Full flow retrieval optimized packet capture
Abstract
A packet capture system may copy packets from an interface to a bucket. When the bucket is full of packets, a new bucket for incoming packets may be started, and the full bucket may be indexed. During the indexing, each packet may be sorted in the bucket by flow, and each flow may be indexed. Once indexing is complete, the packets are written to a flow ordered FCAP file and the indexes are written to disk. The flow ordered nature of the FCAP file combined with the indices and their associated search algorithms allow for rapid retrieval of captured flows.
- Inventors:
- Issue Date:
- Research Org.:
- Los Alamos National Laboratory (LANL), Los Alamos, NM (United States)
- Sponsoring Org.:
- USDOE
- OSTI Identifier:
- 1525041
- Patent Number(s):
- 10230643
- Application Number:
- 15/139,484
- Assignee:
- Ferrell, Paul, Los Alamos, NM (United States)
- Patent Classifications (CPCs):
-
H - ELECTRICITY H04 - ELECTRIC COMMUNICATION TECHNIQUE H04L - TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- DOE Contract Number:
- AC52-06NA25396
- Resource Type:
- Patent
- Resource Relation:
- Patent File Date: 2016-04-27
- Country of Publication:
- United States
- Language:
- English
- Subject:
- 97 MATHEMATICS AND COMPUTING
Citation Formats
Ferrell, Paul. Full flow retrieval optimized packet capture. United States: N. p., 2019.
Web.
Ferrell, Paul. Full flow retrieval optimized packet capture. United States.
Ferrell, Paul. Tue .
"Full flow retrieval optimized packet capture". United States. https://www.osti.gov/servlets/purl/1525041.
@article{osti_1525041,
title = {Full flow retrieval optimized packet capture},
author = {Ferrell, Paul},
abstractNote = {A packet capture system may copy packets from an interface to a bucket. When the bucket is full of packets, a new bucket for incoming packets may be started, and the full bucket may be indexed. During the indexing, each packet may be sorted in the bucket by flow, and each flow may be indexed. Once indexing is complete, the packets are written to a flow ordered FCAP file and the indexes are written to disk. The flow ordered nature of the FCAP file combined with the indices and their associated search algorithms allow for rapid retrieval of captured flows.},
doi = {},
journal = {},
number = ,
volume = ,
place = {United States},
year = {2019},
month = {3}
}
Save to My Library
You must Sign In or Create an Account in order to save documents to your library.
Works referenced in this record:
Managing timeouts for dynamic flow capture and monitoring of packet flows
patent, December 2009
- Chang, Szelap Philip; Apte, Manoj; Deenadayalan, Saravanan
- US Patent Document 7,633,944
Method and system for storing packet flows
patent, October 2016
- Henry, Thomas; Blomquist, Scott A.
- US Patent Document 9,473,373