×

System and method for real-time analysis of network traffic

  • US 10,250,755 B2
  • Filed: 03/19/2018
  • Issued: 04/02/2019
  • Est. Priority Date: 09/13/2013
  • Status: Active Grant
First Claim
Patent Images

1. A set of one or more tangible, non-transitory, machine-readable media storing instructions that when executed by one or more processors effectuate operations to monitor network traffic, the operations comprising:

  • obtaining, with one or more processors, a mirrored data flow of network traffic routed through a network element of a network, wherein;

    the network traffic is transmitted as packets, via the network element, between respective endpoints in communication with the network;

    respective portions of the packets are encoded according to a plurality of different respective protocols;

    the network traffic includes packets having instructions by which network events are effectuated; and

    the network events include network session events;

    before a first network session event among the network session events completes, determining, with one or more processors, based on at least part of the mirrored data flow, that the first network session event is actionable, wherein determining that the first network session event is actionable comprises;

    filtering the packets in the mirrored data flow to identify a subset of the packets pertaining to a type of network session events based on the subset of the packets being encoded in one or more protocols that are a specified subset of protocols among the plurality of protocols;

    writing the subset of the packets from the mirrored data flow to a buffer;

    decoding at least some of the subset of the packets to obtain decoded information by which the first network session event is requested to be effectuated;

    comparing the decoded information of the first network session event to a plurality of conditions specified by a plurality of rules; and

    based on at least part of the comparison, determining that the first network session event is actionable;

    in response to the determining that the first network session event is actionable, with one or more processors, causing an intervention in the first network session before the first network session completes; and

    determining, with one or more processors, that a second network session event among the network sessions is not actionable.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×