A file system for network full-flow packet capturing data and a retrieval method thereof
By designing a file system for capturing network packets across the entire network traffic, and adopting a structure of raw byte storage, columnar storage, and a verification data area, combined with global arrival sequence numbers and two-stage integrity verification, the problems of maintaining network packet arrival order, accurate flow-level retrieval, and data integrity verification in existing technologies are solved, achieving efficient network packet data storage and retrieval.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING ZHIDING TECHNOLOGY CO LTD
- Filing Date
- 2026-04-24
- Publication Date
- 2026-07-21
AI Technical Summary
Existing technologies, in storing and retrieving network packet capture data across the entire network traffic, cannot simultaneously maintain the order of network packet arrival, achieve precise flow-level retrieval, embed integrity verification into a single retrieval transaction, and eliminate the direct physical offset of the storage layer by the index layer.
Design a file system including a raw byte storage area, a columnar storage area, and a check data area. The network packet location is determined by the Global Arrival Sequence Number (GASN), the timestamp column, and the byte length field. A two-phase integrity verification method is adopted to ensure decoupling between the index layer and the storage layer. Stream-level precise retrieval is achieved through stream identifier information and a set of logical row numbers.
It enables precise stream-level retrieval while maintaining the order of network packet arrival, embeds integrity verification into a single retrieval transaction, and completely decouples the index layer from the storage layer, ensuring data integrity and retrieval efficiency.
Smart Images

Figure CN122437691A_ABST