Systems and methods for extracting media from network traffic having unknown protocols
First Claim
Patent Images
1. A method, comprising:
- receiving in a computerized analysis system network traffic, which complies with a protocol, wherein the protocol is not decodable by the analysis system, and which carries a data item of a respective media type;
automatically identifying the media type by processing the network traffic without decoding the protocol; and
extracting at least part of the data item responsively to the identified media type.
3 Assignments
0 Petitions
Accused Products
Abstract
Methods and systems for analyzing network traffic. An analysis system receives network traffic, which complies with a certain protocol. The received network traffic carries a data item, which may be of value to an analyst. In order to access the data item in question, the analysis system automatically identifies the media type of the data item, by processing the network traffic irrespective of the protocol. The analysis system identifies the media type irrespective of the protocol in order to avoid the computational complexity involved in decoding the protocol.
18 Citations
19 Claims
-
1. A method, comprising:
-
receiving in a computerized analysis system network traffic, which complies with a protocol, wherein the protocol is not decodable by the analysis system, and which carries a data item of a respective media type; automatically identifying the media type by processing the network traffic without decoding the protocol; and extracting at least part of the data item responsively to the identified media type. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. An apparatus, comprising:
-
an interface configured to receive network traffic, which complies with a protocol, wherein the protocol is not decodable by the analysis system, and which carries a data item of a respective media type; and a processor, which is configured to automatically identify the media type by processing the network traffic without decoding the protocol, and to extract at least part of the data item responsively to the identified media type. - View Dependent Claims (13, 14, 15)
-
-
16. A non-transitory computer-readable medium having stored thereon instructions that, when executed by a computerized analysis system, direct the analysis system to execute the process comprising the steps of:
-
receiving in the computerized analysis system network traffic, which complies with a protocol, wherein the protocol is not decodable by the analysis system, and which carries a data item of a respective media type; automatically identifying the media type by processing the network traffic without decoding the protocol; and extracting at least part of the data item responsively to the identified media type. - View Dependent Claims (17, 18, 19)
-
Specification