发明名称 Method and apparatus for data capture and analysis system
摘要 Content leaving a local network can be captured and indexed so that queries can be performed on the captured data. In one embodiment, the present invention comprises an apparatus that connects to a network. In one embodiment, this apparatus includes a network interface module to connect the apparatus to a network, a packet capture module to intercept packets being transmitted on the network, an object assembly module to reconstruct objects being transmitted on the network from the intercepted packets, an object classification module to determine the content in the reconstructed objects, and an object store module to store the objects. This apparatus can also have a user interface to enable a user to search objects stored in the object store module.
申请公布号 US8762386(B2) 申请公布日期 2014.06.24
申请号 US201113168739 申请日期 2011.06.24
申请人 McAfee, Inc. 发明人 de la Iglesia Erik;Lowe Rick;Ahuja Ratinder Paul Singh;Deninger William;King Samuel;Khasgiwala Ashish;Massaro Donald J.
分类号 G06F17/30 主分类号 G06F17/30
代理机构 Patent Capital Group 代理人 Patent Capital Group
主权项 1. A method, comprising: receiving a flow of packets in a network; applying a filter to the flow in order to identify a protocol for the flow; extracting a plurality of objects associated with flow; determining a content type for each of the objects based on a signature identified within the objects; and providing a user interface to enable a user to use a query to search for stored objects, wherein the query includes search criteria used to identify certain objects that match the search criteria, wherein a particular search is scheduled for a recurring time interval and includes a particular search query with selected terms, and wherein certain results of the particular search trigger an e-mail message to be sent to an administrator.
地址 Santa Clara CA US