US2011276709A1PendingUtilityA1

Locational Tagging in a Capture System

Assignee: MCAFEE INC A DELAWARE CORPPriority: May 22, 2006Filed: Jul 21, 2011Published: Nov 10, 2011
Est. expiryMay 22, 2026(expired)· nominal 20-yr term from priority
H04L 63/1408H04L 63/12
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method for locational tagging in a capture system are described. Metadata associated with a captured object includes: information about a location in storage of an object and that objects association to a particular user; and/or tiered location information.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method, comprising:
 receiving a packet at a capture system, which is configured for a network security application in which filtering occurs such that certain flows originated at a first computer are prohibited from reaching their originally intended destination;   determining a location classification for the packet within a tiered location structure of the capture system, the location classification being based, at least in part, on an Internet Protocol (IP) address associated with the packet; and   storing the location classification as part of metadata associated with the packet.   
     
     
         22 . The method of  claim 21 , further comprising:
 comparing the IP address associated with the packet to a tier mapping within the tiered location structure.   
     
     
         23 . The method of  claim 21 , further comprising:
 receiving a search query; and   evaluating tiers in the tiered location structure in order to respond to the query.   
     
     
         24 . The method of  claim 21 , wherein the tiered location structure includes a plurality of tiers offering different levels of abstraction. 
     
     
         25 . The method of  claim 24 , wherein the tiers are a selected one or more of a group of tiers, the group consisting of:
 a building tier corresponding to IP addresses associated with devices in the building;   a floor tier corresponding to IP addresses associated with devices on the floor;   a business division tier corresponding to IP addresses associated with devices of the business division;   a geography tier corresponding to IP addresses associated with devices in a certain geographic region; and   a group tier corresponding to IP addresses associated with devices in the group.   
     
     
         26 . The method of  claim 21 , wherein a separate table is provisioned and reflective of numerical tier values being mapped to human readable values that are different from the numerical tier values. 
     
     
         27 . The method of  claim 21 , further comprising:
 initializing a log file that stores internet protocol (IP) address assignments associated with IP addresses, which can be included in the tiered location structure.   
     
     
         28 . The method of  claim 21 , further comprising:
 creating a list of IP address relationships for tier values of the tiered location structure.   
     
     
         29 . A capture system, comprising:
 a processor; and   a memory, wherein the capture system is configured for:
 receiving a packet at a capture system, which is configured for a network security application in which filtering occurs such that certain flows originated at a first computer are prohibited from reaching their originally intended destination; 
 determining a location classification for the packet within a tiered location structure of the capture system, the location classification being based, at least in part, on an Internet Protocol (IP) address associated with the packet; and 
 storing the location classification as part of metadata associated with the packet. 
   
     
     
         30 . The capture system of  claim 29 , wherein the capture system is further configured for:
 comparing the IP address associated with the packet to a tier mapping within the tiered location structure.   
     
     
         31 . The capture system of  claim 29 , wherein the capture system is further configured for:
 receiving a search query; and   evaluating tiers in the tiered location structure in order to respond to the query.   
     
     
         32 . The capture system of  claim 29 , wherein the tiered location structure includes a plurality of tiers, wherein the tiers offer different levels of abstraction, and wherein the tiers are a selected one or more of a group of tiers, the group consisting of:
 a building tier corresponding to IP addresses associated with devices in the building;   a floor tier corresponding to IP addresses associated with devices on the floor;   a business division tier corresponding to IP addresses associated with devices of the business division;   a geography tier corresponding to IP addresses associated with devices in a certain geographic region; and   a group tier corresponding to IP addresses associated with devices in the group.   
     
     
         33 . The capture system of  claim 29 , wherein a separate table is provisioned and reflective of numerical tier values being mapped to human readable values that are different from the numerical tier values. 
     
     
         34 . The capture system of  claim 29 , wherein the capture system is further configured for:
 initializing a log file that stores internet protocol (IP) address assignments associated with IP addresses, which can be included in the tiered location structure, wherein the log file is a dynamic host configuration protocol (DHCP) log.   
     
     
         35 . Logic encoded in non-transitory media that includes code for execution and when executed by a processor operable to perform operations comprising:
 receiving a packet at a capture system, which is configured for a network security application in which filtering occurs such that certain flows originated at a first computer are prohibited from reaching their originally intended destination;   determining a location classification for the packet within a tiered location structure of the capture system, the location classification being based, at least in part, on an Internet Protocol (IP) address associated with the packet; and   storing the location classification as part of metadata associated with the packet.   
     
     
         36 . The logic of  claim 35 , the operations further comprising:
 comparing the IP address associated with the packet to a tier mapping within the tiered location structure.   
     
     
         37 . The logic of  claim 35 , the operations further comprising:
 receiving a search query; and   evaluating tiers in the tiered location structure in order to respond to the query.   
     
     
         38 . The logic of  claim 35 , wherein the tiered location structure includes a plurality of tiers offering different levels of abstraction. 
     
     
         39 . The logic of  claim 35 , wherein a separate table is provisioned and reflective of numerical tier values being mapped to human readable values that are different from the numerical tier values.

Join the waitlist — get patent alerts

Track US2011276709A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.