A file system for network full-flow packet capturing data and a retrieval method thereof

By designing a file system for capturing network packets across the entire network traffic, and adopting a structure of raw byte storage, columnar storage, and a verification data area, combined with global arrival sequence numbers and two-stage integrity verification, the problems of maintaining network packet arrival order, accurate flow-level retrieval, and data integrity verification in existing technologies are solved, achieving efficient network packet data storage and retrieval.

CN122437691APending Publication Date: 2026-07-21BEIJING ZHIDING TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING ZHIDING TECHNOLOGY CO LTD
Filing Date
2026-04-24
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing technologies, in storing and retrieving network packet capture data across the entire network traffic, cannot simultaneously maintain the order of network packet arrival, achieve precise flow-level retrieval, embed integrity verification into a single retrieval transaction, and eliminate the direct physical offset of the storage layer by the index layer.

Method used

Design a file system including a raw byte storage area, a columnar storage area, and a check data area. The network packet location is determined by the Global Arrival Sequence Number (GASN), the timestamp column, and the byte length field. A two-phase integrity verification method is adopted to ensure decoupling between the index layer and the storage layer. Stream-level precise retrieval is achieved through stream identifier information and a set of logical row numbers.

Benefits of technology

It enables precise stream-level retrieval while maintaining the order of network packet arrival, embeds integrity verification into a single retrieval transaction, and completely decouples the index layer from the storage layer, ensuring data integrity and retrieval efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122437691A_ABST
    Figure CN122437691A_ABST
Patent Text Reader

Abstract

The present application relates to a file system for network full-flow packet capturing data and a retrieval method thereof. The file system comprises a segment storage unit, each segment storage unit comprising: a raw byte storage area for appending raw bytes in the actual arrival order of network packets; the raw byte storage area is not physically rearranged after segment encapsulation; metadata corresponding to each network packet is stored in a columnar manner, each row of metadata comprising at least flow identification information, a global arrival sequence number, a timestamp, a raw_offset field, and a byte length field column; a Footer area for storing two layers of verification data of the segment storage unit, the two layers of verification data comprising: column-by-column reference fingerprint data for independent comparison of each metadata column, and interval binding data for joint verification of the metadata column and the raw byte. The arrival order is preserved, the integrity verification is embedded, and the index and storage are decoupled.
Need to check novelty before this filing date? Find Prior Art