System and method for IP target traffic analysis
First Claim
Patent Images
1. A method, comprising:
- acquiring, from a network, data traffic that is associated with a network connection;
analyzing the data traffic so as to identify individual users;
creating a list of one or more individuals who are served by the network connection by processing the acquired data traffic, wherein creating the list comprises distinguishing between two or more of the individuals by applying one or more disassociation criteria to User Identifiers (UIs) that the individuals use for login to one or more servers over the network, and further wherein distinguishing between the individuals comprises distinguishing between first and second groups of the UIs that do not share any common UI, by detecting an event in which all the UIs in the first group simultaneously log out, and, after a time delay that is shorter than a predetermined value, all the UIs in the second group simultaneously log in; and
outputting the created list of the individuals.
3 Assignments
0 Petitions
Accused Products
Abstract
Methods and systems for identifying network users who communicate with the network (e.g., the Internet) via a given network connection. The disclosed techniques analyze traffic that flows in the network to determine, for example, whether the given network connection serves a single individual or multiple individuals, a single computer or multiple computers. A Profiling System (PS) acquires copies of data traffic that flow through network connections that connect computers to the WAN. The PS analyzes the acquired data, attempting to identify individuals who login to servers.
26 Citations
16 Claims
-
1. A method, comprising:
-
acquiring, from a network, data traffic that is associated with a network connection; analyzing the data traffic so as to identify individual users; creating a list of one or more individuals who are served by the network connection by processing the acquired data traffic, wherein creating the list comprises distinguishing between two or more of the individuals by applying one or more disassociation criteria to User Identifiers (UIs) that the individuals use for login to one or more servers over the network, and further wherein distinguishing between the individuals comprises distinguishing between first and second groups of the UIs that do not share any common UI, by detecting an event in which all the UIs in the first group simultaneously log out, and, after a time delay that is shorter than a predetermined value, all the UIs in the second group simultaneously log in; and outputting the created list of the individuals. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. Apparatus, comprising:
-
an interface, which is configured to acquire, from a network, data traffic that is associated with a network connection; and a processor, which is configured to analyze the data traffic so as to identify individual users; and
create a list of one or more individuals who are served by the network connection by processing the acquired data traffic, wherein creating the list comprises distinguishing between two or more of the individuals by applying one or more disassociation criteria to User Identifiers (UIs) that the individuals use for login to one or more servers over the network, and further wherein distinguishing between the individuals comprises distinguishing between first and second groups of the UIs that do not share any common UI, by detecting an event in which all the UIs in the first group simultaneously log out, and, after a time delay that is shorter than a predetermined value, all the UIs in the second group simultaneously log in. - View Dependent Claims (11, 12, 13, 14, 15, 16)
-
Specification