×

Monitoring network traffic by using a monitor device

  • US 7,941,827 B2
  • Filed: 04/04/2006
  • Issued: 05/10/2011
  • Est. Priority Date: 02/26/2004
  • Status: Active Grant
First Claim
Patent Images

1. A computer implemented method for associating packets according to user information defined in a directory service available through a networked environment, the networked environment providing an authentication service and a name service and including at least one client, the method comprising:

  • at a collector, obtaining user information from the directory service by obtaining at least one user object attribute set from the directory service, the directory service maintaining a directory of objects in a hierarchical framework, each of the objects representing a network entity and one or more attributes of the network entity, the hierarchical framework categorizing each of the objects as one of;

    a resource;

    a service; and

    a person;

    at a monitor configured to connect to the collector,identifying at least one authentication exchange packet from packets traversing on the networked environment;

    extracting a first user ID and a first network address from the authentication exchange packet;

    filtering packets traversing on the network environment that each have a network address equivalent to the first network address; and

    at the collector, associating packets found in the filtering with the user information having a user name attribute equivalent to the first user ID.

View all claims
  • 8 Assignments
Timeline View
Assignment View
    ×
    ×