IP Library Granted Patent US 8,140,665
Granted Patent B2
US 8,140,665 · App. 11/507,114 · Granted Mar 20, 2012

Managing captured network traffic data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,140,665
App. No.
11/507,114
Granted
Mar 20, 2012
Kind
B2
Abstract

A system and method for managing captured network traffic data is provided. The invention comprises a plurality of capture agents, each being configured to capture the network traffic associated with one or more applications. Each application is associated with one or more capture agents according to an application profile that is stored and maintained in a capture server. When analysis of an application's network traffic is required, the capture server contacts the corresponding capture agents according to the application profile. The capture server then effects the identification and archiving of the network traffic that corresponds to a user-defined capture condition. A database at the capture server maintains a record that associates the corresponding network traffic with the user-defined capture condition such that the corresponding network traffic can later be retrieved and analyzed using an analysis engine.

Claims (68)

1. A system comprising:

a plurality of capture components that are each configured to continuously record network traffic, wherein new network traffic overwrites old network traffic after a threshold is reached,

a database that includes a plurality of profiles, each profile including a set of capture components of the plurality of capture components associated with a particular capture condition, and

a management component that is configured to:

receive information from which a capture condition can be identified,

retrieve, from the database, the set of capture components associated with the profile corresponding to the identified capture condition, and

effect an archiving of at least a portion of the network traffic that has already been recorded by the set of capture components before the capture condition was identified.

2. The system of claim 1 , wherein the management component is further configured to maintain an association of the archived portion of the recorded network traffic and the received information.

3. The system of claim 1 , wherein the identified capture condition is an association with an application.

4. The system of claim 1 , wherein the identified capture condition is an association with a user.

5. The system of claim 1 , wherein at least one capture component of the set of capture components is further configured to store the archived portion of the network traffic in an archive file separate from the recorded network traffic.

6. The system of claim 5 , wherein the at least one capture component is further configured to store the archive file at the same location as the recorded network traffic.

7. The system of claim 5 , including a repository, wherein the at least one capture component is further configured to transmit the archive file to the repository.

8. The system of claim 1 , wherein at least one capture component of the set of traffic components is further configured to lock the archived portion of the recorded network traffic to prevent an overwriting or deletion of the archived portion.

9. The system of claim 1 , wherein the management component is further configured to effect a filtering of the network traffic recorded in the archived portion of the recorded network traffic of at least one capture component of the set of capture components.

10. The system of claim 1 , including an analytical component that is configured to execute an analysis of the network traffic recorded in the archived portion of the recorded network traffic of at least one capture component of the set of capture components.

11. The system of claim 10 , wherein the analysis includes a simulation.

12. The system of claim 1 , wherein the received information includes a problem description.

13. The system of claim 12 , wherein the problem description includes a problem time.

14. The system of claim 1 , wherein the management component includes a user interface component that is configured to receive the information.

15. The system of claim 14 , wherein the received information includes a sequence of start and stop commands.

16. The system of claim 1 , including a trouble ticketing component that is configured to manage a plurality of trouble tickets corresponding to a plurality of problems.

17. The system of claim 16 , wherein the management component includes a notification component that is configured to transmit a notification message to the trouble ticketing component.

18. A method comprising:

configuring a plurality of capture components, such that each capture component is configured to continuously record network traffic, wherein new network traffic overwrites old network traffic after a threshold is reached,

configuring a database to include a plurality of profiles, each profile including a set of capture components of the plurality of capture components associated with a particular capture condition,

receiving information,

identifying a capture condition based on the received information,

retrieving the set of capture components associated with the profile corresponding to the identified capture condition, and

archiving at least a portion of the network traffic that has already been recorded by the set of capture components before the capture condition was identified.

19. The method of claim 18 , including maintaining an association of the archived portion of the recorded network traffic with the received information.

20. The method of claim 18 , wherein the identified capture condition is an association with an application.

21. The method of claim 18 , wherein the identified capture condition is an association with a user.

22. The method of claim 18 , including storing the archived portion of the recorded network traffic in an archive file separate from the recorded network traffic.

23. The method of claim 22 , including storing the archive file at the same location as the recorded network traffic.

24. The method of claim 22 , including transmitting the archive file to a repository.

25. The method of claim 18 , including locking the archived portion of the recorded network traffic to prevent an overwriting or deletion of the archived portion.

26. The method of claim 18 , including filtering the network traffic recorded in the archived portion of the recorded network traffic.

27. The method of claim 18 , including executing an analysis of the network traffic recorded in the archived portion of the recorded network traffic.

28. The method of claim 27 , wherein the analysis includes a simulation.

29. The method of claim 18 , wherein the received information includes a problem description.

30. The method of claim 29 , wherein the problem description includes a problem time.

31. The method of claim 18 , including providing a user interface that is configured to receive the information.

32. The method of claim 31 , wherein the received information includes a sequence of start and stop commands.

33. The method of claim 18 , including configuring a trouble ticking component to manage a plurality of trouble tickets corresponding to a plurality of problems.

34. The method of claim 33 , including transmitting a notification message to the trouble ticketing component.

35. A computer program product stored on a non-transient computer readable medium, which, when executed by a processor, causes the processor to:

instruct each of a plurality of capture components to continuously record network traffic, wherein new network traffic overwrites old network traffic after a threshold is reached,

receive information,

identify a capture condition based on the received information,

retrieve, based on the identified capture condition, a set of capture components from a database that includes a plurality of sets of capture components, each set of capture components being associated with a particular capture condition, and

archive at least a portion of the network traffic that has already been recorded by the set of capture components before the capture condition was identified.

36. The computer program product of claim 35 , which causes the processor to maintain an association of the archived portion of the recorded network traffic with the received information.

37. The computer program product of claim 35 , wherein the identified capture condition is an association with an application.

38. The computer program product of claim 35 , wherein the identified capture condition is an association with a user.

39. The computer program product of claim 35 , which causes the processor to store the archived portion of the recorded network traffic in an archive file separate from the recorded network traffic.

40. The computer program product of claim 39 , which causes the processor to store the archive file at the same location as the recorded network traffic.

41. The computer program product of claim 39 , which causes the processor to transmit the archive file to a repository.

42. The computer program product of claim 35 , which causes the processor to lock the archived portion of the recorded network traffic to prevent an overwriting or deletion of the archived portion.

43. The computer program product of claim 35 , which causes the processor to filter the network traffic in the archived portion of the recorded network traffic.

44. The computer program product of claim 35 , which causes the processor to execute an analysis of the network traffic recorded in the archived portion of the recorded network traffic.

45. The computer program product of claim 44 , wherein the analysis includes a simulation.

46. The computer program product of claim 35 , wherein the received information includes a problem description.

47. The computer program product of claim 46 , wherein the problem description includes a problem time.

48. The computer program product of claim 35 , which causes the processor to provide a user interface that is configured to receive the information.

49. The computer program product of claim 48 , wherein the received information includes a sequence of start and stop commands.

50. The computer program product of claim 35 , which causes the processor to instruct a trouble ticking component to manage a plurality of trouble tickets corresponding to a plurality of problems.

51. The computer program product of claim 50 , which causes the processor to transmit a notification message to the trouble ticketing component.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2013
From: OPNET TECHNOLOGIES LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 030459/0372 →
CHANGE OF NAME Recorded May 14, 2013
From: OPNET TECHNOLOGIES, INC.
To: OPNET TECHNOLOGIES LLC
Reel/Frame 030411/0310 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2006
From: MALLOY, PATRICK J.; GEHL, RYAN; NUDELMAN, ERIC S.; SCHNEIDER, MARC I.; CANNEY, MICHAEL; COHEN, MARC A.; ELSNER, RUSSELL MARK
To: OPNET TECHNOLOGIES, INC.
Reel/Frame 018548/0808 →