Container Packet Capture Filtering to Prevent Network Self-Recording

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing packet capture methods in industrial automation networks face issues with inflated and unreliable recording due to feedback in packet transmission, particularly when capturing packets at the industrial device level, leading to self-recording and inefficiencies.

Innovation Solution

A method and device for packet capture services that determine network paths and interfaces, check for potential overlaps, and generate filters to prevent self-recording by approving capture requests only when there are no network interface overlaps, ensuring reliable packet capture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If packets are recorded at the network interface of the industrial device, then network traffic can be captured for analysis, but feedback occurs causing the recording to be massively inflated and unreliable

Engineering Contradiction:
Improvereliability of packet recordingVSAvoidvolume of recorded packets
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the harmful feedback packets from the recording stream by implementing a filtering mechanism that identifies and removes packets originating from the recording system itself. The filter is configured to exclude traffic between the industrial device and the client device, preventing self-recording while maintaining capture of legitimate network traffic.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a filter as an intermediary component between the packet capture mechanism and the recording output. This filter acts as a mediator that selectively blocks feedback packets while allowing legitimate traffic to pass through, resolving the contradiction between comprehensive capture and elimination of self-recording.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If packet capture is implemented at industrial device level, then direct network access to production network can be monitored, but self-recording occurs leading to inflated and unreliable data

Engineering Contradiction:
Improvecompleteness of network traffic captureVSAvoidaccuracy of recorded packets
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the system monitors its own recording activity and automatically filters out self-generated traffic. The filter is configured with criteria that identify feedback packets, and this feedback loop ensures that self-recording is continuously prevented while maintaining complete capture of external network traffic.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary action by pre-configuring the filter with appropriate criteria before packet capture begins. The filter is set up in advance to recognize and block feedback packets, preventing the reliability issue before it occurs rather than attempting to correct it after recording.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple capture sessions are created for multiple containers, then comprehensive network monitoring is achieved, but network interface overlaps cause feedback and recording inflation

Engineering Contradiction:
Improvecapability to monitor multiple containersVSAvoidcomplexity of capture session management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the network monitoring function into individual capture sessions for each container, with each session having its own filter configuration. This segmentation allows independent management of each container's traffic while maintaining overall system coordination through centralized filter management, preventing overlaps between sessions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal filter management mechanism that can be applied across multiple capture sessions. The filter configuration system serves multiple functions: it prevents self-recording in individual sessions, coordinates between sessions to prevent overlaps, and provides a standardized approach for managing complex multi-container monitoring scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12407595B2Method of capturing packets from applications hosted on containers
Publication Date: 2025.09.02 SIEMENS AG
  • US12407595B2 patent drawing
  • US12407595B2 patent drawing
  • US12407595B2 patent drawing

AI summary

A method of capturing packets from one or more applications hosted on containers connected to one or more network interfaces in a section of the industrial network by a packet capture service. The method includes receiving a capture request for capturing packets associated with a connection of a second container from the one or more containers, determining a network path associated with the connection of the second container, determining the presence of the one or more network interfaces in one of first capture session and the connection between the packet capture service and a packet capture client, and approving the capture request based on the between the packet capture service and a packet capture client for creating a second capture session for capturing packets associated with the connection of the second container.