IP Library Granted Patent US 8,301,753
Granted Patent B1
US 8,301,753 · App. 11/426,687 · Granted Oct 30, 2012

Endpoint activity logging

Assignee: Nosadia Pass NV, Limited Liability Company
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,301,753
App. No.
11/426,687
Granted
Oct 30, 2012
Kind
B1
Abstract

The ability to identify a specific machine associated with activity taking place on the Internet is provided. This involves recording the association between MAC addresses, which are uniquely associated with endpoints, and local IP addresses, the recording of the association between local IP addresses and port numbers with public IP addresses and port numbers, and the recording of public IP addresses and source port numbers associated with public activity. By recording this information and correlating it, in real-time or in a post-processing step, the specific machine associated with public activity can be determined.

Claims (34)

1. A computer implemented method for logging network activity comprising:

identifying a code to represent a network adapter coupled to a first network;

storing first data, wherein the first data is based at least in part on a first association between the code and a first IP address that has been allocated on the first network;

dynamically translating from the first IP address for use on the first network to a second IP address for use on a second network;

storing second data, wherein the second data is based on an establishment of a network address alias, wherein the network address alias includes the first IP address used on the first network and a first IP port number used on the second network;

transmitting, by at least one source computing device, a request to a destination server via the second network, wherein the destination server is associated with a destination IP address and a destination port number, wherein the request originated from the network adapter and identifies the first IP port number used on the second network, and wherein the first IP port number used on the second network corresponds to a source IP port number used on the second network for the request;

receiving third data at the at least one source computing device from the destination server, wherein receipt of the third data is responsive to the request from the at least one source computing device, wherein the third data is associated with a first historical log entry initially stored by the destination server, and wherein the first historical log entry includes identification of the source IP port number for the request and information corresponding to activity at the destination server associated with the request; and

determining a second association between the activity at the destination server associated with the request and the code representing the network adapter from which the request originated based at least in part on the first data, the second data, and the first historical log entry initially stored by the destination server.

2. The method of claim 1 , wherein the code comprises a 48-bit Ethernet Media Access Control (MAC) address.

3. The method of claim 1 , wherein the network address alias further comprises the second IP address used on the second network and a second IP port number used on the first network.

4. The method claim 1 , wherein the first historical log entry includes a URL.

5. The method of claim 1 , wherein the first historical log entry includes a user id determined by http authentication.

6. The method of claim 1 , wherein the first historical log entry includes the http status code sent back to the at least one source computing device.

7. A computer system for logging network activity comprising:

a network adapter attached to a first network having a code;

means for storing first data, wherein the first data is based at least in part on a first association between the code and a first IP address that has been allocated on the first network;

means for dynamically translating from the first IP address for use on the first network to a second IP address for use on a second network;

means for storing second data, wherein the second data is based at least in part on an establishment of a network address alias, wherein the network address alias includes the first IP address used on the first network and a first IP port number used on the second network;

means for transmitting, by at least one source computing device, a request to a destination server via the second network, wherein the destination server is associated with a destination IP address and a destination port number, wherein the request originated from the network adapter and identifies the first IP port number used on the second network, and wherein the first IP port number used on the second network corresponds to a source IP port number used on the second network for the request;

means for receiving third data at the at least one source computing device from the destination server, wherein receipt of the third data is responsive to the request from the at least one source computing device, wherein the third data is associated with a first historical log entry initially stored by the destination server, and wherein the first historical log entry includes identification of the source IP port number for the request and information corresponding to activity at the destination server associated with the request; and

means for determining a second association between the activity at the destination server associated with the request and the code representing the network adapter from which the request originated based at least in part on the first data, the second data, and the first historical log entry initially stored by the destination server.

8. The system of claim 7 , wherein the code comprises a 48-bit Ethernet Media Access Control (MAC) address.

9. The system of claim 7 , wherein the network address alias further comprises a second IP address used on the second network and a second IP port number used on the first network.

10. The system of claim 7 , wherein the first historical log entry includes a user id determined by http authentication.

11. A computer system for logging network activity, the system comprising:

a network adapter having a code attached to a first network;

a first computing apparatus configured to store first data, based at least in part on a first association between the code and a first IP address that has been allocated on the first network;

a first translation apparatus configured to dynamically translate from the first IP address for use on the first network to a second IP address for use on a second network;

a second computing apparatus configured to store second data based at least in part on an establishment of a network address alias by the first translation apparatus, wherein the network address alias includes the first IP address used on the first network and a first IP port number used on the second network;

means for transmitting, by at least one source computing device, a request to a destination server via the second network, wherein the destination server is associated with a destination IP address and a destination port number, wherein the request originated from the network adapter and identifies the first IP port number used on the second network, and wherein the first IP port number used on the second network corresponds to a source IP port number used on the second network for the request;

means for receiving third data at the at least one source computing device from the destination server, wherein receipt of the third data is responsive to the request from the at least one source computing device, wherein the third data is associated with a first historical log entry initially stored by the destination server, and wherein the first historical log entry includes identification of the source IP port number for the request and information corresponding to activity at the destination server associated with the request; and

means for determining a second association between the activity at the destination server associated with the request and the code representing the network adapter from which the request originated based at least in part on the first data, the second data, and the first historical log entry initially stored by the destination server.

12. The system of claim 11 , wherein the first historical log entry includes a URL.

13. The system of claim 11 , wherein the first historical log entry includes the http status code sent back to the at least one source computing device.

Assignments (2)
MERGER Recorded Jan 15, 2016
From: NOSADIA PASS NV, LIMITED LIABILITY COMPANY
To: CALLAHAN CELLULAR L.L.C.
Reel/Frame 037541/0602 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2010
From: MELVIN, STEPHEN W., DR.
To: NOSADIA PASS NV, LIMITED LIABILITY COMPANY
Reel/Frame 024933/0806 →