IP Library Granted Patent US 9,054,969
Granted Patent B2
US 9,054,969 · App. 13/731,836 · Granted Jun 9, 2015

System and method for situation-aware IP-based communication interception and intelligence extraction

Inventors: Noam Cohen (Kibbutz Givat Brenner, IL); Yoram Ehrlich (Ramat HaSharon, IL)
Assignee: NICE-SYSTEMS LTD.
H04L43/0876H04L43/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,054,969
App. No.
13/731,836
Granted
Jun 9, 2015
Kind
B2
Abstract

A system and method for monitoring Internet Protocol (IP) data traffic may include receiving IP data generated by a target device interacting on the Internet, determining at least one activity performed by the target device based on the IP data, wherein an activity describes an interaction on the Internet, and aggregating data describing the at least one activity into one or more chunks, each chunk corresponding to a portion of time and at least one activity performed by the targets.

Claims (49)

1. A method for monitoring Internet Protocol (IP) data traffic, comprising:

receiving IP data generated by a target device interacting on the Internet;

extracting, from the received IP data, metadata objects linked to respective content data, wherein each metadata object describes at least one web service accessed by the target device, and wherein the content data linked to the metadata object describes content exchanged between the target device and a server providing the web service;

correlating metadata objects based on similar web service parameters; and

determining at least one activity performed by the target device based on the correlated metadata objects, the activity corresponding to an interaction on the Internet; and

aggregating data describing the at least one activity into one or more chunks, each chunk corresponding to a portion of time and at least one activity performed by the target device.

2. The method of claim 1 , further comprising:

storing the content data into a storage device, wherein each metadata object includes a reference to the location of the respectively linked content data in the database, and wherein data describing the at least one activity includes a reference to the correlated metadata objects.

3. The method of claim 1 , comprising:

displaying a queue of the one or more chunks on a graphical user interface, the one or more chunks including nested chunk objects, wherein each nested chunk object corresponds to a time portion that is part of the time portion corresponding to the one or more chunks.

4. The method of claim 3 , wherein displaying a queue of the one or more chunks comprises:

receiving one or more parameters describing at least one of a time resolution, time frame of activity, category of activity, and visual separation between displayed chunks; and

displaying a queue of the one or more chunks based on the one or more parameters.

5. The method of claim 1 , further comprising categorizing the activity as communication or non-communication, wherein a communication activity describes an interaction between or among users on the Internet and a non-communication activity describes content consumption on the Internet.

6. The method of claim 1 , wherein correlating metadata objects based on similar web service parameters comprises:

assigning one or more identifiers to the metadata objects, the identifiers based on the similar web service parameters, wherein web service parameters include one or more of a web host name, a party involved in the interaction, a time stamp, and an activity type;

comparing the assigned identifiers of the metadata objects; and

correlating metadata objects with similar identifiers.

7. The method of claim 1 , comprising:

generating an alert based on the at least one determined activity.

8. The method of claim 1 , wherein aggregating the data describing the at least one activity into one or more chunks comprises aggregating data describing multiple activities into one or more chunks, wherein each chunk corresponds to a portion of time and a category of activities performed by the target device.

9. A computer system comprising:

a processor; and

a memory to store received IP data, wherein the processor is to:

receive IP data generated by a target device interacting on the Internet;

extract, from the received IP data, metadata objects linked to respective content data, wherein each metadata object describes at least one web service accessed by the target, and wherein the content data linked to the metadata object describes content exchanged between the target device and a server providing the web service or between target devices;

correlate metadata objects based on similar web service parameters;

determine at least one activity performed by the target device based on the correlated metadata objects, the activity corresponding to an interaction on the Internet; and

aggregate data describing the at least one activity into one or more chunks, each chunk corresponding to a portion of time and at least one activity performed by the target device.

10. The computer system of claim 9 , wherein the processor is to aggregate data describing multiple activities into one or more chunks, wherein each chunk corresponds to a portion of time and a category of activities performed by the target device.

11. The computer system of claim 9 wherein the processor is to:

receive one or more parameters describing at least one of a time resolution, time frame of activity, category of activity, and visual separation between displayed chunks; and

display a queue of the one or more chunks based on the one or more parameters.

12. The computer system of claim 9 , wherein the processor is to correlate metadata objects based on similar web service parameters by:

assigning one or more identifiers to the metadata objects, the identifiers based on the similar web service parameters, wherein web service parameters include one or more of a web host name, a party involved in the interaction, a time stamp, an activity type, and a file related to the interaction;

comparing the assigned identifiers between the metadata objects; and

correlating metadata objects with similar identifiers.

13. The computer system of claim 10 ,

wherein the memory is to store data describing multiple activities into a database; and

wherein the processor is to retrieve data describing the activities from the database upon aggregating the data describing the at least one activity into one or more chunks.

14. The computer system of claim 9 , wherein the aggregating the data into one or more chunks comprises aggregating data describing multiple activities into one or more chunks, wherein each chunk corresponds to a portion of time and a category of activities performed by the target device.

15. A method comprising:

receiving IP data traffic generated by a target device interacting on the Internet;

extracting, from the received IP data traffic, metadata objects linked to respective content data, wherein each metadata object includes web application parameters describing at least one web service accessed by the target device, and wherein the content data linked to the metadata object describes content exchanged between the target device and a server providing the web service or between target devices;

categorizing the IP data from the IP data traffic according to the web application parameters, wherein the categories describe an interaction on the Internet; and

assigning the IP data to different groups based on the categorization and based on the time the traffic was transmitted.

16. The method of claim 15 wherein each group corresponds to a period of time.

17. The method of claim 15 , comprising displaying the groups in a graph according to a web application parameter category and a time frame.

18. The method of claim 15 , wherein categorizing the IP data is according to web hosts, web services, and recipients of the IP data traffic.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2015
From: NICE SYSTEMS LTD.
To: CYBERBIT LTD.
Reel/Frame 036284/0725 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2013
From: COHEN, NOAM; EHRLICH, YORAM
To: NICE-SYSTEMS LTD.
Reel/Frame 030648/0025 →
Continuity (2)
Provisional Application 61660109 · Jun 15, 2012
Related Publication 20130336137A1 · Dec 19, 2013