×

Intelligent feedback loop to iteratively reduce incoming network data for analysis

  • US 9,350,762 B2
  • Filed: 09/25/2012
  • Issued: 05/24/2016
  • Est. Priority Date: 09/25/2012
  • Status: Active Grant
First Claim
Patent Images

1. A non-transitory medium, readable through a network traffic monitoring system used by a data interception system and comprising instructions embodied therein that are executable through the network traffic monitoring system, comprising:

  • instructions to process flow data from a computer network received through an aggregation switch of the network traffic monitoring system in a first stage module of the network traffic monitoring system;

    instructions to identify target network activities of interest to the data interception system;

    instructions to filter the flow data to target data based on packet classification in the first stage module, the target data being associated with the identified target network activities of interest to the data interception system;

    instructions to determine that a portion of the target data is extraneous data in a data processing system of the network traffic monitoring system based on classifying the target data according to an analysis of protocols associated therewith through a hardware component of the data processing system, the extraneous data being the portion of the target data that is determined to be;

    irrelevant in the network traffic monitoring system used by the data interception system and innocuous with respect to a threat level thereof based on the classification of the target data, and the data processing system being commodity hardware in a second stage of the network traffic monitoring system communicatively coupled to the first stage module;

    instructions to extract metadata associated with the target data in the data processing system;

    instructions to produce, through the data processing system, a set of regular expressions describing a search pattern in the target data;

    instructions to analyze the target data to discover an action of interest in the set of regular expressions associated with a target individual in the data processing system, the action of interest corresponding to an identified target network activity of interest; and

    instructions to utilize, through the data processing system, instructions to monitor the computer network for specific network activities of interest to the data interception system, the instructions to monitor the computer network for the specific network activities of interest comprising instructions to iteratively remove from the target data the extraneous data based on creating a feedback loop between the data processing system and the first stage module of the network traffic monitoring system, the feedback loop being a control system configured to adjust operation thereof between an actual output and a desired output of the data processing system, and the feedback loop involving a modification in data processing through the first stage module to effect the desired output of the data processing system.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×