×

Apparatus and method to collect packets related to abnormal connection

  • US 10,305,754 B2
  • Filed: 11/04/2016
  • Issued: 05/28/2019
  • Est. Priority Date: 12/03/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method performed by a computer, the method comprising:

  • allocating a packet identifier to each of packets captured from a network, and storing the each packet in a buffer;

    associating, with each of the packet identifiers, a connection identifier specifying a connection for a packet identified by the each packet identifier;

    detecting a connection to which a primary abnormality is occurring by analyzing packets stored in the buffer;

    storing, for each of connections to which the primary abnormality has occurred, a primary-abnormality group of packets to which the packet identifiers associated with the connection identifier of the each connection are allocated, in a first storage region;

    detecting a connection to which a secondary abnormality is occurring, based on a statistical value related to results of analyses on packets captured in a sampling duration; and

    writing, in a second storage region, secondary-abnormality groups of packets related to connections to which the secondary abnormality has occurred, among the primary-abnormality groups of packets stored in the first storage region.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×