IP Library Granted Patent US 7,561,569
Granted Patent B2
US 7,561,569 · App. 11/179,230 · Granted Jul 14, 2009

Packet flow monitoring tool and method

Assignee: Battelle Memorial Institute
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,561,569
App. No.
11/179,230
Granted
Jul 14, 2009
Kind
B2
Abstract

A system and method for converting packet streams into session summaries. Session summaries are a group of packets each having a common source and destination internet protocol (IP) address, and, if present in the packets, common ports. The system first captures packets from a transport layer of a network of computer systems, then decodes the packets captured to determine the destination IP address and the source IP address. The system then identifies packets having common destination IP addresses and source IP addresses, then writes the decoded packets to an allocated memory structure as session summaries in a queue.

Claims (50)

1. A method for converting packet streams into session summaries comprising the steps of:

a. capturing packets from a transport layer,

b. decoding the packets to determine the destination IP address and the source IP address,

c. identifying packets having common destination IP addresses and source IP addresses,

d. writing the decoded packets to an allocated memory structure as session summaries in a queue wherein said session summaries contain only packets having common destination and source IP addresses,

e. creating a series of time buckets, each of the time buckets having a predefined beginning time and a predefined end time, wherein the time buckets are sequential in time,

f. associating new session summaries with the time bucket covering the time period corresponding to the time the packet was captured from the transport layer, and

g. moving a session summary to the time bucket at the front of the queue in response to an incoming packet having a destination IP addresses and source IP addresses matching the session summary.

2. The method of claim 1 wherein the step of decoding the packets further comprises determining TCP port source and destination numbers, flag fields, option fields, sequence number, length parameter, and combinations thereof.

3. The method of claim 1 wherein the step of decoding the packets further comprises determining UDP port source and destination numbers and the length parameter.

4. The method of claim 1 , further comprising the step of defining a time out value and deleting session summaries associated with time buckets older than the time out value.

5. The method of claim 1 wherein one or more of the steps of

a. capturing packets from a transport layer,

b. decoding the packets to determine the destination IP address and the source IP address,

c. identifying packets having common destination IP addresses and source IP addresses, and

d. writing the decoded packets to an allocated memory structure as session summaries in a queue wherein said session summaries contain only packets having common destination and source IP addresses, are performed on separate threads.

6. A system for converting packet streams into session summaries comprising:

a. An input device configured to capture packets from a transport layer, and

b. a processor configured to:

i. decode the packets to determine the destination IP address and the source IP address,

ii. identify packets having common destination IP addresses and source IP addresses,

iii. write the decoded packets to an allocated memory structure as session summaries in a queue wherein said session summaries contain only packets having common destination and source IP addresses,

iv. wherein the processor is further configured to decode the packets to:

a. create a series of time buckets, each of the time buckets having a predefined beginning time and a predefined end time, wherein the time buckets are sequential in time, and

b. associate new session summaries with the time bucket covering the time period corresponding to the time the packet was captured from the transport layer, and

v. wherein the processor is further configured to move a session summary to the time bucket at the front of the Queue in response to an incoming packet having a destination IP address and source IP address matching the session summary.

7. The system of claim 6 further comprising decoding the packets to determine at least one of the TCP port source and destination numbers, flag fields, option fields, sequence number, length parameter, and combinations thereof.

8. The system of claim 6 further comprising decoding the packets to determine at least one of the UDP port source and destination numbers and the length parameter.

9. The system of claim 6 , wherein the processor is further configured to define a time out value and delete session summaries associated with time buckets older than the time out value from the allocated memory structure.

10. The system of claim 6 wherein the processor is configured to:

i. decode the packets to determine the destination IP address and the source IP address,

ii. identify packets having common destination IP addresses and source IP addresses, and

iii. write the decoded packets to an allocated memory structure as session summaries in a queue wherein said session summaries contain only packets having common destination and source IP addresses,

on at least two separate threads.

11. A computer readable medium having computer-executable instructions for performing a method for converting packet streams into session summaries comprising the steps of:

a. capturing packets from a transport layer,

b. decoding the packets to determine the destination IP address and the source IP address,

c. identifying packets having common destination IP addresses and source IP addresses.

d. writing the decoded packets to an allocated memory structure as session summaries in a queue wherein said session summaries contain only packets having common destination and source IP addresses

e. creating a series of time buckets, each of the time buckets having a predefined beginning time and a predefined end time, wherein the time buckets are sequential in time,

f. associating new session summaries with the time bucket covering the time period corresponding to the time the packet was captured from the transport layer, and

g. moving a session summary to the time bucket at the front of the queue in response to an incoming packet having a destination IP addresses and source IP addresses matching the session summary.

12. The computer readable medium having computer-executable instructions for performing a method for converting packet streams into session summaries of claim 11 wherein the step of decoding the packets further comprises determining TCP port source and destination numbers, flag fields, option fields, sequence number, length parameter, and combinations thereof.

13. The computer readable medium having computer-executable instructions for performing a method for converting packet streams into session summaries of claim 11 wherein the step of decoding the packets further comprises determining UDP port source and destination numbers and the length parameter.

14. The computer readable medium having computer-executable instructions for performing a method for converting packet streams into session summaries of claim 11 , further comprising the step of defining a time out value and deleting session summaries associated with time buckets older than the time out value.

15. The computer readable medium having computer-executable instructions for performing a method for converting packet streams into session summaries of claim 11 wherein the steps of:

a. capturing packets from a transport layer,

b. decoding the packets to determine the destination IP address and the source IP address,

c. identifying packets having common destination IP addresses and source IP addresses, and

d. writing the decoded packets to an allocated memory structure as session summaries in a queue wherein said session summaries contain only packets having common destination and source IP addresses, are performed on at least two separate threads.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2010
From: THIEDE, DAVID R.; O'LEARY, CASEY R.; MAUTH, JEFFERY A.
To: BATTELLE MEMORIAL INSTITUTE
Reel/Frame 025151/0637 →
CONFIRMATORY LICENSE Recorded Feb 22, 2006
From: BATTELLE MEMORIAL INSTITUTE, PACIFIC NORTHWEST DIVISION
To: ENERGY, U.S. DEPARTMENT OF
Reel/Frame 017280/0452 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2005
From: THIEDE, DAVID R.
To: BATTELLE MEMORIAL INSTITUTE
Reel/Frame 016779/0698 →
Continuity (1)
Related Publication 20070019640A1 · Jan 25, 2007