US 12,413,491 B2
Threat detection of application traffic flows
Thomas Vegas, Gland (CH); Anirban Karmakar, Vaud (CH); Salvatore Valenza, Pomy (CH); and Hamsa Sankaran, Zurich (CH)
Assigned to Cisco Technology, Inc., San Jose, CA (US)
Filed by Cisco Technology, Inc., San Jose, CA (US)
Filed on Jan. 21, 2020, as Appl. No. 16/748,188.
Prior Publication US 2021/0226866 A1, Jul. 22, 2021
Int. Cl. H04L 43/062 (2022.01); H04L 41/0894 (2022.01); H04L 41/14 (2022.01); H04L 41/22 (2022.01); H04L 41/40 (2022.01); H04L 43/026 (2022.01); H04L 43/0817 (2022.01); H04L 43/0823 (2022.01); H04L 43/20 (2022.01); H04L 61/4511 (2022.01)
CPC H04L 43/026 (2013.01) [H04L 41/14 (2013.01); H04L 41/22 (2013.01); H04L 41/40 (2022.05); H04L 43/062 (2013.01); H04L 43/0817 (2013.01); H04L 43/0823 (2013.01); H04L 43/20 (2022.05); H04L 61/4511 (2022.05); H04L 41/0894 (2022.05)] 20 Claims
OG exemplary drawing
 
1. A method comprising:
identifying sub-components of one or more network devices, wherein the one or more network devices are in a network environment;
disaggregating the sub-components from corresponding network devices of the one or more network devices, wherein the sub-components include portions of the corresponding network devices that relate to functioning of the corresponding network devices in the network environment;
monitoring one or more functional flows across the sub-components on a sub-component basis to generate functional flow data associated with the sub-components, wherein the one or more functional flows include both network traffic traversing the network environment and service call traffic related to operation of the sub-components within the corresponding network devices of the one or more network devices including the sub-components;
correlating the network traffic and the service call traffic to generate functionally correlated traffic data included as part of the functional flow data; and
generating, from the functional flow data, analytics of the network environment on a sub-component basis that describe operation of the one or more network devices from both an internal communication perspective between integrated subcomponents of a network device of the one or more network devices and an external communication perspective between subcomponents of two different network devices when the one or more network devices include a plurality of network devices.