×

Real-time content detection in ISP transmissions

  • US 8,190,581 B2
  • Filed: 12/03/2008
  • Issued: 05/29/2012
  • Est. Priority Date: 12/03/2008
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method for operating network management apparatus to detect whether one or more items of preidentified content are present in a network traffic flow being transmitted over an Internet Service Provider (ISP) network, the network traffic flow including data traffic flows potentially carrying the preidentified content intermixed together with data traffic flows carrying other content that is to remain private, all the data in the network data traffic flows being in the form of packets having both a layer with content-free network traffic information and a layer with content information, comprising:

  • providing the network management apparatus with access to the network traffic flow being transmitted over the ISP network;

    providing the network management apparatus with one or more profile identification rules based solely on packet network layer traffic information to identify one or more data traffic flows that correlate with the preidentified content;

    applying the one or more profile identification rules to the network traffic flow as it is being transmitted over the ISP network to select for further analysis those data traffic flows in the network traffic flow that have network layer information that satisfies one or more of the network layer profile identification rules;

    storing in a database apparatus the one or more items of preidentified content whose presence in the network traffic flow being transmitted over the ISP network is to be detected;

    after selecting a data traffic flow satisfying the one or more network layer profile identification rules, further analyzing the selected data traffic flow by comparing the content of the selected data flow with the preidentified content stored in the database apparatus to determine if it matches an item of preidentified content in the database apparatus; and

    if the content of the selected data traffic flow is a match with an item of preidentified content in the database apparatus, taking an action in response,wherein providing the one or more profile identification rules to identify one or more data traffic flows that correlate with the preidentified content comprises adaptively creating the one or more profile identification rules by providing an initial set of network layer profile characteristics, processing data regarding the traffic flows within the ISP network by using the initial set of profile characteristics to determine an initial correlation with preidentified content, and adjusting the set of profile characteristics to improve their correlation with the preidentified content.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×