The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.
The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.
Patent No.:
Date of Patent:
Nov. 22, 2011
Filed:
Dec. 23, 2008
Nicholas Duffield, Summit, NJ (US);
Lee M. Breslau, Basking Ridge, NJ (US);
Cheng EE, Rockaway, NJ (US);
Alexandre Gerber, Madison, NJ (US);
Carsten Lund, Berkeley Heights, NJ (US);
Subhabrata Sen, New Providence, NJ (US);
Nicholas Duffield, Summit, NJ (US);
Lee M. Breslau, Basking Ridge, NJ (US);
Cheng Ee, Rockaway, NJ (US);
Alexandre Gerber, Madison, NJ (US);
Carsten Lund, Berkeley Heights, NJ (US);
Subhabrata Sen, New Providence, NJ (US);
AT&T Intellectual Property I, L.P., Atlanta, GA (US);
Abstract
Disclosed herein are systems, computer-implemented methods, and computer-readable media for sampling network traffic. The method includes receiving a desired quantity of flow record to sample, receiving a plurality of network flow record each summarizing a network flow of packets, calculating a hash for each flow record of based on one or more invariant part of a respective flow, generating a quasi-random number from the calculated hash for each respective flow record, generating a priority from the calculated hash for each respective flow record, and sampling exactly the desired quantity of flow records, selecting flow records having a highest priority first. In one aspect, the method further partitions the plurality of flow records into groups based on flow origin and destination, generates an individual priority for each partitioned group, and separately samples exactly the desired quantity of flow records from each partitioned group, selecting flows having a highest individual priority first.