TAG DATA STRUCTURE FOR MAINTAINING RELATIONAL DATA OVER CAPTURED OBJECTS
9 Assignments
0 Petitions
Accused Products
Abstract
Objects captured over a network by a capture system can be indexed to provide enhanced search and content analysis capabilities. In one embodiment the objects can be indexed using a data structure having a source address field to indicate an origination address of the object, a destination address field to indicate a destination address of the object, a source port field to indicate an origination port of the object, a destination port field to indicate a destination port of the object, a content field to indicate a content type from a plurality of content types identifying a type of content contained in the object, and a time field to indicate when the object was captured. The data structure may also store a cryptographic signature of the object to ensure the object is not altered after capture.
151 Citations
45 Claims
-
1-25. -25. (canceled)
-
26. Software encoded in one or more non-transitory media that includes code for execution and when executed by a processor operable to perform operations comprising:
-
receiving a data stream that includes a plurality of packets; and generating a tag for an object represented by the packets, wherein the tag includes; a source address field indicative of an origination address associated with the object, a destination address field indicative of a destination address associated with the object, a source port field indicative of an origination port associated with the object, a destination port field indicative of a destination port associated with the object, a content field indicative of a content type associated with the object, and a time field indicative of when the object was captured. - View Dependent Claims (27, 28, 29, 30, 31, 32, 33, 34, 35, 36)
-
-
37. A method, comprising:
-
receiving a data stream that includes a plurality of packets; and generating a tag for an object represented by the packets, wherein the tag includes; a source address field indicative of an origination address associated with the object, a destination address field indicative of a destination address associated with the object, a source port field indicative of an origination port associated with the object, a destination port field indicative of a destination port associated with the object, a content field indicative of a content type associated with the object, and a time field indicative of when the object was captured. - View Dependent Claims (38, 39, 40, 41, 42)
-
-
43. An apparatus, comprising:
-
a processor; and a memory, wherein the processor and the memory cooperate such that the apparatus is configured for; receiving a data stream that includes a plurality of packets; and generating a tag for an object represented by the packets, wherein the tag includes; a source address field indicative of an origination address associated with the object, a destination address field indicative of a destination address associated with the object, a source port field indicative of an origination port associated with the object, a destination port field indicative of a destination port associated with the object, a content field indicative of a content type associated with the object, and a time field indicative of when the object was captured. - View Dependent Claims (44, 45)
-
Specification