IP Library Granted Patent US 8,762,386
Granted Patent B2
US 8,762,386 · App. 13/168,739 · Granted Jun 24, 2014

Method and apparatus for data capture and analysis system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,762,386
App. No.
13/168,739
Granted
Jun 24, 2014
Kind
B2
Abstract

Content leaving a local network can be captured and indexed so that queries can be performed on the captured data. In one embodiment, the present invention comprises an apparatus that connects to a network. In one embodiment, this apparatus includes a network interface module to connect the apparatus to a network, a packet capture module to intercept packets being transmitted on the network, an object assembly module to reconstruct objects being transmitted on the network from the intercepted packets, an object classification module to determine the content in the reconstructed objects, and an object store module to store the objects. This apparatus can also have a user interface to enable a user to search objects stored in the object store module.

Claims (70)

1. A method, comprising:

receiving a flow of packets in a network;

applying a filter to the flow in order to identify a protocol for the flow;

extracting a plurality of objects associated with flow;

determining a content type for each of the objects based on a signature identified within the objects; and

providing a user interface to enable a user to use a query to search for stored objects, wherein the query includes search criteria used to identify certain objects that match the search criteria, wherein a particular search is scheduled for a recurring time interval and includes a particular search query with selected terms, and wherein certain results of the particular search trigger an e-mail message to be sent to an administrator.

2. The method of claim 1 , wherein the determining includes identifying malicious content based on a file extension associated with the flow.

3. The method of claim 1 , further comprising:

determining whether the object is to be stored or discarded based on a plurality of capture rules.

4. The method of claim 3 , further comprising:

providing the user interface for authoring the capture rules that designate which objects is to be stored or discarded.

5. The method of claim 1 , further comprising:

storing at least some of the objects in a content store, which is indexed by a tag database in which each record has an associated tag that indexes a corresponding object.

6. The method of claim 1 , further comprising:

receiving a search query for particular content associated with the flow.

7. The method of claim 1 , further comprising:

providing at least some of the objects in response to the search query.

8. The method of claim 1 , further comprising:

providing at least some of the packets to an object assembly module, which is configured to reconstruct an element originally sought for propagation in the network.

9. The method of claim 1 , wherein the packets are reassembled into unique flows based on a source Internet Protocol (IP) address and a destination IP address.

10. The method of claim 1 , wherein the packets form an e-mail.

11. The method of claim 1 , wherein the packets form a document.

12. The method of claim 1 , wherein a network interface receives the flow of packets.

13. The method of claim 12 , wherein the network interface comprises a plurality of network interface cards (NICs).

14. The method of claim 12 , wherein the network interface comprises a plurality of Ethernet cards.

15. Logic encoded in one or more non-transitory media that includes code for execution and when executed by a processor operable to perform operations comprising:

receiving a flow of packets in a network;

applying a filter to the flow in order to identify a protocol for the flow;

extracting a plurality of objects associated with flow;

determining a content type for each of the objects based on a signature identified within the objects; and

providing a user interface to enable a user to use a query to search for stored objects, wherein the query includes search criteria used to identify certain objects that match the search criteria, wherein a particular search is scheduled for a recurring time interval and includes a particular search query with selected terms, and wherein certain results of the particular search trigger an e-mail message to be sent to an administrator.

16. The logic of claim 15 , wherein the determining includes identifying malicious content based on a file extension associated with the flow, and wherein a determination is made as to whether the object is to be stored or discarded based on a plurality of capture rules, and wherein the user interface is provided for authoring the capture rules that designate which objects is to be stored or discarded.

17. The media of claim 15 , wherein the determining includes identifying malicious content based on a file extension associated with the flow.

18. The media of claim 15 , the operations further comprising:

determining whether the object is to be stored or discarded based on a plurality of capture rules.

19. The media of claim 18 , the operations further comprising:

providing the user interface for authoring the capture rules that designate which objects is to be stored or discarded.

20. The media of claim 15 , the operations further comprising:

storing at least some of the objects in a content store, which is indexed by a tag database in which each record has an associated tag that indexes a corresponding object.

21. The media of claim 15 , the operations further comprising:

receiving a search query for particular content associated with the flow.

22. The media of claim 15 , the operations further comprising:

providing at least some of the objects in response to the search query.

23. The media of claim 15 , the operations further comprising:

providing at least some of the packets to an object assembly module, which is configured to reconstruct an element originally sought for propagation in the network.

24. The media of claim 15 , wherein the packets are reassembled into unique flows based on a source Internet Protocol (IP) address and a destination IP address.

25. The media of claim 15 , wherein a network interface receives the flow of packets, and wherein the network interface comprises a plurality of network interface cards (NICs) or a plurality of Ethernet cards.

26. An apparatus, comprising:

a memory element; and

a processor coupled to the memory element, wherein the apparatus is configured for:

receiving a flow of packets in a network;

applying a filter to the flow in order to identify a protocol for the flow;

extracting a plurality of objects associated with flow;

determining a content type for each of the objects based on a signature identified within the objects; and

providing a user interface to enable a user to use a query to search for stored objects, wherein the query includes search criteria used to identify certain objects that match the search criteria, wherein a particular search is scheduled for a recurring time interval and includes a particular search query with selected terms, and wherein certain results of the particular search trigger an e-mail message to be sent to an administrator.

27. The apparatus of claim 26 , wherein the determining includes identifying malicious content based on a file extension associated with the flow.

28. The apparatus of claim 26 , wherein the apparatus is further configured for:

determining whether the object is to be stored or discarded based on a plurality of capture rules.

29. The apparatus of claim 28 , wherein the apparatus is further configured for:

providing the user interface for authoring the capture rules that designate which objects is to be stored or discarded.

30. The apparatus of claim 26 , wherein the apparatus is further configured for:

storing at least some of the objects in a content store, which is indexed by a tag database in which each record has an associated tag that indexes a corresponding object.

31. The apparatus of claim 26 , wherein the apparatus is further configured for:

receiving a search query for particular content associated with the flow.

32. The apparatus of claim 26 , wherein the apparatus is further configured for:

providing at least some of the objects in response to the search query.

33. The apparatus of claim 26 , wherein the apparatus is further configured for:

providing at least some of the packets to an object assembly module, which is configured to reconstruct an element originally sought for propagation in the network.

34. The apparatus of claim 26 , wherein the packets are reassembled into unique flows based on a source Internet Protocol (IP) address and a destination IP address.

35. The apparatus of claim 26 , wherein a network interface receives the flow of packets, and wherein the network interface comprises a plurality of network interface cards (NICs) or a plurality of Ethernet cards.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →