Managing captured network traffic data
First Claim
1. A system comprising:
- a plurality of capture components that are each configured to record network traffic to a capture file, and a management component that is configured to communicate with each of the plurality of capture components, identify at least one capture component based on a first capture condition, and effect an archiving of at least a portion of a capture file recorded by an identified capture component based on a second capture condition.
21 Assignments
0 Petitions
Accused Products
Abstract
A system and method for managing captured network traffic data is provided. The invention comprises a plurality of capture agents, each being configured to capture the network traffic associated with one or more applications. Each application is associated with one or more capture agents according to an application profile that is stored and maintained in a capture server. When analysis of an application'"'"'s network traffic is required, the capture server contacts the corresponding capture agents according to the application profile. The capture server then effects the identification and archiving of the network traffic that corresponds to a user-defined capture condition. A database at the capture server maintains a record that associates the corresponding network traffic with the user-defined capture condition such that the corresponding network traffic can later be retrieved and analyzed using an analysis engine.
-
Citations
51 Claims
-
1. A system comprising:
-
a plurality of capture components that are each configured to record network traffic to a capture file, and a management component that is configured to communicate with each of the plurality of capture components, identify at least one capture component based on a first capture condition, and effect an archiving of at least a portion of a capture file recorded by an identified capture component based on a second capture condition. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17)
-
-
18. A method comprising:
-
configuring a plurality of capture components, such that each capture component is configured to record network traffic to a capture file, configuring a management component such that the management component is configured to communicate with each of the plurality of capture components, defining a first capture condition, defining a second capture condition, identifying at least one of the capture components based on the first capture condition, archiving at least a portion of a capture file recorded by an identified capture component based on the second capture condition. - View Dependent Claims (19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34)
-
-
35. A computer program product stored on a computer readable medium, which, when executed by a processor, causes the processor to:
-
instruct each of a plurality of capture components to record network traffic to a capture file, instruct a management component to communicate with each of the plurality of capture components, receive a first capture condition, receive a second capture condition, identify at least one of the capture components based on the first capture condition, archive at least a portion of a capture file recorded by an identified capture component based on the second capture condition. - View Dependent Claims (36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51)
-
Specification