Abstract

Proposed herein are techniques to correlate together data derived from extended Berkeley Packet Filter (eBPF) visibility on hosts, combined with network data, such as that derived from monitored network traffic, and end host data, such as that derived from network visibility tools or other similar network monitoring tools/sources, in order to drive deeper visibility into traffic flows across network, and potential policy outcomes in mid-span network devices based on these correlations and the insights they provide.

Creative Commons License

Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 License.

Share

COinS