Attributes of captured objects in a capture system
First Claim
Patent Images
1. At least one non-transitory machine-readable medium having instructions stored therein and when executed, the instructions cause one or more processors to:
- capture a plurality of packets being transmitted over a network through a capture system that includes a processor and a network interface for receiving packets;
reconstruct a captured object from the plurality of packets, wherein the captured object is one of a plurality of captured objects reconstructed from the plurality of packets;
determine an association between the captured object and a computer name of a computer sending or receiving the captured object, wherein the association is determined by identifying a network address associated with the captured object and reading one or more log files of the network to determine the computer name associated with the network address, wherein the one or more log files are to be updated if the network address is assigned to another computer, wherein the captured object is to be stored in a storage location in a rolling storage;
generate metadata of the captured object, the metadata including an indication of an association between the storage location and the computer name of the computer; and
search a plurality of metadata of captured objects based on the computer name to determine one or more storage locations in the rolling storage that contain captured objects associated with the computer.
9 Assignments
0 Petitions
Accused Products
Abstract
A system and method for capturing objects and balancing systems resources in a capture system are described. An object is captured, metadata associated with the objected generated, and the object and metadata stored.
450 Citations
17 Claims
-
1. At least one non-transitory machine-readable medium having instructions stored therein and when executed, the instructions cause one or more processors to:
-
capture a plurality of packets being transmitted over a network through a capture system that includes a processor and a network interface for receiving packets; reconstruct a captured object from the plurality of packets, wherein the captured object is one of a plurality of captured objects reconstructed from the plurality of packets; determine an association between the captured object and a computer name of a computer sending or receiving the captured object, wherein the association is determined by identifying a network address associated with the captured object and reading one or more log files of the network to determine the computer name associated with the network address, wherein the one or more log files are to be updated if the network address is assigned to another computer, wherein the captured object is to be stored in a storage location in a rolling storage; generate metadata of the captured object, the metadata including an indication of an association between the storage location and the computer name of the computer; and search a plurality of metadata of captured objects based on the computer name to determine one or more storage locations in the rolling storage that contain captured objects associated with the computer. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A capture system for capturing objects propagating through a network, the capture system comprising:
-
at least one processor; a network interface module that, when executed by the at least one processor, is to receive a plurality of packets being transmitted over the network; a packet capture module that, when executed by the at least one processor, is to capture the plurality of packets received by the network interface module; and an object assembly module that, when executed by the at least one processor, is to reconstruct a captured object from the plurality of packets, wherein the captured object is one of a plurality of captured objects reconstructed from the plurality of packets, wherein the capture system is to; determine an association between the captured object and a computer name of a computer sending or receiving the captured object, wherein the association is determined by identifying a network address associated with the captured object and reading one or more log files of the network to determine the computer name associated with the network address, wherein the one or more log files are to be updated if the network address is assigned to another computer; store the captured object in a storage location of a rolling storage; generate metadata of the captured object, the metadata including an indication of an association between the storage location and the computer name of the computer; and search a plurality of metadata of captured objects based on the computer name to determine one or more storage locations in the rolling storage that contain captured objects associated with the computer. - View Dependent Claims (9, 10, 11, 12)
-
-
13. A method, comprising:
-
capturing a plurality of packets being transmitted over a network through a capture system that includes a processor and a network interface for receiving packets; reconstructing a captured object from the plurality of packets, wherein the captured object is one of a plurality of captured objects reconstructed from the plurality of packets; determine an association between the captured object and a computer name of a computer sending or receiving the captured object, wherein the association is determined by identifying a network address associated with the captured object and reading one or more log files of the network to determine the computer name associated with the network address, wherein the one or more log files are to be updated if the network address is assigned to another computer, wherein the capture system is to store the captured object in a storage location of a rolling storage; generate metadata of the captured object, the metadata including an indication of an association between the storage location and the computer name of the computer; and search a plurality of metadata of captured objects based on the computer name to determine one or more storage locations in the rolling storage that contain captured objects associated with the computer. - View Dependent Claims (14, 15, 16, 17)
-
Specification