Method, apparatus and system for filtering captured network traffic
First Claim
1. A method comprising:
- receiving instructions, at a network captured traffic distribution device communicatively coupled to a plurality of network captured network traffic distribution devices arranged in a stacked topology in which the network captured traffic distribution device exchanges configuration information with at least one of the plurality of network captured traffic distribution devices, to filter received captured network traffic according to one or more criterion, the captured network traffic being a copy of the network traffic flowing through a communication network to a first target destination;
receiving captured network traffic by the network captured network traffic distribution device from at least one of an inline traffic capture point and a minor port;
filtering in accordance with the configuration information, by the network captured network traffic distribution device, the received captured network traffic responsively to the received instructions, wherein the received instructions include a criterion used to filter the received captured network traffic;
generating, by the network captured traffic distribution device, a plurality of filtered captured network traffic sets from the filtered captured network traffic;
determining, by the network captured network traffic distribution device, a second target destination of each filtered captured network traffic set;
determining, by the network captured traffic distribution device, filtered captured network traffic sets of the plurality of filtered captured network traffic sets that have a same second target destination;
aggregating, by the network captured traffic distribution device, the filtered captured network traffic sets determined to have the same second target destination; and
transmitting, by the network captured network traffic distribution device, the aggregated filtered captured network traffic sets toward the second target destination determined for the aggregated filtered captured network traffic sets.
3 Assignments
0 Petitions
Accused Products
Abstract
Methods, systems, computer-readable media, and devices for filtering captured network traffic received by a network captured traffic distribution device communicatively coupled to a plurality of network captured network traffic distribution devices arranged in a stacked topology are described. Methods, systems, computer-readable media, and devices for applying a plurality of filters to received captured network traffic by a network captured traffic distribution device communicatively coupled to a plurality of network captured network traffic distribution devices arranged in a stacked topology are also described. Applying a plurality of filters to the received captured traffic may generate a plurality of filtered captured traffic sets. In some instances, filtered captured network traffic sets that have similar target destinations may be aggregated together and transmitted toward the target destination.
40 Citations
18 Claims
-
1. A method comprising:
-
receiving instructions, at a network captured traffic distribution device communicatively coupled to a plurality of network captured network traffic distribution devices arranged in a stacked topology in which the network captured traffic distribution device exchanges configuration information with at least one of the plurality of network captured traffic distribution devices, to filter received captured network traffic according to one or more criterion, the captured network traffic being a copy of the network traffic flowing through a communication network to a first target destination; receiving captured network traffic by the network captured network traffic distribution device from at least one of an inline traffic capture point and a minor port; filtering in accordance with the configuration information, by the network captured network traffic distribution device, the received captured network traffic responsively to the received instructions, wherein the received instructions include a criterion used to filter the received captured network traffic; generating, by the network captured traffic distribution device, a plurality of filtered captured network traffic sets from the filtered captured network traffic; determining, by the network captured network traffic distribution device, a second target destination of each filtered captured network traffic set; determining, by the network captured traffic distribution device, filtered captured network traffic sets of the plurality of filtered captured network traffic sets that have a same second target destination; aggregating, by the network captured traffic distribution device, the filtered captured network traffic sets determined to have the same second target destination; and transmitting, by the network captured network traffic distribution device, the aggregated filtered captured network traffic sets toward the second target destination determined for the aggregated filtered captured network traffic sets. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A method comprising:
-
receiving captured network traffic from at least one of an inline traffic capture point and a mirror port at a network captured traffic distribution device communicatively coupled to a plurality of network captured network traffic distribution devices arranged in a stacked topology in which the network captured traffic distribution device exchanges configuration information with at least one of the plurality of network captured traffic distribution devices, the captured network traffic being a copy of the network traffic flowing through a communication network to a first target destination; applying, by the network captured traffic distribution device, a plurality of filters to the captured network traffic according to a criterion indicated by the configuration information; generating, by the network captured traffic distribution device, a plurality of filtered captured network traffic sets from the filtered captured network traffic; determining, by the network captured network traffic distribution device, a second target destination of each filtered captured network traffic set; determining, by the network captured traffic distribution device, filtered captured network traffic sets of the plurality of filtered captured network traffic sets that have a same second target destination; aggregating, by the network captured traffic distribution device, the filtered captured network traffic sets determined to have the same second target destination; and transmitting, by the network captured traffic distribution device, the aggregated filtered captured network traffic sets toward the second target destination determined for the aggregated filtered captured network traffic sets. - View Dependent Claims (9, 10)
-
-
11. An apparatus comprising:
-
a plurality of bi-directional ports configured to receive instructions to filter received captured network traffic according to one or more criteria, the instructions being at least one of included in configuration data and received from a user, and perform at least one of receiving captured network traffic from at least one of an inline traffic capture point and a mirror port, the captured network traffic being a copy of the network traffic flowing through a communication network to a first target destination and echoing received captured network traffic to one or more of the plurality of bi-directional ports; an egress port configured to transmit received captured network traffic to an external device; a stacking port configured to enable, via a communication link, the stacking of the network captured traffic distribution device with at least one additional network captured traffic distribution device in a stacked topology wherein the stacking includes an exchange of the configuration information between the network captured traffic distribution device and the additional network captured traffic distribution device; and a processor configured to filter, in accordance with the received instructions, the received captured network traffic responsively to the received instructions, wherein the received instructions include a criterion used to filter the received captured network traffic, the processor further configured to generate a plurality of filtered captured network traffic sets from the filtered captured network traffic, determine a second target destination of each filtered captured network traffic set, determine filtered captured network traffic sets of the plurality of filtered captured network traffic sets that have a same second target destination, aggregate the filtered captured network traffic sets determined to have the same second target destination, and and manage distribution of the aggregated filtered captured network traffic sets toward the second target destination determined for the aggregated filtered captured network traffic sets. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18)
-
Specification