发明名称 Aggregation of network traffic source behavior data across network-based endpoints
摘要 Aggregation of network traffic source behavior data across network endpoints may be implemented. Indications of endpoint-specific network traffic directed to different network endpoints may be received. Aggregate traffic source behavior data may be generated across multiple aggregation levels. One or more traffic aggregation nodes may be implemented for each aggregation level to maintain different respective portions of the aggregate traffic source behavior data. Different granularity of the aggregate traffic source behavior data may be maintained at each of the aggregation levels. An indication of traffic source behavior for traffic sources may be provided such that responsive actions, such as traffic control actions, may be performed with regard to the traffic sources.
申请公布号 US9591018(B1) 申请公布日期 2017.03.07
申请号 US201414549432 申请日期 2014.11.20
申请人 Amazon Technologies, Inc. 发明人 Zakian Christopher Samuel;Smith Patrick Devere
分类号 H04L29/06;G06F17/30;G06F21/55;G06F9/455;H04L12/26 主分类号 H04L29/06
代理机构 Meyertons, Hood, Kivlin, Kowert & Goetzel, P.C. 代理人 Kowert Robert C.;Meyertons, Hood, Kivlin, Kowert & Goetzel, P.C.
主权项 1. A network traffic analysis system, comprising: a plurality of traffic behavior aggregation nodes that implement a plurality of different aggregation levels for traffic source behavior data for a network traffic analysis system, the plurality of traffic behavior aggregation nodes implemented via one or more computers comprising one or more hardware processors and configured to: receive respective indications of endpoint-specific network traffic directed to different ones of a plurality of network endpoints from a plurality of traffic sources;based, at least in part, on the respective indications of the endpoint-specific network traffic from the plurality of traffic sources, generate aggregate traffic source behavior data that is maintained across the plurality of different aggregation levels, wherein a different respective granularity of the aggregate traffic source behavior data is maintained at the plurality of different aggregation levels, wherein the plurality of traffic behavior aggregation nodes maintain different respective portions of the aggregate traffic source behavior data according to the different respective granularity of the plurality of different aggregation levels; a control plane for the network traffic analysis system, configured to: identify traffic behavior for a particular traffic source of the plurality of traffic sources based, at least in part, on the aggregate traffic source behavior data at one or more of the plurality of different aggregation levels, wherein to identify the traffic behavior for the particular traffic source of the plurality of traffic sources, the control plane is configured to: in response to a received request for traffic behavior data: identify one or more aggregation levels that provide a respective granularity of the aggregate traffic source behavior data that includes the requested traffic behavior data;identify at least one of the one or more traffic behavior aggregation nodes of the identified one or more aggregation levels to query for the traffic behavior data; andsend a query to the identified at least one traffic behavior aggregation node to obtain the traffic behavior data; andprovide an indication of the identified traffic behavior of the particular traffic source such that a traffic control action is performed with regard to the particular traffic source for one or more network endpoints of the plurality of endpoints, wherein the particular traffic source did not direct endpoint-specific network traffic to at least one of the one or more network endpoints.
地址 Reno NV US