Network Session Record Summarization for Efficient Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network monitoring systems face challenges in storing and processing large volumes of data packets due to limited storage capacity and computational resources, leading to incomplete or inaccurate analysis and delayed issue detection.

Innovation Solution

The system generates adaptive session records by summarizing network data packets, using a common header and payload metadata, which are updated in real-time, allowing for efficient storage and processing, enabling faster analysis and longer retention of data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Duration of action of stationary object

If network monitoring systems store data packets in storage devices, then data packets can be retained for analysis, but storage capacity is limited and data packets can only be stored for a limited time frame

Engineering Contradiction:
Improvedata retention timeVSAvoidstorage capacity
Core Design Contradiction:
Duration of action of stationary objectVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential and relevant information from data packets to create summaries, rather than storing complete packet data. This extraction approach allows the system to retain summary information for extended periods without requiring proportional increases in storage capacity, directly resolving the contradiction between retention time and storage capacity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments data packet information into hierarchical levels: complete packet data, summary information, and metadata. This segmentation allows the system to store different types of information with different retention requirements, enabling longer overall data retention within limited storage constraints by maintaining detailed data for short periods and summary data for longer periods

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If network monitoring systems retrieve and analyze large numbers of data packets, then comprehensive analysis can be performed, but extensive processing time is required resulting in belated responses

Engineering Contradiction:
Improveanalysis completenessVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by generating summary information and metadata from data packets in real-time as they are captured, before comprehensive analysis is required. This preliminary processing creates condensed representations that can be quickly retrieved and analyzed, maintaining analysis completeness while dramatically reducing the time required for subsequent operations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates simplified copies (summaries and metadata) of the original data packet information. These copies contain the essential characteristics needed for analysis but require minimal processing time to retrieve and examine, allowing comprehensive analysis to be performed on the copies while the system can quickly respond to events

Inventive Principle:
Principle #26Copying

3Loss of information

If network monitoring systems store complete data packets, then all information is available for analysis, but storage resources must be increased to extend retention time

Engineering Contradiction:
Improveinformation completenessVSAvoidstorage resources
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent extracts essential information from complete data packets to create summary records and metadata that preserve the critical analytical value while occupying minimal storage space. This extraction maintains sufficient information completeness for most analysis purposes without requiring proportional storage resources

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different quality levels of information storage to different data elements: complete packet data is retained for a short period, while summary information and metadata are retained for longer periods. This local quality differentiation ensures that the most critical information remains available for extended analysis while optimizing overall storage resource utilization

Inventive Principle:
Principle #3Local quality

Data Source

PatentUSRE49126E1Real-time adaptive processing of network data packets for analysis
Publication Date: 2022.07.05 NETSCOUT SYSTEMS INC
  • USRE49126E1 patent drawing
  • USRE49126E1 patent drawing
  • USRE49126E1 patent drawing

AI summary

A network monitoring system that summarizes a plurality of data packets of a session into a compact session record for storage and processing. Each session record may be produced in real-time and made available during the session and/or after the termination of the session. Depending on protocols, a network monitoring system extracts different sets of information, removes redundant information from the plurality of data packets, and adds performance information to produce the session record. The network monitoring system may retrieve and process a single session record or multiple session records for the same or different protocols to determine cause of events, resolve issues in a network or evaluate network performance or conditions. The session record enables analysis in the units of session instead of individual packets. Hence, the network monitoring system can analyze events, issues or performance of the network more efficiently and effectively.