System and method for real-time analysis of network traffic
First Claim
1. A method for monitoring live-data flow through a network, comprising:
- monitoring, at a first processing node, a mirrored live-data flow of the live-data flow passing through a selected point within the network in a non-intrusive manner that does not affect the live-data flow passing through the selected point, wherein the live-data flow comprises data that is in active transmission between endpoints in the network and prior to onward storage of the data in a database;
decoding, at the first processing node, each packet within the mirrored data flow according to each protocol associated with a packet, wherein packets have a plurality of protocols associated therewith are decoded in parallel with each other;
comparing, at the first processing node, each of the decoded packets to at least one of a set of predetermined or deduced conditions received from a second processing node;
executing at least one of a predetermined or deduced response including an indication of occurrence of the at least one predetermined or deduced condition based upon detection of the at least one predetermined or deduced condition within the decoded packets;
processing, at the second processing node, at least a portion of the decoded packets of the live-data flow causing execution of the at least one predetermined or deduced response to determine a manner for controlling an operation of the network at a same time the live-data flow is in active transmission between the endpoints in the network; and
controlling the operation of the network in response to the processing step while events associated with the live-data flow are occurring within the network.
1 Assignment
0 Petitions
Accused Products
Abstract
A mirrored live-data flow of the live-data flow passing through a selected point within a network is monitored at a first processing node. The live-data flow comprises data that is in active transmission between endpoints in the network and prior to exit from the network and onward storage of the data in a database. Each packet within the mirrored data flow is decoded at the first processing node according to each protocol associated with a packet. Packets having a plurality of protocols associated therewith are decoded in parallel with each other. Each of the decoded packets are compared at the first processing node to a set of predetermined or deduced conditions. A predetermined or deduced response is executed based upon detection of a predetermined or deduced condition within the decoded packets. At least a portion of the decoded packets of the live-data flow causing execution of the predetermined or deduced response are processed at a second processing node to determine a manner for controlling an operation of the network at a same time the live-data flow is in active transmission between the endpoints in the network. The operation of the network is controlled in response to the processing step.
-
Citations
29 Claims
-
1. A method for monitoring live-data flow through a network, comprising:
-
monitoring, at a first processing node, a mirrored live-data flow of the live-data flow passing through a selected point within the network in a non-intrusive manner that does not affect the live-data flow passing through the selected point, wherein the live-data flow comprises data that is in active transmission between endpoints in the network and prior to onward storage of the data in a database; decoding, at the first processing node, each packet within the mirrored data flow according to each protocol associated with a packet, wherein packets have a plurality of protocols associated therewith are decoded in parallel with each other; comparing, at the first processing node, each of the decoded packets to at least one of a set of predetermined or deduced conditions received from a second processing node; executing at least one of a predetermined or deduced response including an indication of occurrence of the at least one predetermined or deduced condition based upon detection of the at least one predetermined or deduced condition within the decoded packets; processing, at the second processing node, at least a portion of the decoded packets of the live-data flow causing execution of the at least one predetermined or deduced response to determine a manner for controlling an operation of the network at a same time the live-data flow is in active transmission between the endpoints in the network; and controlling the operation of the network in response to the processing step while events associated with the live-data flow are occurring within the network. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. A system for monitoring live-data flow through a network, comprising:
-
a server communicating with the network; a network interface card associated with the server for providing access to the data flow through the network; a processor within the server the processor implementing a first processing node for; monitoring, at a first processing node, a mirrored live-data flow of the live-data flow passing through a selected point within the network in a non-intrusive manner that does not affect the live-data flow passing through the selected point, wherein the live-data flow comprises data that is in active transmission between endpoints in the network and prior to storage of the data in a database; decoding, at the first processing node, each packet within the mirrored data flow according to each protocol associated with a packet, wherein packets have a plurality of protocols associated therewith are decoded in parallel with each other; comparing, at the first processing node, each of the decoded packets to at least one of a set of predetermined or deduced conditions; executing at least one of a predetermined or deduced response including an indication of occurrence of the at least one predetermined or deduced condition based upon detection of at least one predetermined or deduced condition within the decoded packets; the processor within the server the processor further implementing a second processing node for; processing, at a second processing node, at least a portion of the decoded packets of the live-data flow causing execution of the at least one predetermined or deduced response to determine a manner for controlling an operation of the network at a same time the live-data flow is in active transmission between the endpoints in the network, wherein controlling comprises alerting or instructing a network provider to affect an event outcome before the event is finalized; and controlling the operation of the network in response to the processing step while events associated with the live-data flow are occurring within the network. - View Dependent Claims (11, 12, 13, 14, 15, 16, 17, 18, 19, 20)
-
-
21. A system for monitoring live-data flow through a network, comprising:
-
a network interface for connecting to the network; a processor coupled to the network interface; a memory coupled to the processor, the memory storing a plurality of instructions for execution by the processor, the plurality of instructions including; instructions for monitoring, at a first processing node, a mirrored live-data flow of the live-data flow passing through a selected point within the network in a non-intrusive manner that does not affect the live-data flow passing through the selected point, wherein the live-data flow comprises data that is in active transmission between endpoints in the network and prior to storage of the data in a database; instructions for decoding, at the first processing node, each packet within the mirrored data flow according to each protocol associated with a packet, wherein packets have a plurality of protocols associated therewith are decoded in parallel with each other; instructions for comparing, at the first processing node, each of the decoded packets to at least one of a set of predetermined or deduced conditions; instructions for executing at least one of a predetermined or deduced response including an indication of occurrence of the at least one predetermined or deduced condition based upon detection of at least one of a predetermined or deduced condition within the decoded packets; instructions for processing, at a second processing node, at least a portion of the decoded packets of the live-data flow causing execution of the at least one predetermined or deduced response to determine a manner for controlling an operation of the network at a same time the live-data flow is in active transmission between the endpoints in the network; and instructions for controlling the operation of the network in response to the processing step, while events associated with the live-data flow are occurring within the network. - View Dependent Claims (22, 23, 24, 25, 26, 27, 28, 29)
-
Specification