Method and apparatus for data capture and analysis system
First Claim
1. An apparatus comprising:
- a network interface module to connect the apparatus to a network;
a packet capture module to intercept packets being transmitted on the network;
an object assembly module to reconstruct objects being transmitted on the network from the intercepted packets;
an object classification module to determine a type of content of the reconstructed objects;
an object store module to store the objects; and
a user interface to enable a user to search objects stored in the object store module.
13 Assignments
0 Petitions
Accused Products
Abstract
Content leaving a local network can be captured and indexed so that queries can be performed on the captured data. In one embodiment, the present invention comprises an apparatus that connects to a network. In one embodiment, this apparatus includes a network interface module to connect the apparatus to a network, a packet capture module to intercept packets being transmitted on the network, an object assembly module to reconstruct objects being transmitted on the network from the intercepted packets, an object classification module to determine the content in the reconstructed objects, and an object store module to store the objects. This apparatus can also have a user interface to enable a user to search objects stored in the object store module.
185 Citations
20 Claims
-
1. An apparatus comprising:
-
a network interface module to connect the apparatus to a network;
a packet capture module to intercept packets being transmitted on the network;
an object assembly module to reconstruct objects being transmitted on the network from the intercepted packets;
an object classification module to determine a type of content of the reconstructed objects;
an object store module to store the objects; and
a user interface to enable a user to search objects stored in the object store module. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. An method comprising:
-
intercepting data being transmitted on a network;
reconstructing objects being transmitted on the network from the intercepted data;
classifying the reconstructed objects by content type;
storing the classified objects; and
indexing the stored objects to enable searching of the stored objects. - View Dependent Claims (13, 14, 15, 16)
-
-
17. An machine-readable medium having stored thereon data representing instructions that, when executed by a processor, cause the processor to perform operations comprising:
-
intercepting data being transmitted on a network;
reconstructing objects being transmitted on the network from the intercepted data;
classifying the reconstructed objects by content type;
storing the classified objects; and
indexing the stored objects to enable searching of the stored objects. - View Dependent Claims (18, 19, 20)
-
Specification