ATTRIBUTES OF CAPTURED OBJECTS IN A CAPTURE SYSTEM
9 Assignments
0 Petitions
Accused Products
Abstract
A system and method for capturing objects and balancing systems resources in a capture system are described. An object is captured, metadata associated with the objected generated, and the object and metadata stored.
18 Citations
40 Claims
-
1-16. -16. (canceled)
-
17. At least one non-transitory machine-readable medium having instructions stored therein and when executed, the instructions cause one or more processors to:
-
capture a plurality of packets being transmitted over a network through a capture system that includes a processor and a network interface for receiving packets; reconstruct a captured object from the plurality of packets, wherein the captured object is one of a plurality of captured objects reconstructed from the plurality of packets; and determine an association between the captured object and a computer name of a computer sending or receiving the captured object, wherein the association is determined from one or more log files of the network, wherein the capture system is configured to operate in a temporal identification mode, which uses a rolling storage mechanism to store the captured object and to indicate the association between the captured object and the computer name of the computer. - View Dependent Claims (18, 19, 20, 21, 22, 23, 24)
-
-
25. A capture system for capturing objects propagating through a network, the capture system comprising:
-
a network interface module configured to receive a plurality of packets being transmitted over the network; a packet capture module configured to capture the plurality of packets received by the network interface module; and an object assembly module configured to reconstruct a captured object from the plurality of packets, wherein the captured object is one of a plurality of captured objects reconstructed from the plurality of packets, wherein the capture system is configured to operate in a temporal identification mode to determine an association between the captured object and a computer name of a computer sending or receiving the captured object, wherein the association is determined from one or more log files of the network, wherein a rolling storage mechanism is used in the temporal identification mode to store the captured object and to indicate the association between the captured object and the computer name of the computer. - View Dependent Claims (26, 27, 28, 29, 30)
-
-
31. A method, comprising:
-
capturing a plurality of packets being transmitted over a network through a capture system that includes a processor and a network interface for receiving packets; reconstructing a captured object from the plurality of packets, wherein the captured object is one of a plurality of captured objects reconstructed from the plurality of packets; and determining an association between the captured object and a computer name of a computer sending or receiving the captured object, wherein the association is determined from one or more log files of the network, wherein the capture system is configured to operate in a temporal identification mode, which uses a rolling storage mechanism to store the captured object and to indicate the association between the captured object and the computer name of the computer. - View Dependent Claims (32, 33, 34, 35)
-
-
36. At least one non-transitory machine-readable medium having instructions stored therein and when executed, the instructions cause one or more processors to:
-
capture a plurality of packets being transmitted over a network through a capture system that includes a processor and a network interface for receiving packets; reconstruct a captured object from the plurality of packets; and generate metadata of the captured object, the metadata including an indication of a mode in which the capture system is configured to operate, wherein, when the metadata indicates the capture system is in a temporal identification mode, the instructions cause the one or more processors to; determine an association between the captured object and a computer name of a computer sending or receiving the captured object; and indicate, in the metadata of the captured object, the association between the captured object and the computer name of the computer, wherein, when the metadata indicates the capture system is in a tiered location tagging mode, the instructions cause the one or more processors to; determine a tiered location classification of a captured packet associated with the captured object; indicate, in the metadata of the captured object, the tiered location classification associated with the captured packet. - View Dependent Claims (37, 38, 39, 40)
-
Specification