Apparatus and method for monitoring and interpretation of application protocols for network data transmission systems
First Claim
Patent Images
1. An apparatus for monitoring and interpretation of application protocols for network data transmission systems comprising:
- a data packets monitoring device (9) at a layer corresponding to the OSI layer 2, said data packets comprising control frames and information frames, wherein the control and information frames contain a header portion and a body portion, said header portion allowing the distinction between an information frame and a control frame;
a control unit (15) receiving as an input the data coming from the monitoring device (9) and comprising means for the discrimination of the control frames from the information frames;
a dating unit (16) connected to the control unit (15) and associating a monitoring time to the control frames and to the information frames; and
a discriminated data storing unit (17), storing the control and the information frames and the monitoring time thereof, bidirectionally connected to the control unit (15), characterised in that it further comprises;
a) a predetermined data storing unit (18), bidirectionally connected to the control unit (15), said predetermined data representing possible interpretations of the information frames contained in the discriminated data storing unit (17);
b) means for comparing, by the control unit (15), said predetermined data stored in the storing unit (18) with the data contained in the body portion of the information frames stored in the discriminated data storing unit (17), thus reconstructing the information frames according to their specific application syntax;
c) means for ordering, according to the time and kind of communication, the information frames reconstructed according to their specific application syntax, thus reconstructing application sequences occurred between a determined source processor and a determined destination processor; and
d) means for ordering said information frames ordered according to the time and kind of communication also according to a logical criterion, thus reconstructing the logical path of said application sequences occurred between a determined source processor and a determined destination processor.
6 Assignments
0 Petitions
Accused Products
Abstract
An apparatus and a method for monitoring and interpretation of application protocols for network data transmission systems are provided, wherein the apparatus comprises: a data packets monitoring device (9); a control unit (15) receiving the data coming from the monitoring device (9) and discriminating them in control and information frames; a dating unit (16) connected to the control unit (15), for obtaining a reconstruction of a tree structure containing statistic information depending on the kind of communication for a certification of the communications and a monitoring of possible anomalies.
20 Citations
4 Claims
-
1. An apparatus for monitoring and interpretation of application protocols for network data transmission systems comprising:
-
a data packets monitoring device (9) at a layer corresponding to the OSI layer 2, said data packets comprising control frames and information frames, wherein the control and information frames contain a header portion and a body portion, said header portion allowing the distinction between an information frame and a control frame;
a control unit (15) receiving as an input the data coming from the monitoring device (9) and comprising means for the discrimination of the control frames from the information frames;
a dating unit (16) connected to the control unit (15) and associating a monitoring time to the control frames and to the information frames; and
a discriminated data storing unit (17), storing the control and the information frames and the monitoring time thereof, bidirectionally connected to the control unit (15), characterised in that it further comprises; a) a predetermined data storing unit (18), bidirectionally connected to the control unit (15), said predetermined data representing possible interpretations of the information frames contained in the discriminated data storing unit (17);
b) means for comparing, by the control unit (15), said predetermined data stored in the storing unit (18) with the data contained in the body portion of the information frames stored in the discriminated data storing unit (17), thus reconstructing the information frames according to their specific application syntax;
c) means for ordering, according to the time and kind of communication, the information frames reconstructed according to their specific application syntax, thus reconstructing application sequences occurred between a determined source processor and a determined destination processor; and
d) means for ordering said information frames ordered according to the time and kind of communication also according to a logical criterion, thus reconstructing the logical path of said application sequences occurred between a determined source processor and a determined destination processor. - View Dependent Claims (2, 3)
-
-
4. A method for monitoring and interpretation of application protocols for network data transmission systems comprising the steps of:
-
monitoring data packets at a layer corresponding to the OSI layer 2, said data packets comprising control frames and information frames, wherein the control and information frames contain a header portion and a body portion, said header portion allowing the distinction between an information frame and a control frame;
discriminating the control frames from the information frames;
associating a monitoring time to the control frames and information frames; and
storing the discriminated control frames and information frames together with their monitoring time, characterized in that it further comprises the steps of; a) storing predetermined data representing possible interpretations of the information frames;
b) comparing said predetermined data with the data contained in the body portion of the stored information frames, thus reconstructing the information frames according to their specific application syntax;
c) ordering, according to the time and kind of communication, the information frames reconstructed according to their specific application syntax, thus reconstructing application sequences occurred between a determined source processor and a determined destination processor; and
d) ordering said information frames ordered according to the time and kind of communication also according to a logical criterion by reciprocally comparing the body portion of the information frames, thus reconstructing the logical path of said application sequences occurred between a determined source processor and a determined destination processor.
-
Specification