Claims
- 1. A method for processing data on a communication line comprising the steps of.
(a) receiving the data from the communication line; (b) segregating the data into the packets; (c) selecting packets based on a respective characteristic; (d) providing the selected packets to one of a plurality of data processing units.
- 2. A method according to claim 1 wherein step (c) includes selecting packets corresponding to a session.
- 3. A method according to claim 1 wherein step (c) includes selecting packets based on at lease one of a source address, a destination address, an autonomous system a source port, a destination port, a network identifier and a pair of hosts.
- 4. A method according to claim 2 wherein step (d) includes providing the selected packets to one of a plurality of intrusion detection devices.
- 5. A method according to claim 1 further comprising the step of encrypting the selected packets before step (d).
- 6. A method according to claim 1 wherein step (c) cases selecting packets based on a respective type.
- 7. A method according to claim 1 further comprising the step of storing the segregated packets and step (c) includes selecting stored packets based on a respective characteristic.
- 8. A method according to claim 1 wherein step (a) includes receiving data under a first protocol and step (d) includes providing the selected packets under a second protocol different from the first protocol.
- 9. A method for processing data on a communication line comprising the steps of:
(a) receiving the data from the communication line; (b) segregating the data into packets; (c) selecting packets based on a respective characteristic; (d) generating a statistic corresponding to the selected packets; (e) generating a threshold based on historical values of the statistic; (e) generating an alarm signal if the statistic exceeds the threshold.
- 10. A method according to claim 9 wherein the statistic corresponds to the number of packets of differ users received from one source address.
- 11. A method according to claim 9 wherein the statistic corresponds to the number of packets received for modifying a key file.
- 12. A method according to claim 9 wherein the statistic corresponds to the number of host pair connections involving a common source or destination address.
- 13. A method according to claim 9 wherein the statistic corresponds to a packet rate corresponding to a host pair.
- 14. A method according to claim 9 wherein the statistic corresponds to the individual sessions corresponding to a host.
- 15. A method according to claim 9 wherein the statistic corresponds the utilization of the communication line over a given period of time.
- 16. A method according to claim 9 wherein the statistic corresponds to a number of invalid source or donation addresses.
- 17. A system for monitoring communication on a network, the system Comprising:
a plurality of network monitors coupled to receive data from their respective communication lines; a management module coupled to each of the plurality of network monitors for receiving at least one of the received data and statistics corresponding to the received data from at least one of the plurality of network monitors.
- 18. A method for collecting and analyzing data transmitted on a network comprising the steps of:
(a) receiving data from a first communication line; (b) segregating the data from the first communication line into packets; (c) receiving data from a second communication line; (d) segregating the data from the second communication line into packets; (e) providing at least one of selected packets from the first communication line and statistics corresponding to the selected packets from the first communication line to a central management module; (f) providing at least one of selected packets from the second communication line and statistics corresponding to the selected packets from the second communication line to a central management module.
Parent Case Info
[0001] This application claims the benefit of priority under 35 U.S.C. § 119 from U.S. Provisional Patent Application Serial No. 60/203,652 filed May 12, 2000, which is hereby incorporated by reference. PCT Application PCT/US99/27969 is incorporated herein by reference.
PCT Information
| Filing Document |
Filing Date |
Country |
Kind |
| PCT/US01/15601 |
5/12/2001 |
WO |
|