Network monitoring system
First Claim
1. A network monitoring system that monitors a communication within a network including a plurality of terminals, the terminals including at least a client and a server, the terminals communicating a plurality of action contents with each other, each action content having a group of associated packets, the network monitoring system comprising:
- a data acquisition section that acquires a plurality of packets flown on the network;
a data analysis section that analyzes each of the packets to extract the group of associated packets from all the packets and that acquires an action content from the group of associated packets, the data analysis section extracting a plurality of groups of the associated packets and acquiring a plurality of action contents therefrom;
a display-information generation section that generates display information by chronologically aligning the plurality of action contents to correspond to respective times when the action contents are actually communicated; and
a display unit that displays an association graph indicating the terminals within the network and that overlaps additional objects on the association graph the additional objects being generated in accordance with the display, the additional objects being overlapped on the association graph in a chronological order corresponding to the respective times when the action contents are actually communicated,wherein the additional objects include;
the type of operating system employed by the client,the type of operating system employed by the server,an account name of a user accessing the client, andan icon representing the account name.
1 Assignment
0 Petitions
Accused Products
Abstract
In a network monitoring system according, first, a data acquisition section acquires a plurality of packets flowing on a network. Then, a data analysis section acquires action explanation information for explaining a single action from the plural packets acquired by the data acquisition section. Then, a display-information generation section displays the single action on the network on the single screen based on the action explanation information acquired by this data analysis section.
16 Citations
27 Claims
-
1. A network monitoring system that monitors a communication within a network including a plurality of terminals, the terminals including at least a client and a server, the terminals communicating a plurality of action contents with each other, each action content having a group of associated packets, the network monitoring system comprising:
-
a data acquisition section that acquires a plurality of packets flown on the network; a data analysis section that analyzes each of the packets to extract the group of associated packets from all the packets and that acquires an action content from the group of associated packets, the data analysis section extracting a plurality of groups of the associated packets and acquiring a plurality of action contents therefrom; a display-information generation section that generates display information by chronologically aligning the plurality of action contents to correspond to respective times when the action contents are actually communicated; and a display unit that displays an association graph indicating the terminals within the network and that overlaps additional objects on the association graph the additional objects being generated in accordance with the display, the additional objects being overlapped on the association graph in a chronological order corresponding to the respective times when the action contents are actually communicated, wherein the additional objects include; the type of operating system employed by the client, the type of operating system employed by the server, an account name of a user accessing the client, and an icon representing the account name. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 25)
-
-
9. A network monitoring method for monitoring a communication within a network including a plurality of terminals, the terminals including at least a client and a server, the terminals communicating a plurality of action contents with each other, each action content having a group of associated packets, the method comprising:
-
acquiring a plurality of packets flown on the network; analyzing each of the packets to extract the group of associated packets from all the packets and acquiring an action content from the group of associated packets, and extracting a plurality of groups of the associated packets and acquiring a plurality of action contents therefrom; generating display information by chronologically aligning the plurality of action contents to correspond to respective times when the action contents are actually communicated; and displaying an association graph indicating the terminals within the network and overlapping additional objects on the association graph, the additional objects being generated in accordance with the display, the additional objects being overlapped on the association graph in a chronological order corresponding to the respective times when the action contents are actually communicated, wherein the additional objects include; the type of operating system employed by the client, the type of operating system employed by the server, an account name of a user accessing the client, and an icon representing the account name. - View Dependent Claims (10, 11, 12, 13, 14, 15, 16, 26)
-
-
17. A network monitoring program recorded on a non-transitory computer readable storage medium and executable by a computer, the program making the computer monitor a communication within a network including a plurality of terminals, the terminals including at least a client and a server, the terminals communicating a plurality of action contents with each other, each action content having a group of associated packets, and perform a process comprising:
-
acquiring a plurality of packets flown on the network; analyzing each of the packets to extract the group of associated packets from all the packets and acquiring an action content from the group of associated packets, and extracting a plurality of groups of the associated packets and acquiring a plurality of action contents therefrom; generating display information by chronologically aligning the plurality of action contents to correspond to respective times when the action contents are actually communicated; and displaying an association graph indicating the terminals within the network and overlapping additional objects on the association graph, the additional objects being generated in accordance with the display, the additional objects being overlapped on the association graph in a chronological order corresponding to the respective times when the action contents are actually communicated, wherein the additional objects include the type of operating system employed by the client, the type of operating system employed by the server, an account name of a user accessing the client, and an icon representing the account name. - View Dependent Claims (18, 19, 20, 21, 22, 23, 24, 27)
-
Specification