首页> 外国专利> Correlating network traffic to their OS processes using packet capture libraries and kernel monitoring mechanisms

Correlating network traffic to their OS processes using packet capture libraries and kernel monitoring mechanisms

机译:使用数据包捕获库和内核监视机制将网络流量与其操作系统进程相关联

摘要

A method of monitoring and reporting of packets including their attribution to their origin processes from a user space application without installing proprietary drivers, rather using only infrastructures and capabilities supplied by the operating system (OS). The method relies on correlation between packets received from a packet capture library and a kernel monitoring mechanism that supplies an event with the process ID which is executed on the same time frame for transmitting or receiving of that traffic. The attribution between the event and the packet is based on the 4-tuple (or other exemplar) that exists on both the event and the packet where the “4-tuple” is a set of: source address, source port, destination address, destination port.
机译:一种监视和报告数据包的方法,包括从用户空间应用程序将其归因于其原始进程,而无需安装专有驱动程序,而仅使用操作系统(OS)提供的基础结构和功能。该方法依赖于从分组捕获库接收到的分组与内核监视机制之间的相关性,该内核监视机制为事件提供进程ID,该进程ID在同一时间帧上执行以发送或接收该流量。事件和数据包之间的归属基于事件和数据包上都存在的4元组(或其他示例),其中“ 4元组”是一组:源地址,源端口,目标地址,目的端口。

著录项

  • 公开/公告号US2020099600A1

    专利类型

  • 公开/公告日2020-03-26

    原文格式PDF

  • 申请/专利权人 CYBEREASON INC.;

    申请/专利号US201916579455

  • 发明设计人 GAL KAPLAN;

    申请日2019-09-23

  • 分类号H04L12/26;H04L29/12;H04L12/741;

  • 国家 US

  • 入库时间 2022-08-21 11:21:11

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号