Query generation for a capture system
First Claim
Patent Images
1. An apparatus, comprising:
- a processor;
a memory; and
a query generator configured to issue a query for a selected object included in a plurality of objects that are stored, wherein the objects are identified within packets that are captured at a network interface configured to receive the packets, and wherein the objects are stored with one or more respective tags indicative of characteristics of the objects, and wherein the query includes one or more regular expressions and at least one of the regular expressions are matched to an attribute, and wherein a first object is stored with a first attribute such that identification of the first attribute is used to determine whether the first object is relevant to the query, and wherein the first attribute is a selected one of a group of attributes, the group consisting of;
a) a document type;
b) an Internet protocol (IP) address from which the packets were sent or to where the packets were delivered;
c) an application type that generated the packets;
d) a size of a document associated with the packets; and
e) a time range in which the document associated with the packets was sent or received.
11 Assignments
0 Petitions
Accused Products
Abstract
A document accessible over a network can be registered. A registered document, and the content contained therein, is not transmitted undetected over and off of the network. In one embodiment, the invention includes a manager agent to maintain signatures of registered documents and a match agent to detect the unauthorized transmission of the content of registered documents.
-
Citations
20 Claims
-
1. An apparatus, comprising:
-
a processor; a memory; and a query generator configured to issue a query for a selected object included in a plurality of objects that are stored, wherein the objects are identified within packets that are captured at a network interface configured to receive the packets, and wherein the objects are stored with one or more respective tags indicative of characteristics of the objects, and wherein the query includes one or more regular expressions and at least one of the regular expressions are matched to an attribute, and wherein a first object is stored with a first attribute such that identification of the first attribute is used to determine whether the first object is relevant to the query, and wherein the first attribute is a selected one of a group of attributes, the group consisting of; a) a document type; b) an Internet protocol (IP) address from which the packets were sent or to where the packets were delivered; c) an application type that generated the packets; d) a size of a document associated with the packets; and e) a time range in which the document associated with the packets was sent or received. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15)
-
-
16. Logic encoded in one or more tangible media that includes code for execution and when executed by a processor operable to perform operations comprising:
processing a query for a selected object included in a plurality of objects that are stored, wherein the objects are identified within packets that are captured at a network interface configured to receive the packets, and wherein the objects are stored with one or more respective tags indicative of characteristics of the objects, wherein the query includes one or more regular expressions and at least one of the regular expressions are matched to an attribute, and wherein a first object is stored with a first attribute such that identification of the first attribute is used to determine whether the first object is relevant to the query, and wherein the first attribute is a selected one of a group of attributes, the group consisting of; a) a document type; b) an Internet protocol (IP) address from which the packets were sent or to where the packets were delivered; c) an application type that generated the packets; d) a size of a document associated with the packets; and e) a time range in which the document associated with the packets was sent or received. - View Dependent Claims (17, 18, 19, 20)
Specification