IP Library Granted Patent US 8,625,642
Granted Patent B2
US 8,625,642 · App. 12/126,551 · Granted Jan 7, 2014

Method and apparatus of network artifact indentification and extraction

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,625,642
App. No.
12/126,551
Granted
Jan 7, 2014
Kind
B2
Abstract

A method, system, and apparatus of network artifact identification and extraction are disclosed. In one embodiment, a method includes aggregating a payload data (e.g., may be a component of the extracted artifact) from different network packets to form an aggregated payload data, matching the payload data with an entry of a library of known artifacts, determining a type of the payload data based on a match with the entry of the library of known artifacts, separating the payload data from a header data in a network packet, and communicating the aggregated payload data as an extracted artifact to a user. The method may include using the extracted artifact to perform network visibility analysis of users on packets flowing across the network. The method may validate that the entry is accurate by performing a deeper analysis of the payload data with the entry of the library of known artifacts.

Claims (19)

1. A non-transitory machine readable medium, comprising:

a packet rearrange module to reorder received network packets based upon sequence numbers;

a packet analyzer module to separate payload data from header data in the received network packets;

an identification module to perform a first match of the payload data with an entry from a library of known artifacts;

a validation module to perform a second match of the payload data based upon a deeper analysis of the payload data with another entry from the library of known artifacts;

a library formation module to populate a table with characteristics of a packet of the received network packets;

an extraction module to communicate an extracted artifact to a user, wherein the extracted artifact is a file with aggregated payload data from a presentation module that includes reordered network packets based on sequence numbers of each packet from the packet rearrange module and wherein the file has an associated file type based on marker matches with the library of known artifacts;

an incomplete management module to identify an incomplete artifact through a comparison of the extracted artifact with a file structure with a known file specification; and

a visibility module to perform network visibility analyses of the extracted artifact.

2. The non-transitory machine readable medium of claim 1 wherein each row of the table includes characteristics of a single network packet.

3. The non-transitory machine readable medium of claim 2 wherein the characteristics specify packet start bits.

4. The non-transitory machine readable medium of claim 2 wherein the characteristics specify packet length.

5. The non-transitory machine readable medium of claim 2 wherein the characteristics specify packet end bits.

6. The non-transitory machine readable medium of claim 2 wherein the characteristics specify an artifact type selected from a word processing document, a spreadsheet document, a database, an image, a video, a multimedia file, an email, an instant message communication, an audio file, a compressed file, an executable file, and a web page.

7. The non-transitory machine readable medium of claim 2 wherein the characteristics specify an encryption indicator.

8. The non-transitory machine readable medium of claim 1 further comprising:

a determination module to determine that the payload data is encrypted;

encrypted data processing module to generate a request for the encrypted data from a source and to receive a decryption key from the source;

a decryption module to apply the decryption key to decrypt the encrypted data.

Assignments (11)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30747/0452 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC., AS SUCCESSOR BY MERGER TO SOLERA NETWORKS, INC.
Reel/Frame 035797/0332 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30521/0379 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC., AS SUCCESSOR BY MERGER TO SOLERA NETWORKS, INC.
Reel/Frame 035797/0899 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
MERGER Recorded Feb 10, 2014
From: SOLERA NETWORKS, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 032188/0063 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED ON REEL 020997 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CORRECTION BY DECLARATION TO REVISE THE NAME OF THE ASSIGNEE. Recorded Nov 22, 2013
From: WOOD, MATTHEW SCOTT; TVEIT, PAAL; EDGINTON, BRIAN; SHILLINGFORD, STEVE; BROWN, JAMES
To: SOLERA NETWORKS, INC.
Reel/Frame 031713/0133 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: SOLERA NETWORKS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030747/0452 →
PATENT SECURITY AGREEMENT Recorded May 31, 2013
From: SOLERA NETWORKS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030521/0379 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2008
From: WOOD, MATTHEW S.; TVEIT, PAAL; EDGINTON, BRIAN; SHILLINGFORD, STEVE; BROWN, JAMES
To: SOLERA NETWORKS
Reel/Frame 020997/0646 →