Auditing Networking Devices via Resource Discovery Packets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is uncertainty in identifying the path that data traffic takes between points in a network, and existing methods like traceroute are insufficient to detail all networking devices through which data is transmitted, lacking control over traffic paths.
Innovation Solution
A method involving initiating a traceroute to identify networking devices, sending a resource discovery packet with a reserved multicast MAC address, and compiling information about these devices to exclude specific devices from the data path upon request.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If traceroute is used to identify networking devices, then the path information is obtained, but the detail information of all networking devices is insufficient
Solution Approach 1:
The patent segments the path identification process into two distinct phases: first using traceroute to obtain the basic path and identify networking devices, then using resource discovery packets with reserved multicast MAC addresses to gather detailed information about each device. This segmentation allows comprehensive information collection while maintaining clear process structure.
Solution Approach 2:
The patent performs preliminary action by first identifying the path and networking devices using traceroute before sending resource discovery packets. This preliminary identification enables targeted information gathering about specific devices on the path, improving efficiency and accuracy of the overall auditing process.
2Loss of information
If resource discovery packet with reserved multicast MAC address is sent, then detailed networking device information is obtained, but the process complexity increases
Solution Approach 1:
The patent uses a universal resource discovery packet format with reserved multicast MAC addresses that can be sent to any networking device on the path. This multi-functional approach allows the same packet structure to audit different device types (routers, switches, firewalls) uniformly, reducing the need for device-specific auditing procedures and simplifying the overall process.
3Ease of operation
If networking devices are excluded from data path, then traffic control is improved, but the routing flexibility is reduced
Solution Approach 1:
The patent implements feedback by providing compiled networking device information back to the system administrator or routing controller. This feedback enables informed decision-making about which devices to exclude, allowing traffic control while maintaining routing flexibility through conscious selection rather than rigid predetermined rules.
Data Source
AI summary
Auditing networking devices is provided. A first traceroute is initiated from a first computing device to a second computing device. The first traceroute identifies at least one networking device along a data path from the first computing device to the second computing device. The first computing device is caused to send a first resource discovery packet to the second computing device. The first resource discovery packet includes a value matching a reserved multicast MAC address. Information describing one or more networking devices is compiled. The information is based, at least in part, on replies generated by one or more networking devices that received a resource discovery packet. One or more networking devices described by the information from the data path is excluded responsive to receiving a request.


