Correlating Packets in Communications Networks/US
2 Assignments
0 Petitions
Accused Products
Abstract
A computing system may identify packets received by a network device from a host located in a first network and may generate log entries corresponding to the packets received by the network device. The computing system may identify packets transmitted by the network device to a host located in a second network and may generate log entries corresponding to the packets transmitted by the network device. Utilizing the log entries corresponding to the packets received by the network device and the log entries corresponding to the packets transmitted by the network device, the computing system may correlate the packets transmitted by the network device with the packets received by the network device.
10 Citations
21 Claims
-
1. (canceled)
-
2. A method comprising:
-
generating, by a computing system, a plurality of log entries corresponding to a plurality of packets received by a network device from a first host located in a first network, each of the plurality of log entries comprising a receipt timestamp indicating a packet receipt time; generating, by the computing system, a plurality of log entries corresponding to a plurality of packets transmitted by the network device to a second host located in a second network, each of the plurality of log entries comprising a transmission timestamp indicating a packet transmission time; determining, by the computing system and for each transmission timestamp indicating a packet transmission time, differences between at least one packet transmission time indicated by transmission timestamps and at least one packet receipt time indicated by receipt timestamps; correlating, by the computing system and based on the plurality of log entries corresponding to the plurality of packets received by the network device and based on the plurality of log entries corresponding to the plurality of packets transmitted by the network device, at least a portion of the plurality of packets transmitted by the network device with at least a portion of the plurality of packets received by the network device based on the determined differences; and responsive to correlating the at least the portion of the plurality of packets transmitted by the network device with the at least the portion of the plurality of packets received by the network device; generating, by the computing system, data identifying the first host located in the first network; and communicating, by the computing system, the data identifying the first host located in the first network. - View Dependent Claims (3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. An apparatus comprising:
-
at least one processor; and a memory storing instructions that when executed by the at least one processor cause the apparatus to; generate, by the apparatus, a plurality of log entries corresponding to a plurality of packets received by a network device from a first host located in a first network, each of the plurality of log entries comprising a receipt timestamp indicating a packet receipt time; generate, by the apparatus, a plurality of log entries corresponding to the plurality of packets transmitted by the network device to a second host located in a second network, each of the plurality of log entries comprising a transmission timestamp indicating a packet transmission time; determine, by the apparatus and for each transmission timestamp indicating a packet transmission time, differences between at least one packet transmission time indicated by transmission timestamps and at least one packet receipt time indicated by receipt timestamps; correlate, by the apparatus and based on the plurality of log entries corresponding to the plurality of packets received by the network device and based on the plurality of log entries corresponding to the plurality of packets transmitted by the network device, at least a portion of the plurality of packets transmitted by the network device with at least a portion of the plurality of packets received by the network device based on the determined differences; and responsive to correlating the at least the portion of the plurality of packets transmitted by the network device with the at least the portion of the plurality of packets received by the network device; generate, by the apparatus, data identifying the first host located in the first network; and communicate, by the apparatus, the data identifying the first host located in the first network. - View Dependent Claims (13, 14, 15, 16, 17, 18, 19, 20, 21)
-
Specification