloud services CS in some cases. In the embodiments described below, an exemplary use of the cloud service CS is referred to.

[0028] Furthermore, each node including the assets AS 1 ~AS F (or a part thereof) is equipped with software agents AG 1 ~AG N and the software agents AG 1 ~AG N are configured to capture packets from each asset on which they are installed and redirect them towards the cloud service CS. Specifically, the software agents AG 1 ~AG N may also have analytical capabilities and are thus packet sniffers capable of performing deep packet inspection (DPI). Specifically, each agent AG 1 ~AG N is stored in the corresponding asset AS 1 ~AS F .

[0029] Each software agent AG 1 ~AG N has the following basic attributes that are specific to the agent. - The agent is not strictly called for a task and starts itself. - The agent can reside in a waiting state on the asset while perceiving the situation. - The agent can reach an execution state on the asset under start conditions. - The agent does not require user interaction.

[0030] In the following description, it is confirmed that all nodes (such as the first node N 1 etc.) including the asset with the corresponding agent are also called "endpoints". Packet traffic can be captured and / or analyzed by the agent AG X from all network interfaces of the endpoint N j and / or analyzed.

[0031] As will be further clarified below, the cloud service CS is configured to process the packet traffic received by the agents AG 1 ~AG F and construct an abstract model representing the communication network NT. Specifically, the abstract model may be in the form of a topological graph of the network NT.

[0032] Furthermore, the cloud service CS can be configured to receive further information about each asset AS 1 ~AS F from the agents AG 1 ~AS N and associate such further information with each node in an abstract model such as a topological graph. The cloud service CS may have additional DPI capabilities.

[0033] An example of a method for constructing an abstract network model will be described below. The above method can be implemented by the network monitoring system 100 described above.

[0034] All software agents AG 1 ~AG N capture packet traffic from each endpoint on which it is installed and send such traffic to the cloud service CS (periodically, for example). The software agent AG 1 ~AG N can observe the interaction between the asset and the public Internet.

[0035] The cloud service CS extracts the source address and destination address from the received packets above. Specifically, thanks to its DPI capabilities, the cloud service CS decrypts all the packets received from the agent AG 1 ~AG N and understands a wide range of protocols and network layers. A non-limiting list of exemplary protocols can be found on the following web page, namely https: / / www.nozominetworks.com / resources / protocol-support-list.

[0036] As an example, the cloud service CS extracts the source and destination IP addresses from the network layer (i.e., the third layer of the Open Systems Interconnection model - OSI model). As is known, the IP address is used to uniquely identify the network connection used when a device joins the network.

[0037] In one embodiment, the cloud service CS may extract source and destination MAC (Media Access Protocol) addresses. The MAC address, sometimes called a hardware or physical address, is a unique, 12-character alphanumeric attribute used to identify individual electronic devices on a network. The MAC address is extracted from the physical layer (i.e., the second layer of the OSI model).

[0038] From the extracted addresses, the cloud service CS identifies a plurality of nodes N 1 ~N M (specifically, assets AS 1 ~AS F and public devices PS) as well as a plurality of node connections E 1 ~E P between the nodes and associates each node with a corresponding node identifier (such as its respective IP address).

[0039] As an example, a first software agent AG 1 observes the following node connections (i.e., links). - 192.168.1.15 (node N M ) ⇔ 192.168.1.16 (node N 1 ) - 192.168.1.12 (node N 3 ) ⇔ 192.168.1.14 (node N X )

[0040] A second software agent AG 2 observes these node connections. 192.168.1.12 (node N 3 ) ⇔ 192.168.1.13 (node N 2 ) 192.168.1.12 (node N 3 ) ⇔ 192.168.1.16 (node N 1 ) 192.168.1.13 (node N 2 ) ⇔ 192.168.1.17 (node N M-1 )

[0041] The j-th software agent AG j observes these node connections. 192.168.1.17 (node N M-1 ) ⇔ 192.168.1.18 (node N 4 ) 192.168.1.16 (node N 1 ) ⇔ 192.168.1.18 (node N 4 ) 192.168.1.13 (node N 2 ) ⇔ 192.168.1.17 (node N M-1 )

[0042] Using the knowledge of node identifiers and node connections, the cloud service CS constructs and stores an abstract model of the network NT. Such an abstract model can be represented by a topology graph 200 (shown in Figure 2) that describes the communication network NT.

[0043] The abstract model is accessible to the user. Specifically, the graph 200 can be displayed on the monitor by the user of the cloud service CS to obtain a clear depiction of the network NT.

[0044] The construction of the graph 200 is performed by the cloud service CS thanks to the fact that the software agents AG 1 ~AG N provide duplicate information globally. Thus, it should be noted that the cloud service CS merges all the links and creates the global network graph 200.

[0045] Furthermore, it is confirmed that the graph 200 can be represented by a set of pairs where each item of the pair represents a node in the graph and the pair itself represents a link between the nodes. The cloud service CS receives a list of pairs, merges the duplicates, and the resulting set can be directly rendered as a graph.

[0046] According to another embodiment, the network monitoring system 100 uses the technical information regarding each asset AS 1 ~AS F to enhance the abstract model described above and is further configured to associate each piece of information with the corresponding node.

[0047] According to this embodiment, the software agents AG 1 ~AG N are packet sniffers adapted to perform deep packet inspection (DPI) on the assets AS 1 ~AS F and extract information about the public network (such as the public server PS). Specifically, at least some of the software agents AG 1 ~AG N are also configured to extract information by directly invoking the operating system API (application program interface) of the asset.

[0048] In one embodiment, each software agent AG 1 ~AG F may extract one or more of the following technical data related to the corresponding asset, namely host label, operating system version, firmware version in the case of an OT (operational technology) device, CPU (central processing unit) usage rate, RAM (random access memory) usage rate, disk usage rate, installed software, etc., and send it to the cloud service CS.

[0049] OT is the hardware and software that detects or causes changes through the direct monitoring and / or control of industrial equipment, assets, processes, and events. The CPU usage rate indicates the total percentage of processing power consumed to process data and execute various programs on a network device, server, or computer at a given point in time.

[0050] As an example, agent AG 1 ~AG F may operate as shown below with respect to FIG. 3.

[0051] The second software agent AG 2 observes the endpoint 192.168.1.16 (corresponding to the first node N as an example) 1 and extracts the CPU usage rate (e.g., 55%, time: z) from SNMP (Simple Network Management Protocol) packets and the firmware version (e.g., 14.5, time: a) from Ethernet / IP packets. As shown above, all fields have a timestamp related to the field (time: z; time: a) to mark the observation time of each value. The second software agent AG 2 sends these two fields (INF1) to the cloud service CS.

[0052] The first software agent AG 1 is installed on the endpoint 192.168.1.16, and directly extracts the CPU usage rate (e.g., 50%, time: y) and the host label (label: "lbl", time: x) along with the corresponding timestamp through the endpoint operating system API of this endpoint (N1). The first software agent AG 1 sends these two fields (INF2) to the cloud service CS in the same way as the second agent AG 2 does.

[0053] The cloud service CS receives the label, CPU, and firmware version for the endpoint 192.168.1.16, and processes the above information to enhance the network model. The first and second software agents AG 1 and AG 2The label and firmware version information received from are complementary and non - conflicting. Therefore, the cloud service CS adds the label ("lbl" - time: x) and firmware version (14.5, time: a) information to the endpoint 192.168.1.16.

[0054] Regarding CPU usage, there is a conflict between the values received from the first and second software agents AG 1 and AG 2 Such a contradiction in the information regarding the CPU usage field is resolved by selecting the more recently extracted value, and the CPU usage at time z is newer than that at time x. In the final form, the asset 192.168.1.16 contains three fields and is represented in Figure 3 (INF3).

[0055] Specifically, regarding the process executed by the cloud service CS when merging information, all information is represented as a pair containing a key and a value, for example, as a pair containing key = label, value = "lbl". Further, each pair is attached with a timestamp representing the freshness of the information. When performing the above - mentioned merge, the cloud service CS assumes that the key is unique, that is, an asset can contain only a single instance of all keys.

[0056] When an existing key is to be added to the abstract model as being associated with the corresponding node N 1 ~N M a conflict is caused. This conflict is resolved by considering the timestamp of the value received by the cloud service CS, and the value assumed by the key with the most recent timestamp is attached to the description of that node in the abstract model. When adding a key / value pair to a node and there is no conflict, the information is added to the abstract model and is only associated with a specific asset.

[0057] Software agent AG 1 ~AGF and / or the cloud service CS may be configured to also perform anomaly detection, and it is confirmed that the results of such detection can be integrated into the abstract model and displayed in the graph 200 representing the network NT.

[0058] The network monitoring system 100 and method according to this specification find useful applications in any type of physical infrastructure or automated system connected by a network, specifically in industrial automation systems such as industrial processes for manufacturing production, industrial processes for power generation, infrastructure for the distribution of fluids (water, oil, and gas), infrastructure for the generation and / or transmission of electricity, infrastructure for transportation management, etc. Further, it finds useful applications in all technical environments including information technology (IT), operational technology (OT), and the Internet of Things (IoT).

[0059] The monitoring system and method disclosed above ensure complete network visualization while avoiding the use of dedicated hardware thanks to the software agents installed on the network assets. Software resources dedicated to abstract model construction, such as cloud services, are configured to inspect a wide range of protocols and network layers on the packet traffic redirected by the software agents, completely overcoming the need for dedicated devices associated with each asset.

[0060] The monitoring system described above enables the acquisition of a complete asset inventory that enhances the abstract model of the network by being able to extract and merge several types of technical information about the assets.

Explanation of Reference Numerals

[0061] 100 Network monitoring system 200 Topology graph AG Software agent AS Asset CS Cloud Service Connection (Link) between E Nodes INF Field N Node NT Communication Network PS Public Server

Claims

1. A communication network including a plurality of nodes and a plurality of node connections, each node including an asset configured to receive / transmit packets; a plurality of software agents each installed on at least a portion of the plurality of nodes, each software agent configured to redirect packets from a respective asset; At least one monitoring computer having a software resource, said software resource comprising: receiving said packets transmitted by each software agent; extracting a source address and a destination address from the packet; identifying the plurality of nodes and the plurality of node connections from the source address and the destination address, and associating each node with a corresponding node identifier; constructing an abstract model representing said communications network, wherein each node is represented by a corresponding node identifier and each node connection is represented by a corresponding link between respective nodes; at least one monitoring computer configured to Network monitoring system.

2. The network monitoring system of claim 1 , wherein the software resource is part of a cloud computing service.

3. The network monitoring system of claim 1 , wherein the software resources are configured to construct the abstract model in the form of a displayable topology graph.

4. 2. The network monitoring system of claim 1, wherein the software resource is configured such that the source address and the destination address include network layer addresses, and the software resource is configured to identify links between nodes from the network layer addresses.

5. 2. The network monitoring system of claim 1, wherein the software resource is configured such that the source address and the destination address include physical layer addresses, and the software resource is configured to identify links between nodes from the physical layer addresses.

6. The network monitoring system of claim 1 , wherein the software resource has deep packet inspection capabilities.

7. the plurality of nodes being associated with a management entity; The network monitoring system of claim 1 , wherein the communications network further comprises at least one public network device.

8. 10. The network monitoring system of claim 1, wherein a first node of the plurality of nodes includes a first asset including a computer running a version of Windows, Linux, or macOS.

9. The network monitoring system of claim 1 , wherein the plurality of software agents are configured to operate as packet sniffers.

10. 10. The network monitoring system of claim 9, wherein the plurality of software agents are configured to operate as packet sniffers and extract at least one of the following technical information related to each asset from the packets: host label, operating system version, firmware version in case of an operation technology device, central processing unit utilization, RAM random access memory utilization, disk utilization, installed software.

11. The network monitoring system of claim 10 , wherein the plurality of software agents are configured to associate with technical information relating to each asset a timestamp representative of an extraction time.

12. The software resource is performing a merging process by processing the technical information received by the plurality of software agents; Associating with each node of said abstract model corresponding technical information related to a corresponding asset; The network monitoring system of claim 11 configured to:

13. The software resource is receiving, from a first software agent, a first value assumed by a technical information key, the first value being associated with a first timestamp value and relating to a selected node; receiving from a second software agent a second value assumed by the technical information key, the second value being associated with a second timestamp value and relating to the selected node; selectively associating the first value and the second value with the abstract model in response to the first timestamp value and the second timestamp value; The network monitoring system of claim 12 configured to:

14. The network monitoring system of claim 1 , wherein the software resource and / or the plurality of software agents are configured to perform anomaly detection.

15. Accessing a communication network including a plurality of nodes and a plurality of node connections, each node including an asset configured to receive / transmit packets; providing a plurality of software agents each installed on at least a portion of the plurality of nodes, each software agent configured to redirect packets from a respective asset; providing at least one monitoring computer having software resources, said software resources comprising: receiving said packets transmitted by each software agent; extracting a source address and a destination address from the packet; identifying the plurality of nodes and the plurality of node connections from the source address and the destination address, and associating each node with a corresponding node identifier; constructing an abstract model representing said communications network, wherein each node is represented by a corresponding node identifier and each node connection is represented by a corresponding link between respective nodes; configured to perform the steps of: A network monitoring method comprising:

Citation Information

Patent Citations

  • US10,955,831