EP2974355A2

A device and a related method for dynamic traffic mirroring and policy, and the determination of applications running on a network

Abstract

This record has no abstract on file.

Term

7.5 yearsto projected expiry

Projected expiry 13 March 2034, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

16 claims: 4 independent, 12 dependent

  1. 1
    Claims of equivalent WO 2014151591 A2 T!AI IS CLAIMED IS:1. A method of controlling dynamic traffic mirrors of a network system including a plurality of network infrastructure devices, the method comprising the steps of: a. providing in one or more of the network infrastructure devices one or more mirror policies;b, monitoring events, topology d status of the net work system;and c< automatically installing, enabling, selecting or changing one or more of the traffic mirrors in the one or more network infrastructure devices based on the monitoring.
  2. 2
    The method of Claim I wherein one or more of the one or .more mirror policies provided, installed, enabled, selected or changed implement one or more network policies of the network system and/or one or more rules based on one or more network policies.
  3. 3
    The method of Claim 2 further comprising the step of establishing one or more criteria tor the providing, installing, enabling, selecting or changing of the one or more mirror policies based on the one or more network policies of the network system and/or the one or more rules based on one or more network policies.
  4. 4
    The method of Claim I further comprising the step of esta lishing one or more criteria for the providing, installing, enabl ing, selecting or changing of the one or more mirror policies.
  5. 5
    The method of Claim 4 further comprising the step of selecting one or more of the one or more network intrastracture devices from which to mirror the network traffic based on one or more of the one or more criteria.
  6. 6
    The method of Claim 5 further comprising the step of selecting a destination for the mirrored traffic based on one or more of the one or more criteria.
  7. 7
    The method of Claim 6 wherein the destination may be one or more of:a, one or more of the plurality of network infrastructure devices;one or .more network services;C, a function of the network system d. a portal,
  8. 8
    The method of Claim 7 further comprising the step of selecting a portion of the network traffic to mirror, wherei the selected portion may be any one of:a flow of packets;h. a set of packets wi thin a flow;and a portion of one or more frames of one or more packets within a Sow.
  9. 9
    The method of Claim 8 wherein the portion of the network traffic selected for mirroring is selected based on one or more of the one or more criteria.
  10. 10
    The method of Claim 8 farther comprising the step of determining when to stop the mirroring of the network traffic.
  11. 11
    11 - The method of Claim 10 wherein, the stopping is determined based on one or more of;a, one or more of the one or more criteria;b. one or more mirror policies or one or more network policies;and one or more priorities of one or more other network traffic Sows.
  12. 12
    The method of Claim I wherein the events monitored include one or mors of;. traffic loads;b. time of the day ;link outages and other bandwidth constraints of the network system;d. oea&on and status of one or more of the plurality of network infrastructure devices;e, number of attached fonciions attached to the network system;f. usage and numbers of wireless access points of the network system g< mirrored network traffic;h> IDS and other security events;L identification of a computer application running on the network system;and j, triggers.
  13. 13
    The method of Claim 1 further comprising the step of securing the network traffic to be mirrored prior to mirroring,
  14. 14
    The method of Claim 1 further comprising the step of securing the network traiiic by including a security mechanism as pan of the mirror.
  15. 15
    The method of Claim 13 wherein the step of securing is provided by one or more of:a, a tunnel;h. encrypting the content of the network traffic;and e. an encrypted tunnel 16.. The method of Claim 1 wherein one of the one or more mirror policies is to allow a source of the mirrored network traffic to choose the destination of that mirrored network traffic. .17. The method of Claim 1 wherein one of the mirror policies is to mirror selectable network traffic based on an attached function or us r generating the network traffic to be mirrored or ci.mie.nt of the network traffic to be monitored. 18. The method of Claim 1 further comprising the step of storing the one or more mirror policies in the one or more network infrastructure devices and wherein the stored one or more mirror policies may be changed. 1 . The method, of Claim 1 wherei n the one or more mirror policies re based on one or more of;a. a role of an authenticated user of the network system;h, a device using the network system;c. & type of a. device using the network system;d. local packet classification;e. time of day;1 other events which may be monitored;md g. network policies, 20. A device of a network sy stem including a pluralit of networ k infrastructure devices, the device comprising;a. one or more ports configured to receive packets mc!uding frames and to end frames to one or more other network infrastructure devices;b. a i-afflc mirroring function including one or more portals for mirroring selectable ones of the frames of the received packets aad to mirror the selectable ones of the frames of the received packets to one or more other devices of the network- system, wherein the device Is configured store thereon one or more mirror policies for mirroring network traffic, to carry out traffic mirroring activity according to the one or more mirror policies and to change to the one or more mirror policies. 21. The device of Claim 20 wherein the change of the one or more mirror policies includes changing one or more of: a. the one or more portals;h. one or more configurations of the one or more portals c. the frames of the received packets to mirror;d. ¾ portion of the selectable ones of the frames to be mirrored;e. where to mirror the frames;and £ when to stop the mirroring. 22■ The device of Claim 21 wherein the one or more portals is one or more of the one or more ports of the device. 23. The device of Claim 21 wherein the one or more mirror policies include one or more of: a< where to mirror the frames;b, which frames to mirror;which portions of frames to mirror;d. when to stop mirroring;e. frame mirroring based on criteria of the user and device soureing ihe received tmfhe;and frame mirroring based on criieria of tlie network system. evice of Claim 21 wherein a .mirror policy change is made based on one or more of;traffic loads at selectable packe forwarding devices of the network r ^structure;b. time of the day ;link outages and other bandwidth constraints of the netw ork infestrucrare;l cation and status of the network policy controller;number of attached functions attached to the network system;usage and numbers of wireless access points of the network inirastrueture;and triggers. 25. ' The device of Claim 24 wherein the one or more mirror policies for mirroring the selectable ones of the frames are established based on one or more of;a. roles of users attached to the network infrastructure;b, services available through the network infras ructure devices;e, time period of usage of the services;d. applications used on the network infmstructure devices;ana e . hi story of network use. 26. The device of Claim. 20 wherein the device is a switch. 27. The device of Claim 20 wherein at least one of the one or more portals is a tunnel to another device of the network infrastructure. 28. The device of Claim 20 wherein the one or more mirror policies are pro vided to the device by network policy controller. 29. The device of Claim 20 wherein at least one of the one or more portals includes a data link layer encapsulation for the received frames to he mirrored. 30. The device of Claim 20 wherein the one or more portals or a type of the one or more portals is selectable based on one or more of;a. source, destination or both of the recei ved frames;h. one or more fields in the frames to be mirrored;c. performance;d. security;and e. location of the mirror, destination of the mirroring or both. 31 . A device of a network system including a plurality of network infrastructure devices, the de v ce eomprl sing : a, one or more ports configured to receive packets including frames and to send frames to one or more other network infrastructure devices;and b. a traffic mirroring function for mirroring through one or more portals selectable ones of the frames of the recei ved packets for mirroring and to mirror the selectable ones of the frames of the received packets to one or more other network infrastructure devices based on a pluralit y of criteria, the criteria including one or more of: i . a first criterion for selecting one or more received frames for mirroring;si. a second criterion for selecting one or more portions of the frames for mirroring;iii. a third criterion for selecting which of the one or more portals through which to mirror the frames;and iv. a fourth criterion, for establishing a destination of the mirrored frames, 32. The device of Claim 31 wherein the first criterion is the establishment of a new flow of frames received at the device. 33- The device of Claim 31 xvherein any of the one or more portals Is one or more of the one or more ports of the device. 34. The device of Claim 31 further comprising a fifth criterion for stopping the mirroring of the selected frames. 35. The device of Claim 3 wherein the second criterion is a field or a portion of a field of the frames, 36. The device of Claim 35 wherein the field or a portion of the field is selected from the group consisting of address fields, protocol fields, length fields, byte eonnt fields, and fields used in determining & value, meaning, placement or inclusion of other fields, 37. The device of Claim 34 wherein the fifth criterion is a count setting of the frames meeting the first criterion. 38. The device of Claim 34 wherein the filth criterion is a pro-set count or based on infor ation in the received frames mirrored. 39. The device of Claim 34 wherein the tilth criterion is based on atformafioa about an application associated with the received frames, 40. The device of Claim 31 configured io receive mirroring instructions for the device based on one or. more of;a. network events;b. applications detected;c. user authentication;d. type of the device;e. status of the device;f. ownership of an attached function attached to the device;and g< triggers, 1. The de vice of Claim 31 wherei n at least one of the one or more portals is a tunnel to another device of the network infrastructure. 42. The device of Claim 31 wherein the mirrored frames are encapsulated i a data link layer encapsulation. 43. T he de vice of Claim 31 wherein the one or more portals or a type of the one or more portals is selectable based on one or more of: a. source address, destination address or both of the received frames;b. one or more fields in the frames to be mirrored;c. peifomtan.ce;d. security;and e. location of the mirror, destination of the mirroring or both. 44» A method for .mirroring one or more frames of one or more packets of a flow established in a network system signal exchange, wherein the network system includes a plurality of network Infrastructure devices, the method, comprising the steps of: a. establishing a first criterion for selecting one or more received frames for mirroring;b. establishing a second criterion for selecting one or more portions of the frames tor mirroring;c. establishing a third criterion for selecting one or more portals through which to mirror the frames;d. establishing a fourth criterion for establishing a destination for the mirrored frames;e. establishing a fifth criterion for the establishme of a mirror in a device of the network infrastructure;£ creating one or more portals in one or more of the plurality of network Inirast.ructure devices meeting the criterion for establishing a mirror to mirror the selected fr mes;and g. carrying out the mirroring of the selected frames through the created one or more portals, 45. The method of Claim 44 further comprising the step of ehaag.bg one or more of the criteria. 46. The method of Claim 44 further comprising the step of establishing a sixth criterion for stopping the mirroring. 47. l te method of Claim 44 further comprising the step of modifying automatical ly the mirroring of the selected frames during mirroring. 48. The method of Claim 44 further comprising the step of generating mirroring instructions associated with one or more of the criteria based on one or more of: a. network events;b. applications detected;c . user authentication;d, type of t he device;e, status of the device;f, ownership of an attached function attached to the device;and g, niggers, 49. The method of Claim 44 further comprising die step of changing mirroring instructions associated with one or more of the criteria based on one or more of: a. network events;b. applications detected;c. user authentication;d . type of the device;e. status of the device;f ownership of an attached function attached, to the device;and g. triggers. 50. The method ©fCkira 46 further comprising the step of generating mirroring instructions associated with one or more of the criteria based o one or more of: a. network events;b. applications detected;c . user aathen iicaiion ;d. type of the device;e< status of the device;f. ownership o f an attached function attached to the device;and g. triggers. 51.. The method of Claim 44 further comprising the step of modifying mirroring instructions associated with one or more of the criteria automatically based on one or more of: a. network events;b. applications detected;e. user authentication;d. type of the device;e> status of the device;f ownership of an attached iimetkm attached to the device;and g, triggers, 52. The method of Claim 44 wherein the step of creating the portal includes the step of establishing an encapsulation for the frames to be mirrored. 53. The method of Claim 44 wherein the steps of creating a portal and carrying out the mirroring ate earned out in a packet forwarding device of the network infrastructure. 54. The method of Claim 44 wherein the one or more portals or a type of the one or more portals is selectable based on one or more of;a, source address, destination address or both of the received irames;b> one or more fields in the frames to be mirrored;c. performance;d. security;and e. location of the mirror, destination of the ndrroring or both, 55. A device of a network system including a plurality of network mfrastmeture devices, the device com risin : a, one or more ports configured to receive packets including frames and to send frames to one or more other devices;b, one or more network policies for receiving and se d n packets;and c, a network policy controller in communication with a packet ibr arding fkiciicm eonilguml for changing one or more of the policies of the device for forwarding packets based on one or more computer applications detected running, or attempting to run by analyzing frames received by any device of the network mt¾istructi5fe on one or more of the plurality of network infrastructure devices, 56. The device of Claim 55 wherein the one or more policies are based on application metadata information , 57, The device of Claim 55 wherein the device is a network switch or a router. 58. The device of Claim 55 wherein the network policy controller is located in a policy server of the plurality of network infrastructure devices. 59, The device of Claim 55 wherein one of the policies is to mirror selectable ones of the frames to an application Identification appliance of the network, .khrastrue ore, 60, The device of Claim 55 wherein the one or more policies changed on the device are selected from: 1.) block a specific application flow;2) block n IF address;3) snipe a TCP connection;4} disable communication lor an application;5) disable communications to an attached function;6} disable a network communication, in either or both of a forward path and a reverse path;7) bandwidth-limit an application by a particular user;8} ban width-iimit n application for all users of the network system;9} log all application data;and 10) honeypot the application flow. 6 i , The device of Claim 55 wherein the device is a packet forwarding device and the network pol cies are implemented on the packet forwarding device as at least one of a set of ingress rales, egress rules, and nirroring rules. 62. A method for the operation of a network system including a plurality of network infrastructure devices, the method comprising the steps of: a. establishing on one or more packet forwarding devices of the network m&asifiseture one or more network policies or rules implementing the one or more network policies for forwarding frames of received packets based on computer applications running or attempting to run on the network system;and b. changing one or more of the one or more of the policies or rules based on the detection of one or more computer applica tions running on one or more of the plurality of network inftastYuetirre devices, 63. The method of Claim 62 wherein the applications running on t he network system are identified based on one or more frames received from the network system. 64. The method of Claim 62 mrther comprising the step of implementing the net work policies on the packet forwarding device as ai least one of a set of ingress rules, egress rules, and mirroring rules. 65. The method of Claim 62 wherein the one or more network policies changed is to mirror selectable frames of the received packet to an application identification appliance of the network inimstraefcure. 66. The method of Claim 61 wherein the one or more pol cies changed are selected from: 1 ) block a specific application Sow;2} block m IP address;3) snipe a TCP connection;4) disable communication- for an application;5) disable communications to an attached fonction;6} disable a network communication, in either or both of a forward path and a reverse path;7) bandwidth- limit an application by particular user;8} andwidi¾~I«mt an. application tor all users f the network system;9) log all application data;and 10} honeypot the application flow. 67. A device of a network system including a plurality of network infrastructure devices, the device comprising: aii application idemilieation function the application identification function including: a. an application identification library including information about one or more signatures dete min d to be indicative of characteristics of one or more computer applications;b. an application identification database including information other than signatures information, wherein the other information is indicative of characteristics of the one or more computer applications and wherein the other information is obtained from one or more mechanisms for determining characteristics of the one or more computer appl ications;and c. an application identification engine configured to: 1 examine content of one or more frames received at the device for the one or more signatures and the other information;ϋ compare the content examined with: (a) the one or more signatures;and (b) the other mforoiaiiou to match known computer application information from those two sources with the information derived from the examination of the one or more frames;and ni, outpu information representing an indication of a likely computer application associated with the examined, fr mes based on the comparison. 68. The device of Claim 6? wherein the application identification engine is configured to weight the likely acc uracy of the one or more signatures and. t he other information in the comparison, 69. The device of Claim 6S wherein the one or more signatures and the other information are not weighted equally. 70, The devl.ce of Claim 67 wherein the other iiifonnation is deri ved from one or more of TCP UDP canonical port value, IP protocol value, heuristics, regular expression, history, computer applications installed on the network and statistics. 71 , The device of Claim 67 wherei the information includes a confidence level of the indication, 72, The device of CI aim 67 wherein the application identificaiion engine further includes a scorin analysis engine configured to: a, establish a mathematical value representing the likely accuracy of the computer application identified by the one or more signatures compariso and the other information: and b. generate a single output with an identification of the likely computer application associated with the received one or more frames, 73, The device of Claim 72 wherein the scoring analysis engine assesses likely accuracy on a scale of 0 to 100. 74, The device of Claim 67 wherein the device is a standalone appliance of the network infrastructure devices. 75, The device of Claim 67 wherein the application identification engine farther includes an application progr mming interface configured to enable loading into the application identification engine one or more custom mechanisms with corresponding indicators as one or m ore of the other mechanisms for determining computer applications to be identified by the application idend: caiion engine.. 76, The device of Claim 67 wherein the application identification engine farther includes an interface configured to enable loading into the application identification library one or more signatures of one or more computer applications to be identified b the application identification engine. 77, A device of a network system including a plurality of network iufi¾stri ct¾re devices, the device comprising: an application identification fYmetiom the application identification function including: a. an application identification librar mdadkg information about one or more signatures determined to be indicative of characteristics of one or more computer applications;h. an application identification database including information other than signatures information, wherein the other infom ation is indicative of characteristics of the one or more computer applications and wherein the other information is obtained from one or more mechanisms for de emiining characteristics of the one or more computer applications;c. an application programming interface configured io enable inclusion in the database a custom mechanism for establishing other information indicative oi characteristics of one or more computer applications;and d, an application identification engine configured to: f examine content of one or more frames received at the device for the one or more signatures and the other information;it. compare the content examined with: (a) the one or more signatures;and (h) the other information to match known computer application information from those two sources with the ini rmaion derived from the examination of the one or more frames: and Hi, output information representing an indication of a likely computer application associated with the examined frames based on the comparison, 78. The device of Claim 77 wherein the output infomiation includes a level of confidence in the indication. 7<), A method for monitoring a network system to identity one or more computer application fanning on one or more network devices of a plurality of network infrastructure devices of the network system, the method comprising the steps of;, receiving on a device of the plurality of network mhaatruciure devices one or more packets containing one or more frames, wherein the one or more -frames are associated wit a computer application;b. examining content of the one or more frames received for one or more signatures associated with the computer application and for other Inform ion obtained ikvm one or more mechanisms, wherein the inform tion is indicative of characteristics of the compute application;c. comparing the examined content with computer application information of the one or more signatures and the other infonnatiom d. establishing a most likely match of the computer application information associated with the one or more frames derived from the comparison;and e< ooipuhing information representing an indication of a likely computer application associated with the examined frames based on the comparison, 80, The method of Claim 79 wherein the information outputted includes a level of confidence In the indication, 81. The method of Clai 79 farther comprising the step of weighting the information of the one or more signatures and the other information, &2, The method of Claim 81 wherein the weighting is not equal. S3, The method of Claim 79 further comprising the steps of;f, scoring the comparison to assess the likely accuracy of the correlation between the computer application identified by the one or more signatures comparison and the other information;and g. generating a single output with an identification of the l ikely computer application associated with the recei ved one or more frames. 84. The method of Claim 83 wherein the single output includes a level of confidence in the identification. 85, The method of Claim 79 further comprising the step of providing an application programming interface to ¾dd information from one or store custom mechanisms with corresponding indicators as one or mote of the other mechanisms for detsnnimng computer applications to he identified. 86. The method of Claim 79 wherein the one or more other indicators includes TCF UDP canonical port, vaine, IF protocol value, heuristics., regular expression, history, applications installed on the network and statistics. 87. The method of Claim 79 wherein the step of outputting includes transmitting the identification, of the likely computer application to a network control manager. 88. The method of Claim 79 wherein the device is a standalone appliance of the network infrastructure 89. The method of Claim 88 wherein the appliance receives the one or more frames from one or more packets mirrored to the appliance from one or more other devices of the network inirastxuetare. 90. A network system, comprising: a. a plurality of packet forwarding devices including one or more packet forwarding devices that, are arranged in the network system as network entry devices for receiving packets from one or more attached functions, wherein the one or more network entry devices are configu ed to detect packet. Hows and forward packets of the network, system;h, one or more flow monitoring devices configured to examine and/or log information associated with Hows of the network system, wherein at least one of the one or more packet forwarding devices is configured to mirror frames of received packets to ai least one of the one or more flow monitoring devices;and c. a manager function of the network system configured to adjust mirroring actions of the at least one of the one or more network entry devices based on information received from the one or more Ho monitoring devices or other Infon¾ation. 1. The system of Claim 9t) wherein the manager function is located within the flow monitoring device. 92. The system of Claim 90 wherein the manager function s further configured to select one or more of the one or more packet forwarding devices to mirror flows or portions of flows to the a least one of the one or more flow monitoring devices or another device of the network system, 93. The system of Claim 5 ) 0 wherein the manager function is configured to do one or more of: a, change a mirror;b, stop a mirroring activity;c, initiate miransng of a flow of another packet forwardi»g device to the same or a different monitoring device;d, change either or both of mhToring and monitoring activities based on ooe or more events associated with the network system;e» determine a source of a flow;f, determine a source of a response in a flow;and g. determine a source network entry device of a response low. 94. The sy stem of Claim 90 wherein the one or more llow monitoring devices is selected from;a. one or more applicatio kfesititicatlon engines;b. one o more intrusion detection svsiems e, one or more network loggers;ami d, ooe or more network management monitors, 95. The system of Claim 94 wherein a least one of the one or more flow monitoring devices is configured to identify computer applications .running on the network system. 96. The system of Claim 95 wherein the at least one of the one or more Sow monitoring devices is configured to examine one or more frames and other mfomiatkni niinor d to it from the one or more of the one or more packet forwarding devices for iafotmat associated with one or more computer applications and output to the manager f nction one or more indications of the computer application associated with die examined one or more frames. 97. The system of Claim 90 further comprising a traffic nurroring function configured to establish one or more portals for mirroring selectable ones of the frames of the received packets o the application identification engine based, on one or more criteria. 98. The system of Claim 9? wherein the one or mom criteria include one or more of: a, a first criterion for selecting one or more received frames for mirroring;h, second criterion for selecting one or more portions of the frames for nnrrorixvg;c. a third criterion for selecting one or more portals through which to mirror the frames;d. a fourth criterion for where to mirror the frames;and e. a fifth criterion for selecting at least one of the one or more packet forwarding devices within which to configure a mirror for mirroring frames of its received packets. 99. The system of Claim 9 ( 1 wherein the manager function Is in a policy server of the network system. 1 0. The system of Claim 90 wherein a flow monitoring device of the one or more flow monitoring devices is established in an application identification appliance of the network system, 101. The system of Claim 100 wherein the flow monitoring device includes an application Identification engine, wherein die application identification engine includes a primary identification, fonction and a secondary application identific tion function and wherein the primary application identification function is established in the same device of the network system as the manager inaction and the secondary application identification function is established in the application identification alliance, 102- The system of Claim 90 wherein the one or mors packet, forwarding devices that receives the one or more frames to be examined is a network entry switch of the network system. 103, The system of Claim 90 wherein the one or more packet forwarding devices that receives the one or more frames to be examined is a core switch, of the network system. 104, The system of Gaim 90 wherein: a. the network system includes a data center;b. packets are forwarded to and from the data center by one or more data center switching devices of the network system;c. a flow monitoring device of the one or more flow monitoring devices includes an application identification engine established in an application identificatio appliance;and d. the one or more data center switching devices mirror the one or more frames for examination to the application identification appliance. 105. A method tor controlling the operation of a network system including a plurality of network infrastructure devices, wherein the plurality of network infrastructure devices includes one or more packet .forwarding devices, the method comprising the steps of;a, mirroring one or more frames received at one or more of the one or more packet forwarding devices to another device of the network inlxastructure;b, examining one or more frames received at one or more of the one or more packet forwarding de vices tor one or more indications of one or more computer applications naming on the one or more packet !brwarding devices receiving the examined frames;e. comparing the one or more indications of the examined one or more frames to one or more computer application indicators of an application identification database;and d, identifying one or more computer applications runnmg on the network system, 106. The method of Claim 105 wherein the examining and comparing steps are carried, out in a single device of the plurality of network infrastructure de vices. 107. The method of Claim 105 further comprising as pan of the step of comparing, the s e of scoring a plurality of the indications and weighting the score based on indicators to determine specific computer applications running on the network system, 1 OS, A network system comprising;a. a pinrahty of packet forwarding devices including one or more packet, forwarding devices that are as-ranged in the network system tor receiving packets from one or more attached functions, wherein the one or more network entry devices are configured to detect packets flows and t ward packets of tire network system, wherein at least one of the one or more packet forwarding devices is configured to mirror frames of recei ved packets;and e. a device for identifying one or more computer applications running or attempting to rim on the network system, the device comprising a scoring analysis engine configured to;i receive frames mirrored from the at least one of the one or more packet forwarding devices, wherein the mirrored frames include mfonraatkm indicati ve of one or more computer applications;ii. compare the received information with information of a computer appl ication s identi ficati on database, w herein the information of the database includes information about a plurality of computer applications;hi, establish a score for each computer application likely to match the .received information related to the one or more frames;and iv, designate one of the computer applications as being associated with the one or more framos based on the established score. 109. The system of Claim 1 OS wherein the designation of the one of the computer applications includes an Indication of the confidence in the designation. 11 . A device of a network system including a plurali ty of network infrastructure de vices tor identifying one or more computer applications running or attempting to run on the -network system, the device comprising a scoring analysis engine configured to;a. recei ve Information related to one or more frames received- by one or more of the plurality of network infrastructure devices indicative of one or more am aor applications;b. compare the received inibraiatlon with information of a computer applications identification, d tabase, wherein the information of the database includes information about a plurality of computer applications obtained fmm a plurality of mechanisms;c. establish a score for e ch computer application likely to match the received Information re ated to the one or more frames;and d. designate one of the computer applications- as being associ ated with the one or more frames based o the established score. H i. The d ice of Claim 1 10 wherein the designation of the one of the computer pplkatioas includes n indication of the confidence i the designation. 1 12. The device of Claim 1 10 wherein the scoring analysis engine assesses likely accuracy on a scale of δ to 100, 1 13. The device of Claim 1 10 wherein the device is a standalone appliance of the plurality of network infrastructure devices. 1 14. The device of Claim 1 10 wherein the device is a policy server or a manager server, 115. The device of Claim 110 wherein the scoring analysis engine receives information from a application identification engine that includes a interface configured to enable loading Into the computer applications i entifica ion database new indicators of computer applications to he identified by the application identification engine. 116. The device of Claim 1 15 wherein the interface is an application programming interface to add information from one or more custom mechanisms with corresponding indicators as one or more of the pluralit of mechanisms for determining computer applications to be identified, i 17, The devic of Claim 11 S wherein the interface is an Interface to add one or more computer application signatures infonnation to the computer applications identification database for 'ά signatures compaiisciit niccli pism of the plurality af tncohanisms< 1 18. The device of Claim US wherein the ap lication entificatien engine is configured to weight the likely accuracy of the one or more kuHcators in the comparison, 11 . T he device of Claim 1 18 wherein the one or more indicators are not weighted equally. 120. The device of Claim 110 wherein the received information includes one or more computer application signatures, TCP UDP canonical port value, IP protocol value, heuristics, regular expression, history, statistics and applications installed on the network. 12 ! , The device of Claim 120 wherein the score k established by combining scores tor each type of received information. 122. The device of Claim 121 wherein the combining involves the use of one or more mathematical operations for the received information. 123. The device of Claim 122 wherein the scores for each type of received inforrnation arc not weighted equally in the combining. 124. The device of Claim 123 wherein history and installed applications are weighted greater than the other types, 125. The device of Clai 120 wherein the received infonnatlon from either or both of the history 1 and installed applications is used to weight others of the oilier types of received information.
  16. 16
    1 6. A method ibr identifying one or more computer applications running or attempting to run on a network system including a plurality of network infrastructure devices including one or more packet forwarding devices, the method comprising the steps of:a. receiving information of one or more frames forwarded by one or more of the plurality of network iaftssmtcture devices indicative of one or more computer applications;b. comparmg information of one or more frames forwarded by one or more of the one or more packet forwarding devices with information of computer applications identification database, wherein the information of the database includes information about a plurality of computer applications obtained from a plurality of mechanisms;c, establishing a score for each computer application likely to match the received information of the one or more frames;and d» designating one of tire computer applications as being associated wit the one or more frames based on the established score. 12?> The method of Claim 126 wherein the step of designating includes providing an indication of the confidence i the designation, Ϊ28. The method of Claim 126 further comprising the step of assessing likely accuracy on a scale of 0 to 100. 129, The method of Claim 126 wherein the scoring is conducted on standalone appliance of the plurality of network infrastructure devices. 130, The method of Claim 126 further comprising the step of weighting the likely accuracy of the one or more indicators ia the comparison. .131 « The method of Claim 130 wherein the one or more Indicators are not weighted equally. 132. The method of Claim 126 wherein the information of the one or more frames includes one or more compute application signatures, TCP/UDP canonical port value, IP protocol value, heuristics, regular expression, history, applications Installed on the network and statistics. 133. The method of Claim 132 wherein the score is established by combining scores for each type of received information. at 134, The method of Claim 133 wherein the scores tor each type of received information are not. weighted equally in the combining. 135. The method of Claim .134 wherein history surd installed applications are used to weight the other types.