Patent · US Active

Apparatus and method to collect packets related to abnormal connection

US10305754B2 · kind B2 · utility

0Cited by
3References
5Claims
0Family size

Assignee

Inventors

Key dates

Filing dateNov 4, 2016
Grant dateMay 28, 2019
Priority date
Expiry dateNov 17, 2037

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L43/10
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

An apparatus allocates a packet-identifier to each packet captured from a network, and stores the each packet in a buffer. The apparatus associates, with each of the packet-identifiers, a connection-identifier specifying a connection of a packet identified by the each packet-identifier, and detects a connection to which a primary abnormality is occurring by analyzing packets stored in the buffer. The apparatus stores, for each connection to which the primary abnormality has occurred, a primary-abnormality group of packets to which the packet-identifiers associated with the connection-identifier of the each connection are allocated, in a first storage-region, detects a connection to which a secondary abnormality is occurring, based on a statistical value related to results of analyses on packets captured in a sampling duration, and writes, in a second storage-region, packets related to connections to which the secondary abnormality has occurred, among the primary-abnormality groups stored in the first storage-region.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.