DOE Patents title logo U.S. Department of Energy
Office of Scientific and Technical Information

Title: Full flow retrieval optimized packet capture

Abstract

A packet capture system may copy packets from an interface to a bucket. When the bucket is full of packets, a new bucket for incoming packets may be started, and the full bucket may be indexed. During the indexing, each packet may be sorted in the bucket by flow, and each flow may be indexed. Once indexing is complete, the packets are written to a flow ordered FCAP file and the indexes are written to disk. The flow ordered nature of the FCAP file combined with the indices and their associated search algorithms allow for rapid retrieval of captured flows.

Inventors:
Issue Date:
Research Org.:
Los Alamos National Laboratory (LANL), Los Alamos, NM (United States)
Sponsoring Org.:
USDOE
OSTI Identifier:
1525041
Patent Number(s):
10230643
Application Number:
15/139,484
Assignee:
Ferrell, Paul, Los Alamos, NM (United States)
Patent Classifications (CPCs):
H - ELECTRICITY H04 - ELECTRIC COMMUNICATION TECHNIQUE H04L - TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
DOE Contract Number:  
AC52-06NA25396
Resource Type:
Patent
Resource Relation:
Patent File Date: 2016-04-27
Country of Publication:
United States
Language:
English
Subject:
97 MATHEMATICS AND COMPUTING

Citation Formats

Ferrell, Paul. Full flow retrieval optimized packet capture. United States: N. p., 2019. Web.
Ferrell, Paul. Full flow retrieval optimized packet capture. United States.
Ferrell, Paul. Tue . "Full flow retrieval optimized packet capture". United States. https://www.osti.gov/servlets/purl/1525041.
@article{osti_1525041,
title = {Full flow retrieval optimized packet capture},
author = {Ferrell, Paul},
abstractNote = {A packet capture system may copy packets from an interface to a bucket. When the bucket is full of packets, a new bucket for incoming packets may be started, and the full bucket may be indexed. During the indexing, each packet may be sorted in the bucket by flow, and each flow may be indexed. Once indexing is complete, the packets are written to a flow ordered FCAP file and the indexes are written to disk. The flow ordered nature of the FCAP file combined with the indices and their associated search algorithms allow for rapid retrieval of captured flows.},
doi = {},
journal = {},
number = ,
volume = ,
place = {United States},
year = {Tue Mar 12 00:00:00 EDT 2019},
month = {Tue Mar 12 00:00:00 EDT 2019}
}

Works referenced in this record:

Packet file system
patent, June 2013


Managing timeouts for dynamic flow capture and monitoring of packet flows
patent, December 2009


Method and system for storing packet flows
patent, October 2016