Claims
- 1. A method permitting access for monitoring network traffic, said method comprising:
defining a plurality of views of network traffic, each of the views containing a subset of network traffic that satisfies a set of conditions, and at least one of the views is a group view comprising two or more previously defined views as members; classifying network traffic passing through a network component according to the views; selecting a group view for permitting access to a given user; and associating the given user with the group view.
- 2. A method as in claim 1 wherein types of conditions imposed on the views are based on data categories comprising at least one of the following: network address, application, protocol, flow type, packet type, geographic region, ICMP type, slow scan, operating system, flag, remote host count, local host count, spoofing, fragments, service, sessions, response time, status, and user.
- 3. A method permitting access to a system for monitoring network traffic, said method comprising:
defining parameters relating to a network configuration of a network; generating graphical user interface menu items based on said parameters, a first set of parameters producing a first set of menu items and a second set of parameters producing a second set of menu items; and for a given user, permitting access to at least one set of menu items by associating the given user therewith.
- 4. A method as claimed in claim 3 wherein said parameters define a plurality of views of network traffic.
- 5. A method as claimed in claim 4 wherein each of the views contains a subset of network traffic that satisfies a set of conditions.
- 6. A method as claimed in claim 5 wherein a part of the menu items are related to the views.
- 7. A method as in claim 6 wherein a subset of the views is based on different data categories.
- 8. A method as claimed in claim 7 wherein a part of the menu items are related to a composite view of the subset of the views, wherein the composite view contains an intersection of network traffic of the subset of the views.
- 9. A method for monitoring network traffic, said method comprising:
defining a plurality of views of network traffic, each of the views containing a subset of network traffic that satisfies a set of conditions and at least one of the views is a group view comprising two or more previously defined views as members; associating a given user with the group view thereby giving access thereto; and the given user displaying the group view of network traffic.
- 10. A method as in claim 9 further comprising:
determining a selection of a selected group view; displaying network traffic of members of the selected group view; displaying, in response to a selection of a selected member of the selected group view, network traffic of the selected member.
- 11. A method permitting access for monitoring network traffic, said method comprising:
defining a plurality of views of network traffic, each of the views containing a subset of network traffic that satisfies a set of conditions, and at least one of the views is a group view comprising two or more previously defined views as members; classifying network traffic passing through a network component according to the views; forming a group view from a set of selected views; selecting the group view for permitting access to a given user; and associating the given user with the group view.
- 12. A method as in claim 11 wherein types of conditions imposed on the views are based on data categories comprising at least one of the following: network address, application, protocol, flow type, packet type, geographic region, ICMP type, slow scan, operating system, flag, remote host count, local host count, spoofing, fragments, service, sessions, response time, status, and user.
- 13. A method permitting access to a system for monitoring network traffic, said method comprising:
defining parameters relating to a network configuration of a network; generating graphical user interface menu items based on said parameters, a first set of parameters producing a first set of menu items and a second set of parameters producing a second set of menu items; and restricting graphical user interface menu items presented to a given user by associating a subset of menu items with the given user.
- 14. A method as claimed in claim 13 wherein said parameters define a plurality of views of network traffic.
- 15. A method as claimed in claim 14 wherein each of the views contains a subset of network traffic that satisfies a set of conditions.
- 16. A method as claimed in claim 15 wherein a part of the menu items are related to the views.
- 17. A method as in claim 16 wherein a subset of the views is based on different data categories.
- 18. A method as claimed in claim 17 wherein a part of the menu items are related to a composite view of the subset of the views, wherein the composite view contains an intersection of network traffic of the subset of the views.
- 19. A machine readable media containing executable computer program instructions which when executed by a digital processing system causes said system to perform a method comprising:
permitting access for monitoring network traffic, said method comprising: defining a plurality of views of network traffic, each of the views containing a subset of network traffic that satisfies a set of conditions, and at least one of the views is a group view comprising two or more previously defined views as members; classifying network traffic passing through a network component according to the views; selecting a group view for permitting access to a given user; and associating the given user with the group view.
- 20. A media as in claim 19 wherein types of conditions imposed on the views are based on data categories comprising at least two of the following: network address, application, protocol, flow type, packet type, geographic region, ICMP type, slow scan, operating system, flag, remote host count, local host count, spoofing, fragments, service, sessions, response time, status, and user.
- 21. A machine-readable media containing executable computer program instructions, which when executed by a digital processing system causes said system to perform a method comprising:
defining parameters relating to a network configuration of a network; generating graphical user interface menu items based on said parameters, a first set of parameters producing a first set of menu items and a second set of parameters producing a second set of menu items; and for a given user, permitting access to at least one set of menu items by associating the given user therewith.
- 22. Apparatus for permitting access for monitoring network traffic comprising:
configuration files for defining a plurality of views of network traffic, each of the views for containing a subset of network traffic that satisfies a set of conditions, and at least one of the views is a group view comprising two or more previously defined views as members; a classification engine for classifying network traffic passing through a network component according to the views; and a master console for selecting a group view for permitting access to a given user and associating the given user with the group view.
- 23. Apparatus as in claim 22 wherein types of conditions imposed on the views are based on data categories comprising at least one of the following: network address, application, protocol, flow type, packet type, geographic region, ICMP type, slow scan, operating system, flag, remote host count, local host count, spoofing, fragments, service, sessions, response time, status, and user.
- 24. Apparatus for permitting access to a system for monitoring network traffic comprising:
configuration files for defining parameters relating to a network configuration of a network; a graphical user interface for generating menu items based on said parameters, a first set of parameters producing a first set of menu items and a second set of parameters producing a second set of menu items; and a master console for permitting a given user access to at least one set of menu items by associating the given user therewith.
- 25. Apparatus for permitting access for monitoring network traffic comprising:
configuration files for defining a plurality of views of network traffic, each of the views for containing a subset of network traffic that satisfies a set of conditions, and at least one of the views is a group view comprising two or more previously defined views as members; a classification engine for classifying network traffic passing through a network component according to the views; and a master console for forming a group view from a set of selected views, selecting the group view for permitting access to a given user, and associating the given user with the group view.
- 26. Apparatus as in claim 22 wherein types of conditions imposed on the views are based on data categories comprising at least one of the following: network address, application, protocol, flow type, packet type, geographic region, ICMP type, slow scan, operating system, flag, remote host count, local host count, spoofing, fragments, service, sessions, response time, status, and user.
- 27. Apparatus for permitting access to a system for monitoring network traffic comprising:
configuration files for defining parameters relating to a network configuration of a network; a graphical user interface for generating menu items based on said parameters, a first set of parameters producing a first set of menu items and a second set of parameters producing a second set of menu items; and a master console for restricting graphical user interface menu items presented to a given user by associating a subset of menu items with the given user.
RELATED APPLICATIONS
[0001] The present invention relates co-pending U.S. patent application Ser. No. 09/872,995 the entire specification of which is hereby incorporated by reference.