US2011208861A1PendingUtilityA1
Object classification in a capture system
Est. expiryJun 23, 2024(expired)· nominal 20-yr term from priority
H04L 67/63H04L 67/568H04L 67/564H04L 67/56H04L 63/12
48
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Objects can be extracted from data flows captured by a capture device. Each captured object can then be classified according to content. In one embodiment, the present invention includes determining whether a captured object is binary or textual in nature, and classifying the captured object as one of a plurality of textual content types based tokens found in the captured object if the captured object is determined to be textual in nature.
Claims
exact text as granted — not AI-modified1 .- 31 . (canceled)
32 . A method, comprising:
receiving a flow of packets in a network environment; extracting an object from at least one of the packets; classifying the object based on at least one signature provided inside the object; and providing the object to an object statistics module configured to perform a statistical calculation in order to determine whether the object is binary or textual.
33 . The method of claim 32 , wherein if the object is binary, a determination is made whether the object is encrypted.
34 . The method of claim 32 , wherein if the object is textual, a determination is made about a type of text in the object.
35 . The method of claim 32 , wherein at least one statistical analysis is performed in order to evaluate a frequency of bytes contained in the object.
36 . The method of claim 32 , wherein if the object is determined to be binary, then a distribution analysis is performed to determine whether bytes in the object are uniformly distributed.
37 . The method of claim 36 , wherein if the bytes are distributed uniformly, then the object is classified as being associated with encrypted data.
38 . The method of claim 36 , wherein if a byte distribution is found to be non-uniform, the object is classified using a catchall binary unknown type.
39 . The method of claim 32 , further comprising:
inserting an indicator reflective of the object being classified as binary or textual.
40 . The method of claim 32 , further comprising:
generating a tag data structure that includes a content field associated with the object.
41 . The method of claim 32 , wherein if the object is determined to be textual, a token database is accessed in order to statistically analyze a presence of certain tokens in the object.
42 . The method of claim 41 , wherein at least some of the tokens in the token database are reflective of either a word, a phrase, a syntax, a grammatical notation, or a part of a word.
43 . The method of claim 41 , wherein the token database is organized by content type.
44 . The method of claim 41 , wherein particular tokens in the token database have a numerical weight associated thereto.
45 . The method of claim 41 , wherein a token analyzer is configured to access the token database in order to sum weights for content types associated with particular tokens of the object.
46 . The method of claim 41 , wherein certain tokens in the token database are weighted differently as a function of their frequency and as a function of their strength in an association with a specific content type.
47 . The method of claim 41 , wherein the token analyzer is configured to assign a confidence characteristic to its content classification.
48 . The method of claim 41 , wherein the token analyzer is configured to perform object classification using a Bayesian statistical analysis, which is indicative of a probability of a correctness of a particular classification.
49 . The method of claim 41 , wherein the signature is a binary signature associated with a bit torrent.
50 . An apparatus comprising:
a processor; a memory element; and an object statistics module, wherein the processor and the memory element interact with the object statistics module such that the apparatus is configured for;
receiving a flow of packets in a network environment;
extracting an object from at least one of the packets;
classifying the object based on at least one signature provided inside the object; and
providing the object to an object statistics module configured to perform a statistical calculation in order to determine whether the object is binary or textual, wherein at least one statistical analysis is performed in order to evaluate a frequency of bytes contained in the object.
51 . Logic encoded in non-transitory media that includes code for execution and when executed by a processor operable to perform operations comprising:
receiving a flow of packets in a network environment; extracting an object from at least one of the packets; classifying the object based on at least one signature provided inside the object; and providing the object to an object statistics module configured to perform a statistical calculation in order to determine whether the object is binary or textual, wherein if the object is determined to be textual, a token database is accessed in order to statistically analyze a presence of certain tokens in the object.Join the waitlist — get patent alerts
Track US2011208861A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.