Storing, retrieving and displaying captured data in a network analysis system
First Claim
1. A method of storing data from a network for use in network analysis, the method comprising:
- capturing network traffic on a network during a period of time, wherein the network traffic is captured as raw data;
organizing the raw data into logical blocks on a mass storage; and
compiling data points, each data point defining information about one of the logical blocks, each data point including;
an offset defining a number of bytes into the captured network traffic; and
datum headers including a number of frames in a logical block, number of bytes contained in the logical block, and clock ticks since the initiation of capturing.
1 Assignment
0 Petitions
Accused Products
Abstract
Analyzing data on a network. A method of analyzing data on a network is disclosed. The method includes capturing network traffic on the network during a period of time where the network traffic is captured as raw data into data blocks. The data blocks are streamed to a mass storage. The data blocks are organized into logical blocks on the mass storage. A set of data points are compiled. The data points are useful for defining information about the logical blocks. The data points include an offset defining a number of bytes into the captured data and datum headers including the number of frames into a logical block, number of bytes contained in the logical block and clock ticks since the initiation of capturing.
-
Citations
21 Claims
-
1. A method of storing data from a network for use in network analysis, the method comprising:
-
capturing network traffic on a network during a period of time, wherein the network traffic is captured as raw data;
organizing the raw data into logical blocks on a mass storage; and
compiling data points, each data point defining information about one of the logical blocks, each data point including;
an offset defining a number of bytes into the captured network traffic; and
datum headers including a number of frames in a logical block, number of bytes contained in the logical block, and clock ticks since the initiation of capturing. - View Dependent Claims (2, 3, 4, 5)
-
-
6. A method of analyzing network traffic, the network traffic being captured data on a network during a period of time, the method comprising:
-
accessing a plurality of data points corresponding to logical blocks of the network traffic, the data points comprising;
an offset defining a number of bytes into the captured data;
a number of frames in a logical block;
a number of bytes contained in the logical block; and
a number of clock ticks since the initiation of capturing; and
presenting a user with a graphical user interface representation of the network traffic, by graphing the data points to show byte density over time in a capture histogram. - View Dependent Claims (7, 8, 9, 10, 11)
-
-
12. A computer readable medium having a plurality of data fields stored on the medium and representing a data structure, comprising:
-
a captured data storage field containing data stored in logical blocks representing data frames captured during a capture operation; and
a histogram data storage field containing data representing a compilation of data points, each data point comprising;
an offset defining a number of bytes into the data frames captured during the capture operation; and
datum headers including a number frames in a logical block, number of bytes contained in the frames, and clock ticks since the initiation of capturing. - View Dependent Claims (13, 14, 15)
-
-
16. In a computer system having a graphical user interface, a method of displaying captured network traffic, the method comprising:
-
retrieving data points from at least a portion of a capture, the data points comprising;
an offset defining a number of bytes into captured raw data of the captured network traffic, the raw data organized into logical blocks or datums; and
datum headers including the number of frames in a logical block, number of bytes contained in the logical block, and clock ticks since the initiation of capturing. presenting a user with a graphical user interface representation in the form of a histogram of the network traffic using the data points by graphing byte density over time. - View Dependent Claims (17, 18, 19, 20, 21)
-
Specification