Adaptive Traffic Monitoring for Failure Packet Capture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing traffic monitoring systems fail to accurately capture packets at the time of failure occurrence due to fixed threshold values that do not account for normal variations in traffic volume, leading to erroneous detection or non-detection of failures.
Innovation Solution
A traffic monitoring device that dynamically updates threshold values for failure detection by using an information processing unit to acquire traffic statistical information and a packet capture unit to capture packets when predetermined references are satisfied, with the threshold values being adjusted based on real-time or periodic traffic patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a fixed threshold value is used for failure detection, then the device complexity is reduced and ease of operation is improved, but measurement precision deteriorates due to inability to detect normal traffic variations
Solution Approach 1:
The patent applies the dynamics principle by transitioning from a fixed threshold value to a dynamically adjustable threshold that adapts to normal traffic variations. The threshold is updated based on learned traffic patterns, allowing the system to maintain ease of operation while improving measurement precision for failure detection.
Solution Approach 2:
The patent implements parameter changes by modifying the threshold value parameter based on observed traffic patterns. The threshold is no longer a static value but changes over time according to learned normal traffic behavior, enabling accurate detection of anomalies while maintaining operational simplicity.
2Device complexity
If a fixed threshold value is used for failure detection, then device complexity is reduced, but reliability deteriorates due to erroneous detection or non-detection of failures
Solution Approach 1:
The system dynamically adjusts the threshold value based on learned traffic patterns, improving reliability by adapting to normal variations. This dynamic approach maintains reasonable device complexity while significantly enhancing the reliability of failure detection.
Solution Approach 2:
The system performs self-service by automatically learning and adapting its own threshold values based on observed traffic patterns. This self-adjustment mechanism improves reliability without requiring complex external configuration or manual intervention, maintaining simplicity while enhancing detection accuracy.
3Productivity
If packet capture is performed based on fixed threshold comparison, then productivity is improved through rapid failure reporting, but measurement precision deteriorates due to inability to distinguish normal variations from actual failures
Solution Approach 1:
The patent uses dynamic threshold adjustment to maintain high productivity through rapid failure reporting while improving measurement precision. The adaptive threshold enables the system to quickly identify true failures by distinguishing them from normal traffic variations, reducing false positives and unnecessary packet captures.
Solution Approach 2:
By changing the threshold parameter from fixed to adaptive, the system maintains fast failure detection capability while improving precision. The threshold evolves based on learned patterns, enabling rapid and accurate identification of actual failures without sacrificing productivity.
Data Source
AI summary
An embodiment is a traffic monitoring device configured to acquire traffic statistical information of a flow in the monitoring target network, determine whether the acquired traffic statistical information satisfies a predetermined reference for failure detection, capture packets of the flow determined to satisfy the predetermined reference as packets at the time of failure occurrence in the flow, and dynamically update the predetermined reference while the device is still acquiring traffic statistical information of the flow in the monitoring target network.


