Container Packet Capture Filtering to Prevent Network Self-Recording
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing packet capture methods in industrial automation networks face issues with inflated and unreliable recording due to feedback in packet transmission, particularly when capturing packets at the industrial device level, leading to self-recording and inefficiencies.
Innovation Solution
A method and device for packet capture services that determine network paths and interfaces, check for potential overlaps, and generate filters to prevent self-recording by approving capture requests only when there are no network interface overlaps, ensuring reliable packet capture.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If packets are recorded at the network interface of the industrial device, then network traffic can be captured for analysis, but feedback occurs causing the recording to be massively inflated and unreliable
Solution Approach 1:
The patent extracts the harmful feedback packets from the recording stream by implementing a filtering mechanism that identifies and removes packets originating from the recording system itself. The filter is configured to exclude traffic between the industrial device and the client device, preventing self-recording while maintaining capture of legitimate network traffic.
Solution Approach 2:
The patent introduces a filter as an intermediary component between the packet capture mechanism and the recording output. This filter acts as a mediator that selectively blocks feedback packets while allowing legitimate traffic to pass through, resolving the contradiction between comprehensive capture and elimination of self-recording.
2Loss of information
If packet capture is implemented at industrial device level, then direct network access to production network can be monitored, but self-recording occurs leading to inflated and unreliable data
Solution Approach 1:
The patent implements a feedback mechanism where the system monitors its own recording activity and automatically filters out self-generated traffic. The filter is configured with criteria that identify feedback packets, and this feedback loop ensures that self-recording is continuously prevented while maintaining complete capture of external network traffic.
Solution Approach 2:
The patent applies preliminary action by pre-configuring the filter with appropriate criteria before packet capture begins. The filter is set up in advance to recognize and block feedback packets, preventing the reliability issue before it occurs rather than attempting to correct it after recording.
3Adaptability or versatility
If multiple capture sessions are created for multiple containers, then comprehensive network monitoring is achieved, but network interface overlaps cause feedback and recording inflation
Solution Approach 1:
The patent segments the network monitoring function into individual capture sessions for each container, with each session having its own filter configuration. This segmentation allows independent management of each container's traffic while maintaining overall system coordination through centralized filter management, preventing overlaps between sessions.
Solution Approach 2:
The patent implements a universal filter management mechanism that can be applied across multiple capture sessions. The filter configuration system serves multiple functions: it prevents self-recording in individual sessions, coordinates between sessions to prevent overlaps, and provides a standardized approach for managing complex multi-container monitoring scenarios.
Data Source
AI summary
A method of capturing packets from one or more applications hosted on containers connected to one or more network interfaces in a section of the industrial network by a packet capture service. The method includes receiving a capture request for capturing packets associated with a connection of a second container from the one or more containers, determining a network path associated with the connection of the second container, determining the presence of the one or more network interfaces in one of first capture session and the connection between the packet capture service and a packet capture client, and approving the capture request based on the between the packet capture service and a packet capture client for creating a second capture session for capturing packets associated with the connection of the second container.


