发明名称 System and method for capturing network data and identifying network events therefrom
摘要 A system (Figure 1) for network (142) security transparently occupies an observation port (104) on the data stream (144), passing the entire range of network information to a dedicated interpreter (108). The interpreter resolves the data stream into individual data packets (110), which are then assembled into reconstructed network sessions (140) according to parameters such as protocol type, source and destination addresses, source and destination ports, sequence numbers and other variables. The different types of sessions may include the traffic of many different types of users, such as e-mail, streaming video, voice-over-Internet and others. The system detects and stores the sessions into a database (122). A parser module (120) may extract only the minimum information needed to reconstruct individual sessions (118). A backend interface permits a systems administrator to interrogate the forensic record of the network for maintenance, security and other purposes. The invention captures and records a comprehensive record of network behavior.
申请公布号 AU6888300(A) 申请公布日期 2000.11.21
申请号 AU20000068883 申请日期 2000.04.27
申请人 NETWORK FORENSICS, INC. 发明人 JOHN D. ABROMAVAGE;MARK LONGWORTH;TODD A. MOORE;SCOTT V. TOTMAN;VINCE ROMANO
分类号 H04L12/26;H04L29/06 主分类号 H04L12/26
代理机构 代理人
主权项
地址