The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 10, 2018

Filed:

Feb. 29, 2016
Applicant:

Airmagnet, Inc., Santa Clara, CA (US);

Inventors:

Robert Vogt, Colorado Springs, CO (US);

Peter Reilly, Colorado Springs, CO (US);

Blair Pendelton, Colorado Springs, CO (US);

Arong Pan, Beijing, CN;

Lei Xiong, Beijing, CN;

Matthew Richards, Colorado Springs, CO (US);

Assignee:

AirMagnet, Inc., Santa Clara, CA (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
H04L 12/26 (2006.01); H04L 12/801 (2013.01); H04L 12/863 (2013.01); G06F 17/30 (2006.01);
U.S. Cl.
CPC ...
H04L 43/106 (2013.01); G06F 17/30 (2013.01); H04L 43/04 (2013.01); H04L 43/0888 (2013.01); H04L 43/0894 (2013.01); H04L 47/10 (2013.01); H04L 47/50 (2013.01); H04L 43/026 (2013.01); H04L 43/045 (2013.01);
Abstract

A storage system includes network monitoring device having NIC coupled to network and configured to capture raw data packets. The system further includes 4 data repositories. A first repository stores captured packets. A second repository stores captured packets' metadata. A third repository stores captured packets' and metadata's timestamp indexed data. A fourth repository stores captured packets' data flow. The storage system further includes a storage engine coupled to the repositories. The storage engine receives packet search criteria specifying at least a first time range. Data flow information associated with the search criteria is retrieved from the fourth repository. The retrieved data flow information is associated with a second, narrower, time range. Metadata information associated with the second time range is retrieved from the second repository using corresponding timestamp indexed data. Captured packets associated with the retrieved metadata are retrieved from the first repository using corresponding timestamp indexed data.


Find Patent Forward Citations

Loading…