NETWORK TRAFFIC MONITORING DEVICES AND MONITORING SYSTEMS, AND ASSOCIATED METHODS
First Claim
1. A monitoring device, comprising:
- a communication module configured to capture wireless communications of a wireless device within a monitored area; and
processing circuitry coupled with the communication module and configured to;
form a new cluster comprising at least a portion of the captured wireless communications according to at least one specific parameter identified in the at least a portion of the captured wireless communications;
generate at least one rule set relating to the formed new cluster;
combine the at least one rule set to a current rule set representing previous wireless communications to create an updated rule set;
compare the captured wireless communications to the updated rule set to determine a difference from the previous wireless communications; and
generate an alert if the difference is greater than a predetermined threshold.
2 Assignments
0 Petitions
Accused Products
Abstract
Network traffic monitoring devices and monitoring systems include a communication module for capturing wireless communications of a wireless device. Processing circuitry is coupled with the communications module and configured to form a new cluster or refine an existing cluster from the captured wireless communications, in which the cluster includes wireless communications having one or more relevant parameters. The processing circuitry is also configured to generate/refine at least one rule set relating to the clusters, create an updated rule set by combining the one or more rule sets to current rule sets, and to compare the captured wireless communications to the updated rule set to determine whether the wireless communications pose a potential threat. Methods of monitoring network traffic are also provided.
-
Citations
25 Claims
-
1. A monitoring device, comprising:
-
a communication module configured to capture wireless communications of a wireless device within a monitored area; and processing circuitry coupled with the communication module and configured to; form a new cluster comprising at least a portion of the captured wireless communications according to at least one specific parameter identified in the at least a portion of the captured wireless communications; generate at least one rule set relating to the formed new cluster; combine the at least one rule set to a current rule set representing previous wireless communications to create an updated rule set; compare the captured wireless communications to the updated rule set to determine a difference from the previous wireless communications; and generate an alert if the difference is greater than a predetermined threshold. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. A system for monitoring network traffic, comprising:
-
at least one analysis sensor device comprising; a communications module configured to capture wireless communications of a wireless device within a monitored area; and programming configured to;
form a new cluster comprising at least a portion of the captured wireless communications which comprise at least one relevant parameter;
generate at least one rule set relating to the new cluster;
combine the at least one rule set to a current rule set representing previous wireless communications to form an updated rule set; and
compare the at least a portion of the captured wireless communications to the updated rule set to determine whether the captured wireless communications pose a potential threat;at least one storage media accessible by the programming and configured to store at least the current rule; and a visualization and control system coupled to the at least one analysis sensor device and configured to generate a visual representation of at least a portion of the captured wireless communications. - View Dependent Claims (10, 11, 12, 13, 14)
-
-
15. A method of monitoring network traffic, comprising:
-
capturing wireless communications from at least one wireless device; forming at least one new cluster comprising at least a portion of the captured wireless communications having at least one relevant parameter; generating at least one rule set from the at least one cluster; creating an updated rule set comprising a combination of the at least one rule set with a current rule set representing previous wireless communications; evaluating the difference of the at least one rule set from the updated rule set and deriving a threat level for the captured wireless communications based on the evaluation. - View Dependent Claims (16, 17, 18, 19, 20, 21, 22, 23, 24, 25)
-
Specification