IP Library › Granted Patent US 11,102,132
Granted Patent B2
US 11,102,132 · App. 15/782,607 · Granted Aug 24, 2021

Extracting data from network communications

Inventors: Leslie Zsohar (Austin, TX); Wei Lu (Austin, TX); Craig Botkin (Austin, TX); Randal Mullin (Austin, TX); Edward A. Wartha (Austin, TX)
Assignee: Trend Micro Incorporated
H04L47/2441H04L43/026H04L43/028H04L43/04H04L47/2483H04L69/22H04L43/06H04L69/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,102,132
App. No.
15/782,607
Granted
Aug 24, 2021
Kind
B2
Abstract

Examples relate to extracting data from network communications. In one example, a programmable hardware processor may: receive a first set of network packets; store each network packet included in the first set in a first storage device; identify, from each network packet included in a subset of the first set of network packets, data included in the network packet, the data meeting at least one condition defined by first programmable logic of the programmable hardware processor; and for each network packet included in the subset: extract, from the network packet, data of interest; and store, in a second storage device, i) the extracted data of interest, and ii) an identifier associated with the network packet.

Claims (64)

1. A computing device for extracting data from network communications, the computing device comprising a programmable hardware processor configured to:

receive a first set of network packets;

store each network packet included in the first set in a first storage device;

identify, from each network packet included in a subset of the first set of network packets, data included in the network packet, the data meeting at least one condition defined by first programmable logic of the programmable hardware processor; and

for each network packet included in the subset:

extract, from the network packet, data of interest; and

store, in a second storage device, i) the extracted data of interest, and ii) an identifier associated with the network packet.

2. The computing device of claim 1 , wherein the programmable hardware processor is further configured to:

identify, for each network packet included in the first set, a network flow, each network flow including at least one of the network packets included in the first set; and

for each network packet included in the subset, organize the network packet according to the network flow identified for the network packet.

3. The computing device of claim 2 , wherein the programmable hardware processor is further configured to:

determine that particular data of interest identified in a particular network packet is partial data;

identify a particular network flow that includes the particular network packet; and

identify other network packets included in the particular network flow, the other network packets including other partial data that, when combined with the partial data of the particular network packet, comprise the particular data of interest.

4. The computing device of claim 3 , wherein the programmable hardware processor is further configured to:

combine the extracted data of interest from the particular network packet and each other network packet included in the particular network flow, and wherein storing the extracted data of interest comprises storing the combined extracted data of interest.

5. The computing device of claim 1 , wherein the data of interest comprises at least one of:

network packet header data;

network packet payload data;

network packet footer data; or

network packet metadata.

6. The computing device of claim 1 , wherein the data meeting the at least one condition defined by first programmable logic is included in at least one of:

network packet header data;

network packet payload data;

network packet footer data; or

network packet metadata.

7. The computing device of claim 2 , wherein, for each network packet included in the subset, the identifier associated with the network packet is based on the network flow in which the network packet is included.

8. The computing device of claim 1 , wherein the programmable hardware processor is further configured to:

obtain second programmable logic for the programmable hardware processor, the second programmable logic defining a condition that is different from the at least one condition defined by the first programmable logic;

receive, subsequent to receiving the first set of network packets, a second set of network packets;

store each network packet included in the second set in the first storage device;

identify, from each network packet included in a second subset of the second set of network packets, second data included in the network packet, the second data meeting at least one condition defined by the second programmable logic of the programmable hardware processor; and

for each network packet included in the second subset:

extract, from the network packet, second data of interest; and

store, in the second storage device, i) the extracted second data of interest, and ii) a second identifier associated with the network packet.

9. A method for extracting data from network communications, implemented by a programmable hardware processor, the method comprising:

obtaining at least one network packet from a first storage device, each of the at least one network packet being included in a network flow;

determining that a particular network packet included in the network flow includes data meeting at least one condition defined by first programmable logic of the programmable hardware processor;

in response to determining that the particular network packet includes data meeting the at least one condition:

extracting, from the particular network packet, data of interest; and

storing, in a second storage device, i) the extracted data of interest, and ii) an identifier associated with the particular network packet.

10. The method of claim 9 , further comprising:

determining that the data of interest is a portion of whole data;

extracting each portion of the whole data from each network packet that i) includes a portion of the whole data, and ii) is included in the network flow; and

storing, in the second storage device, each extracted portion of the whole data.

11. The method of claim 10 , further comprising:

generating whole data of interest by combining each extracted portion of the whole data, and wherein storing each extracted portion of the whole data comprises storing the whole data of interest.

12. The method of claim 9 , wherein the extracted data of interest:

is defined by the first programmable logic; and

includes data that is different from the data meeting the at least one condition.

13. The method of claim 9 , further comprising:

obtaining second programmable logic for the programmable hardware processor, the second programmable logic defining a condition that is different from the at least one condition defined by the first programmable logic;

receiving, subsequent to the obtaining the at least one network packet, at least one second network packet from the first storage device, the at least one second network packet being included in a second network flow;

determining that a particular second network packet included in the second network flow includes second data meeting at least one condition defined by the second programmable logic;

in response to determining that the particular second network packet includes second data meeting the at least one condition:

extracting, from the particular second network packet, second data of interest; and

storing, in the second storage device, i) the extracted second data of interest, and ii) an identifier associated with the particular second network packet.

14. The method of claim 9 , further comprising:

receiving a plurality of network packets;

identifying, for each of the plurality of network packets, a network flow, each network flow including at least one of the plurality of network packets; and

storing each of the plurality of network packets in the first storage device.

15. The method of claim 14 , further comprising:

organizing each of the plurality of network packets stored in the first storage device according to the network flow identified for the network packet;

organizing the extracted data of interest stored in the second storage device according to the identifier associated with the particular network packet.

Continuity (2)
Continuation PCTUS2015028596 · Apr 30, 2015
Related Publication 20180034738A1 · Feb 1, 2018
Cited By (1)
US 12,519,741