×

Streaming method and system for processing network metadata

  • US 10,079,843 B2
  • Filed: 07/09/2016
  • Issued: 09/18/2018
  • Est. Priority Date: 11/07/2011
  • Status: Active Grant
First Claim
Patent Images

1. A method of processing network metadata generated on a network transmitting network traffic using one or more network protocols, the network including devices at least some of which receive network traffic through an ingress interface and transmit network traffic through an egress interface, the method comprising the steps of:

  • receiving network metadata from a plurality of sources in a data processing system, in at least one data format;

    determining the type or character of said network metadata;

    processing said network metadata by applying at least one policy governing network metadata processing, wherein said at least one policy includes the steps of;

    comparing the source of incoming network traffic to a predefined list of monitored off-limit devices on said network;

    if the destination IP address is on a predefined list of off-limit devices, storing the source IP/port, as well as the destination IP/port in a potential alert list, along with the number of bytes and packets reported in the ingress NetFlow record;

    examining output records to determine if the source IP/port and the destination IP/port match an entry in the potential alert list;

    if a match is found, treating such match as an indication that an internal host replied to an outside peer request; and

    generating an alert message in a timely manner to inform of a potential botnet infection; and

    converting at least a portion of said network metadata into one or more different data formats that are used in said data processing system for other system metadata, in response, at least in part, to the results of said determining step.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×