×

Method and apparatus of network artifact indentification and extraction

  • US 8,625,642 B2
  • Filed: 05/23/2008
  • Issued: 01/07/2014
  • Est. Priority Date: 05/23/2008
  • Status: Active Grant
First Claim
Patent Images

1. A non-transitory machine readable medium, comprising:

  • a packet rearrange module to reorder received network packets based upon sequence numbers;

    a packet analyzer module to separate payload data from header data in the received network packets;

    an identification module to perform a first match of the payload data with an entry from a library of known artifacts;

    a validation module to perform a second match of the payload data based upon a deeper analysis of the payload data with another entry from the library of known artifacts;

    a library formation module to populate a table with characteristics of a packet of the received network packets;

    an extraction module to communicate an extracted artifact to a user, wherein the extracted artifact is a file with aggregated payload data from a presentation module that includes reordered network packets based on sequence numbers of each packet from the packet rearrange module and wherein the file has an associated file type based on marker matches with the library of known artifacts;

    an incomplete management module to identify an incomplete artifact through a comparison of the extracted artifact with a file structure with a known file specification; and

    a visibility module to perform network visibility analyses of the extracted artifact.

View all claims
  • 11 Assignments
Timeline View
Assignment View
    ×
    ×