×

Efficient access to sparse packets in large repositories of stored network traffic

  • US 9,537,972 B1
  • Filed: 02/05/2015
  • Issued: 01/03/2017
  • Est. Priority Date: 02/20/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • capturing a first packet from a network;

    annotating the first packet with a time stamp specifying an arrival time of the first packet;

    s storing the first packet in a first data file of a set of data files organized at predetermined intervals, the first data file dedicated to a first predetermined interval based on the time stamp;

    creating a first primary index for the first packet, the first primary index containing a path and an offset to the first packet stored in the first data file;

    storing the first primary index for the first packet in a first primary index file associated with the first data file dedicated to the first predetermined interval; and

    creating a secondary index for the first packet, the secondary index having an ordered sequence of present bits, wherein a first present bit corresponds to the first primary index and the first data file dedicated to the first predetermined interval, and wherein an asserted value of the first present bit indicates presence of a target value in the first packet stored in the first data file over a search time window.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×