IP Library Granted Patent US 8,301,635
Granted Patent B2
US 8,301,635 · App. 12/967,013 · Granted Oct 30, 2012

Tag data structure for maintaining relational data over captured objects

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,301,635
App. No.
12/967,013
Granted
Oct 30, 2012
Kind
B2
Abstract

Objects captured over a network by a capture system can be indexed to provide enhanced search and content analysis capabilities. In one embodiment the objects can be indexed using a data structure having a source address field to indicate an origination address of the object, a destination address field to indicate a destination address of the object, a source port field to indicate an origination port of the object, a destination port field to indicate a destination port of the object, a content field to indicate a content type from a plurality of content types identifying a type of content contained in the object, and a time field to indicate when the object was captured. The data structure may also store a cryptographic signature of the object to ensure the object is not altered after capture.

Claims (56)

1. Software encoded in one or more non-transitory media that includes code for execution and when executed by a processor is operable to perform operations comprising:

receiving a data stream that includes a plurality of packets;

generating a tag for an object represented by the packets, wherein the tag includes:

a source address field indicative of an origination address associated with the object,

a destination address field indicative of a destination address associated with the object,

a source port field indicative of an origination port associated with the object,

a destination port field indicative of a destination port associated with the object,

a content field indicative of a content type associated with the object, and

a time field indicative of when the object was captured;

generating a cryptographic tag signature over at least a portion of the tag;

generating an object signature over at least a portion of the object, wherein at least one of the object signature and the tag signature is generated using a first key; and

storing a tag record in a database in which the tag record indexes the object in a content store and contains information about the object, the tag record including a pointer associated with a storage location where the object is stored,

wherein the object is verified by using the tag signature and the object signature before the object is presented, and wherein at least one key pair is used in a verification operation, the at least one key pair including the first key and a second key.

2. The software of claim 1 , wherein the packets are grouped into individual flows based on Internet Protocol (IP) address information.

3. The software of claim 1 , wherein the flows are sorted using port data.

4. The software of claim 1 , wherein signature filters are applied to the flows in order to identify a protocol based on the packets.

5. The software of claim 1 , wherein objects within the data stream are used in order to identify a content type associated with documents being transmitted in the data stream.

6. The software of claim 1 , wherein capture rules are configured in order to determine whether certain types of data streams are to be discarded or stored.

7. The software of claim 1 , wherein the first key of the key pair is a private key of the capture system, and wherein the second key of the key pair is a public key.

8. The software of claim 1 , wherein both the object signature and the tag signature are generated using the first key.

9. A method, comprising:

receiving a data stream that includes a plurality of packets;

generating a tag for an object represented by the packets, wherein the tag includes:

a source address field indicative of an origination address associated with the object,

a destination address field indicative of a destination address associated with the object,

a source port field indicative of an origination port associated with the object,

a destination port field indicative of a destination port associated with the object,

a content field indicative of a content type associated with the object, and

a time field indicative of when the object was captured;

generating a cryptographic tag signature over at least a portion of the tag;

generating an object signature over at least a portion of the object, wherein at least one of the object signature and the tag signature is generated using a first key; and

storing a tag record in a database in which the tag record indexes the object in a content store and contains information about the object, the tag record including a pointer associated with a storage location where the object is stored,

wherein the object is verified by using the tag signature and the object signature before the object is presented, and wherein at least one key pair is used in a verification operation, the at least one key pair including the first key and a second key.

10. The method of claim 9 , wherein the flows are sorted using port data, and wherein signature filters are applied to the flows in order to identify a protocol based on the packets.

11. The method of claim 9 , wherein objects within the data stream are used in order to identify a content type associated with documents being transmitted in the data stream, and wherein capture rules are configured in order to determine whether certain types of data streams are to be discarded or stored.

12. The method of claim 9 , wherein the first key of the key pair is a private key of the capture system, and wherein the second key of the key pair is a public key.

13. The method of claim 9 , wherein both the object signature and the tag signature are generated using the first key.

14. An apparatus, comprising:

a processor; and

a memory, wherein the processor and the memory cooperate such that the apparatus is configured for:

receiving a data stream that includes a plurality of packets;

generating a tag for an object represented by the packets, wherein the tag includes:

a source address field indicative of an origination address associated with the object,

a destination address field indicative of a destination address associated with the object,

a source port field indicative of an origination port associated with the object,

a destination port field indicative of a destination port associated with the object,

a content field indicative of a content type associated with the object, and

a time field indicative of when the object was captured;

generating a cryptographic tag signature over at least a portion of the tag;

generating an object signature over at least a portion of the object, wherein at least one of the object signature and the tag signature is generated using a first key; and

storing a tag record in a database in which the tag record indexes the object in a content store and contains information about the object, the tag record including a pointer associated with a storage location where the object is stored,

wherein the object is verified by using the tag signature and the object signature before the object is presented, and wherein at least one key pair is used in a verification operation, the at least one key pair including the first key and a second key.

15. The apparatus of claim 14 , further comprising:

a user interface configured for searching for the object based on the tag.

16. The apparatus of claim 14 , wherein the first key of the key pair is a private key of the capture system, and wherein the second key of the key pair is a public key.

17. The apparatus of claim 14 , wherein both the object signature and the tag signature are generated using the first key.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →