Please download the dossier by clicking on the dossier button x
×

System and method for retrospective network traffic analysis

  • US 10,243,971 B2
  • Filed: 03/25/2016
  • Issued: 03/26/2019
  • Est. Priority Date: 03/25/2016
  • Status: Active Grant
First Claim
Patent Images

1. A network traffic monitoring system comprising:

  • a processing device;

    a traffic intercept device configured to intercept and copy network traffic traversing a network;

    a stream tracking device coupled to the traffic intercept device configured to receive the copied packets from the intercept network traffic device wherein the copied packets are associated with a plurality of respective traffic streams included in the network traffic;

    a security device coupled to the stream tracking device configured to detect attacks in the network traffic traversing on the network;

    a first memory storage for storing the copied packets of the intercepted network traffic for a first time period;

    a second memory storage for storing at least a portion of the copied packets in the first memory for a second time period wherein the second time period is greater than the first time period; and

    a processing device configured to;

    store the copied packets in the first memory;

    maintain an ordered list per traffic stream of copied packets that are stored in the first memory;

    remove selected copied packets from first memory based on a storage constraint, the copied packets being selected based on their positions in the respective ordered lists in which they are included;

    receive an attack alert from the security device identifying a packet that is involved in a network attack;

    identify the traffic stream stored in the first memory storage that includes the packet identified; and

    transfer stored copied packets that are included in the identified traffic stream from the first memory storage to the second memory storage wherein transferring the copied packets from the first memory storage includes removing the transferred copied packets from the first memory storage.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×