首页> 外国专利> Storing network bidirectional flow data and metadata with efficient processing technique

Storing network bidirectional flow data and metadata with efficient processing technique

机译:利用高效的处理技术存储网络双向流数据和元数据

摘要

A processing technique provides an improved indexing arrangement that enables storage, filtering and querying of metadata used to retrieve packets captured from a network and persistently stored in a data repository. A packet capture engine records the packets in packet capture (PCAP) formats from a network link at a substantially high packet transfer rate to persistent storage of the data repository in a sustained manner. Efficient filtering and querying of the metadata to retrieve the stored packets may be achieved, in part, by organizing the metadata as one or more metadata repositories. The processing technique uses the Berkeley Packet Filter (BPF) language as an interface of a BPF engine to search or index the stored packets in response to queries. The BPF engine processes BPF expressions used as precursors to the indexing arrangement to enable access to the repositories when searching and locating stored packets matching the expressions.
机译:一种处理技术提供了一种改进的索引安排,该索引安排使得能够存储,过滤和查询用于检索从网络捕获并永久存储在数据存储库中的分组的元数据。数据包捕获引擎以相当高的数据包传输速率从网络链路以数据包捕获(PCAP)格式记录数据包,并以持续的方式将数据包持久存储到数据存储库中。可以部分地通过将元数据组织为一个或多个元数据存储库来实现对元数据的有效过滤和查询,以检索存储的数据包。该处理技术使用伯克利分组过滤器(BPF)语言作为BPF引擎的接口来响应查询来搜索或索引存储的分组。 BPF引擎处理用作索引安排前身的BPF表达式,以在搜索和查找与表达式匹配的已存储数据包时能够访问存储库。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号