Method of surveilling intennet communication
Abstract
A network detector terminal used to track network communication lines and simulate the browser activity of a given terminal. The detector terminal monitors TCP/IP data packets routed through the communication line to filter related requests and responses involving a given IP address. These requests and responses are analyzed and classified according to their type and content. Based on this analysis, the probe terminal identifies all relevant data transactions involving the navigation process of a given terminal. The probe terminal activates a virtual browser that simulates the processing of the identified data transaction to create a navigational presentation similar to the actual navigation seen by a given terminal user.

Term
Term ended
Projected expiry passed 23 May 2021, 5.3 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
18 claims: 2 independent, 16 dependent
- 1一种通过网络探测器终端(“终端代理”)仿真一个给定终端的浏览器(“初始浏览器”)活动来跟踪网络通信线的方法,该方法包括步骤:I.接入网络通信线;II.跟踪通过通信线路由的TCP/IP数据分组;III.选择涉及一个给定IP地址的TCP/IP数据分组(“所识别的数据分组”);IV.从所识别的数据分组中选择对于新连接的当前请求(“初始请求”);V.从所识别的数据分组中选择指示新地址的当前网页组件(“新导航组件”);VI.将新导航组件划分成为两类:(f1)嵌入对象或帧(“错误的新组件”);(f2)超级链接(“正确的新组件”);VII.根据下列原则将初始请求分别划分成为“主要”或“次要”请求:(g1)初始请求与正确的新组件相匹配,或者初始请求不能与任何新连接组件相匹配并属于HTTP或POST类型;(g2)初始请求与错误组件相匹配或者初始请求不与任何新连接组件相匹配并且不属于HTTP或POST类型;VIII.从所识别的数据分组中选择涉及主要请求的HTML数据文件(“各自的主要响应”);IX.根据各自的次要响应生成“虚拟”的次要请求;X.从所识别的数据分组中选择涉及次要虚拟请求的响应;(“各自的次要响应”);以及XI.根据各自的次要响应仿真终端代理上的网页呈现。
- 2根据权利要求1所述的方法,还包括步骤:—选择当前与任何各自的初始响应(“未回答的次要请求”)不匹配的虚拟次要请求;—如果初始浏览器本地高速缓存(“初始高速缓存”)被涉及未回答的次要请求使用,则从终端代理的本地高速缓存(“虚拟高速缓存”)中检索内容;—如果虚拟高速缓存含有这种数据,则根据涉及未回答的次要请求的数据来仿真代理终端上的网页呈现;以及—如果虚拟高速缓存不含有涉及未回答次要请求的数据,则在代理终端的各自位置上显示错误消息。
- 3根据权利要求2所述的方法,还包括步骤:如果虚拟高速缓存不含有数据,则通过通信线寻址到恰当的互联网服务器,以便接收涉及未回答的次要请求的各自被仿真的响应并将其显示。
- 4根据权利要求1所述的方法,还包括步骤:—从所识别的数据分组中选择涉及如电子邮件的网络消息的数据(“消息数据”);—将消息数据转换成为文本数据文件;以及—在终端代理上显示文本数据文件。
- 5根据权利要求1所述的方法,其中网络是局域网(LAN),并且终端连接到扩展的通信线上。
- 6根据权利要求1所述的方法,其中通信线是一条外部通信线,例如电话线、ISDN线、光线路等。
- 7根据权利要求1所述的方法,其中网络是局域网(LAN),并且终端代理位于不同于给定终端的一个位置。
- 8根据权利要求1所述的方法,其中由通信线提供者(ISP)识别给定的IP地址。
- 9根据权利要求1所述的方法,其中由通信线拥有者识别给定的IP地址。
- 10根据权利要求1所述的方法,其中给定的IP地址是网站访问者的地址并由网站拥有者识别。
- 11一种用于跟踪网络通信线并仿真一个给定终端的浏览器(“初始浏览器”)活动的网络探测器终端,包括:I.用于接入网络通信线的连接装置;II.用于跟踪路由通过通信线的TCP/IP数据分组的监控装置;III.用于从涉及一个给定IP地址的TCP/IP数据分组(“所识别的数据分组”)中选择新的连接请求(“初始请求”)以及指示新地址(“新导航组件”)的网页组件的第一过滤模块;IV.用于将新的导航组件划分成为两类的第一分类装置;(f1)嵌入对象或帧(“错误的新组件”);(f2)超级链接(“正确的新组件”)V.用于根据下述原则分别将初始请求划分成为“主要”或“次要”请求的第二分类装置:(g1)初始请求与正确的新组件相匹配,或者初始请求不能与任何新连接组件相匹配并属于HTTP或POST类型;(g2)初始请求与错误组件相匹配或者初始请求不与任何新连接组件相匹配并且不属于HTTP或POST类型;VI.用于从所识别的数据分组中选择涉及主要请求(“主要响应”)的HTML数据文件的分类模块;VII.用于根据各自的次要响应而创建“虚拟”次要请求的请求生成模块;VIII.用于从所识别的数据分组中选择涉及次要虚拟请求的响应(“次要响应”)的第二过滤模块;以及IX.用于根据次要响应来仿真在终端代理上的网页呈现的显示装置。
- 12根据权利要求11的网络探测器终端,其中过滤模块包括用于选择目前与任何各自的初始响应不匹配的虚拟次要请求(“未回答的次要请求”)的装置。
- 13根据权利要求11的网络探测器终端,还包括高速缓存模块,用于如果初始浏览器本地高速缓存(“初始高速缓存”)已经被响应于未回答的次要请求而使用,则激活终端代理本地高速缓存。
- 14根据权利要求13的网络探测器终端,还包括一个检索模块,用于如果虚拟本地高速缓存不含有数据,则通过通信线寻址到恰当的互联网服务器并且接收涉及未回答的次要请求的各自被仿真的响应。
- 15根据权利要求11的网络探测器终端,还包括一个电子消息模块,用于选择涉及如电子邮件的网络消息的所识别的数据分组数据(“消息数据”),将消息数据转换成为文本数据文件,并将文本数据文件显示在终端上。
- 16根据权利要求11的网络探测器终端,其中由通信线提供者(ISP)识别给定的IP地址。
- 17根据权利要求11的网络探测器终端,其中由通信线拥有者(ISP)识别给定的IP地址。
- 18根据权利要求11的网络探测器终端,其中给定的IP地址是网站访问者的地址并由网站拥有者识别。
Independent claims18
36 paragraphs, as filed
Methods of monitoring Internet communications
BACKGROUND OF THE INVENTION The present invention relates to a method and system for enabling monitoring and monitoring of a network by analyzing data passing therethrough.
A large number of businesses are passing through todays computer networks, but not all businesses are harmless. Therefore, the owner or administrator of a given network may be very interested in being able to track or "listen" in real time in order to effectively monitor and/or protect the network. This monitoring or monitoring can be achieved by connecting a probe to the network to monitor data passing between two of multiple nodes (for example, user workstations) on the network.
In a system where the communication between two nodes is in the form of discrete packets, the network probe can "read" a data packet to collect information such as the source and destination addresses of the packet or the packet's protocol. In addition, statistics and related information can be calculated, such as the total or average number of traffic of a certain protocol type in a given time period, or the total number of packets sent to or from a node. This information can be reported to the system administrator in real time or stored for later analysis.
Various attempts have been made in this regard. For example, in Lincolnshire, USA, the software program "Clear View Network Window" of Clear Communications Company III states that it provides predictive/proactive maintenance, intelligent root cause analysis, and quality verification reports. However, the output is a network fault management design, which is different from "eavesdropping" on the communication between two nodes in the network. In this way, the clear observation system does not allow monitoring of data transmitted between two nodes in the network regarding content or characteristics.
The Livermore National Laboratory in Livermore, California, USA has developed a set of computer programs to protect the U.S. Department of Energy's computers by "error testing" data packets through a local area network. The National Aeronautics and Space Administration used one of these programs, called the "iWatch" program, to eavesdrop on a computer-hackable communication that broke into the computer systems of the U.S. Department of Defense and NASA. The iWatch program uses a network probe to read all packets passing through a network, and then "store" the information in a public database. Then, you can write a simple computer program to read the stored data and display only the predefined "interesting" pieces of information.
Whenever an interesting piece of information is found, the stored information is rescanned, and a certain number of characters at both ends of the "interesting" information are reported. These interesting characters are then re-observed to determine the content of the message and used as a guide for future monitoring activities.
The system is limited to historical analysis of user activities, and cannot complete the "eavesdropping" of all user activities and the complete simulation of user surfing activities.
Three major problems were encountered in obtaining continuous and reliable tracking: (a) Each browser did not report all activities performed on a web server. For example, when a browser loads a web page from its browser cache space or from a proxy server, it does not send the request to any "remote" web server through the computer space; (b) is designed to be a web server of a manufacturer Applications that implement certain characteristics are usually incompatible with those made by another manufacturer, because the browser interface mechanisms are different and are proprietary to each of them; and (c) each browser comes in a non-system order Send their request to the web server. In other words, for a given web server, the previous request has nothing to do with a subsequent request. In the processing of requests, the website has no control over the sequence of requests.
In an attempt to overcome these problems, US Patent No. 5,951,643 pointed out a mechanism for trusted organization and management of information for web synchronization and tracking in multiple consumer browsers.
However, the solution is limited to tracking the activities of certain users who agree to be "eavesdropped" and are willing to cooperate and connect to a host with a designated application.
Therefore, the main purpose of the present invention is to provide a monitoring and monitoring method and system that enables a network communication manufacturer to eavesdrop on any user connected to the network.
Another object of the present invention is to provide an eavesdropping method that enables a network communication manufacturer to monitor the activities of all users in real time during network communication.
Another object of the present invention is to enable website owners to monitor and eavesdrop on users who contact their website.
Summary of the invention
According to the present invention, there is provided a method for simulating the browser ("initial browser") activity of a given terminal by a network probe terminal ("terminal agent") to track network communication lines, the method includes the steps of: access Network communication line, trace the TCP/IP data packet routed through the communication line, select TCP/IP data packet involving a given IP address; ("identified data packet"), select from the identified data packet for Newly connected current request ("initial request"), select the current web page component indicating the new address from the identified data group ("new navigation component"), and divide the new navigation component into two categories, embedded objects or frames (" Wrong new component"), hyperlink ("correct new component"), divide the initial request into the initial request that matches the correct new component, does not match any new connected component and belongs to HTTP or as the "main request" The initial request of POST type and the initial request matching the error component as the "secondary request" select the HTML data file related to the primary request from the identified data group; ("the respective primary response"), according to the respective secondary In response, a "virtual secondary request is generated, a response related to the secondary virtual request is selected from the identified data packet ("respective secondary response), and the web page presentation on the terminal agent is simulated according to the respective secondary response.
Description of the drawings
These and other features and advantages of the present invention can be understood more clearly by describing several preferred embodiments with reference to the accompanying drawings. Among them: Figure 1 illustrates a typical network configuration in which the present invention can be implemented; Figure 2 illustrates the terminal proxy Operation scheme; Figure 3 illustrates the process of tracking and identifying TCP/IP data packets; Figure 4 is a flow chart for classifying TCP/IP requests; Figure 5 is a flow chart for simulating the creation of virtual secondary TCP/IP requests; and Figure 6 Explain the process of simulating initial browser activity.
The preferred embodiment discusses Fig. 1 in detail, assuming that the terminals 01, 02... are connected to the same communication line, where the communication line is used as an intranet ("Intranet") or an extranet such as the Internet. According to the present invention, it is recommended to connect a designated network probe (hereinafter referred to as "terminal agent") to the data communication line. Alternatively, the terminals 01, 02, etc. and the terminal agent may be connected to different data communication lines or located in different local networks.
The general scheme of terminal agent operation is shown in Figure 2.
The terminal agent faces all data frames passing through the communication line. These data frames contain information transferred between terminals or external data transfers to external sources such as Internet servers.
It is also assumed that the "owner" of the data communication line of a network such as an ISP or a private organization is interested in real-time monitoring of the actual communication activities of a given terminal while surfing the Internet.
The operation of the terminal agent is first to analyze the data frame to track TCP/IP data packets. As shown in Figure 3, data analysis is processed according to different protocol levels (see Internet Protocol RFC0793), that is, first analyze the local network protocol, filter external data transmission ("gateway level"), and then identify Internet Protocol (IP) data Frame, and finally detect the "host level" TCP ("Transmission Control Protocol") data packet.
Once the IP header of the data packet is analyzed, the IP addresses of the requesting terminal and the message destination are identified. The owner of the communication line can easily associate the IP address with the user terminal. Therefore, it is possible to filter out all other irrelevant data packets, and further restrict the processing of data (hereinafter referred to as "identified data packets") transmission of a selected terminal.
The identified data packet is also processed in accordance with the RFC079 specification that enables complete management and control of the data communication port.
According to known routines for managing TCP data communication ports, as handled by traditional browsers such as Inter Explorer, the terminal operating the browser is the initial source of all data transmission. For example, suppose the terminal sends out for YAHOO! The request of the homepage, the request is distributed to YAHOO through the network! server. In response, the server sends an HTML data file containing the YAHOO homepage component. Therefore, the browser sends a new request for receiving all components of the webpage by opening a new communication "virtual" port, where each port is used to send different components of the same webpage. An "outsider" terminal facing all data requests and their respective responses cannot request a complete YAHOO for example! A distinction is made between the initial "primary" request for the home page and the "secondary" request for receiving its components. In order to emulate the initial browser activity by an "outsider" probe terminal, it is essentially the same identification of the main request.
Figure 4 illustrates the process of distinguishing primary requests from secondary requests. The main requests come from different operations, such as inputting a new URL by the user, selecting a hyperlink, etc. Therefore, in order to detect the same one, the previous information sent to the same IP address must be analyzed. All new navigation components of the webpage received by the terminal (addressing the browser to a new location) are classified according to their type, all embedded objects, frames, etc. are marked as "error" components, and hyperlinks are marked as "correct" Components. All data are stored in the buffer response database for later use.
When a request for a new connection is identified according to TCP analysis, the request is checked according to the respective navigation component (RNC) entering the response buffer. If the RNC is marked as "error", the request is ignored; if the RNC is marked as "correct", the request is classified as primary; otherwise, if there is no RNC involved in the request, the connection type should be identified . If the connection is of the HTML type or "post" type, it is classified as the main request.
In order to observe and monitor the activity of a terminal, all "initial" browser activity must be reconstructed. For this, it is recommended to use a "virtual" browser. The virtual browser has all the functions of a "real" browser to download web pages from the Internet in real time. However, its connection to the Internet is virtual, because no actual data exchange with the Internet server is performed, but only the initial "real" browser activity is simulated.
Figure 5 shows the first function of the virtual browser. The browser is receiving all major requests from the "real" browser. These main requests and respective main responses from the Internet are analyzed and processed according to traditional browser operations. However, the results of secondary virtual requests (used to complete the process of downloading webpage components in traditional browsers) are not directly transmitted via the Internet to the appropriate server as usual, but are stored in a virtual "secondary" request buffer. In the database.
Although virtual browser connections are not "actual", all TCP protocol management for opening and controlling port connections is handled by the terminal agent as if these connections are "actual".
The final process of simulating and presenting the webpage on the virtual browser is further shown in Figure 6. All initial secondary responses through the communication line are analyzed and recorded in the response buffer database. The virtual requests are compared with the respective secondary responses stored in the incoming response buffer database in the order of their arrival. If the respective secondary responses are already in the buffer, these responses are transferred to the virtual browser and processed (according to traditional browser operations) to present visual images of the respective webpage components. As a result, the terminal agent simulates the precise process of downloading Internet web pages in real time, since it has been executed by the initial terminal.
If the respective response does not appear in the incoming response buffer database, the initial local cache activity is inferred. If the initial local cache is not used for the virtual request, its execution is suspended in the cache database until the initial secondary respective response arrives. Otherwise, if the actual local cache is used to refer to the response, the local cache of the virtual browser is checked, and if the respective secondary response is in the local cache, the respective response is transmitted to the virtual browser and It is processed as described above. If the respective responses are not in the virtual cache, any of the following alternatives can be applied. According to an alternative, the "passive" scheme of the terminal agent, no further action is taken to find the "missing" response, and an "error" message will appear on the agent terminal instead of the webpage component that appears on the actual terminal. According to this scheme, the simulation of the actual terminal is not completed, but the eavesdropping activity is not detectable. According to another scheme, the "active" scheme, the terminal agent addresses the web server to request a "missing" response. Although this solution enables the terminal agent to present a more accurate picture of the actual active activity, it is trackable to more experienced terminal users who can detect eavesdropping activity.
According to another implementation mode of the present invention, it is recommended not only to eavesdrop on related webpage data packets, but also related message data packets, such as e-mail or chat. The network initiates this kind of eavesdropping, and the same methods and principles as described above are applied to requests for receiving and sending messages instead of requests for web pages. The process of analyzing such requests and their respective responses is more pipelined, because there is no need to check cache memory activity, because by definition, this information is always new.
Finally, it should be understood that the above-mentioned embodiments are aimed at the Internet communication environment. However, the present invention can also be generally applied to computerized network communications in a broad sense, such as satellites, cellular, etc.
Although the above description contains many characteristics, they are not intended to limit the scope of the present invention, but rather serve as examples of preferred embodiments. Those skilled in the art can imagine other possible variations are also within the scope of the present invention. Therefore, the scope of the present invention should be determined not only by the illustrated embodiments, but also by the appended claims and their legal equivalents.
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN100359858C | Cited by | China | Search report |
| CN101132396A | Cited by | China | Search report |
17 members in 9 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 136324 | Israel | – | |
| 13632400 | Israel | A | |
| 13632400 | Israel | A | |
| 136324 | – | – | – |
| IL20000136324 | – | – | – |
Members17
| Document | Office | Kind | |
|---|---|---|---|
| WO0191412A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU6261701A | Australia | A | |
| WO0191412A3 | World Intellectual Property Organization (WIPO) | A3 | |
| KR20020035840A | Republic of Korea | A | |
| US2002116512A1 | United States of America | A1 | |
| CN1386355AThis record | China | A | |
| EP1284077A2 | European Patent Office (EPO) | A2 | |
| JP2003534721A | Japan | A | |
| CN1185843C | China | C | |
| US7216162B2 | United States of America | B2 | |
| EP1284077B1 | European Patent Office (EPO) | B1 | |
| AT413759T | Austria | T | |
| ATE413759T1 | Austria | T1 | |
| DE60136454D1 | Germany | D1 | |
| EP2028818A2 | European Patent Office (EPO) | A2 | |
| EP2028818A3 | European Patent Office (EPO) | A3 | |
| JP4708662B2 | Japan | B2 |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cessation of patent rightC17 | C17 | |
| Succession or assignment of patent rightASS | ASS | |
| Transfer of patent application or patent right or utility modelC41 | C41 | |
| Grant of patent or utility modelGrantedC14 | C14 | |
| Succession or assignment of patent rightASS | ASS | |
| Transfer of patent application or patent right or utility modelC41 | C41 | |
| Change of bibliographic dataCORRECT APPLICANT ADDRESSCOR | COR | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 1386355
- Publication, DOCDB
- 1386355
- Publication, EPODOC
- CN1386355
- Application
- 1802155
- Application, DOCDB
- 01802155
- Application, EPODOC
- CN2001802155
Titles2
- Chinese
- 监视互联网通信的方法
- English
- Methods of monitoring Internet communications
Classification
- CPC, 5
- H04L43/00
- H04L67/75
- H04L43/12
- H04L67/02
- H04L67/535
- IPC, 5
- H04L12 24
- H04L12 26
- H04L12 28
- H04L29 06
- H04L29 08