Distributed Traffic Statistics for Short-Term Variation Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network traffic analysis techniques face challenges in detecting short-term traffic variations efficiently due to high resource and cost requirements, with xflow methods lacking detail and PI devices being too expensive for widespread deployment.

Innovation Solution

A system comprising multiple data collection devices at network points for real-time traffic analysis and variation detection, coupled with a data accumulation device for constructing a database using aggregated information, allowing efficient monitoring with reduced resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If xflow sampling technique is used to aggregate traffic information, then arithmetic resources and costs are reduced, but short-term traffic variation analysis capability deteriorates

Engineering Contradiction:
Improvearithmetic resourcesVSAvoidshort-term traffic variation detection
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The system segments the network monitoring function into multiple data collection devices distributed at different collection points. Each device independently aggregates traffic information locally, enabling parallel processing and reducing the arithmetic burden on any single device while maintaining the ability to detect short-term variations through local aggregation operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The data collection devices perform preliminary aggregation of traffic information locally before transmitting to the data accumulation device. This preliminary action reduces the volume of data that needs to be processed centrally, enabling efficient short-term variation detection without requiring excessive arithmetic resources at the central accumulation point.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If PI packet inspection technique is used to analyze all packets, then short-term traffic variation analysis capability is improved, but device cost and arithmetic resources increase significantly

Engineering Contradiction:
Improveshort-term traffic variation detectionVSAvoidarithmetic resources
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts only the necessary traffic statistical information from individual packets during the aggregation process at data collection devices. By taking out only essential fields (such as flow identifiers, packet counts, and timing information) rather than inspecting all packet contents, the system achieves short-term variation detection with significantly reduced arithmetic resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Multiple data collection devices merge their locally aggregated traffic information with the data accumulation device. This combining approach allows the system to achieve comprehensive network monitoring and short-term variation detection by aggregating results from multiple distributed sources, avoiding the need for each device to perform expensive individual packet inspection.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If multiple PI devices are deployed to analyze entire network region, then comprehensive traffic analysis capability is improved, but system cost and complexity increase

Engineering Contradiction:
Improvenetwork analysis coverageVSAvoidsystem cost
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The data collection devices are designed with universal functionality to perform multiple tasks: packet analysis, traffic information extraction, local aggregation, and variation detection. This multi-functionality eliminates the need for separate specialized devices, reducing overall system complexity and cost while maintaining comprehensive network analysis coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The data accumulation device serves as an intermediary that receives and processes data from multiple data collection devices. This intermediary approach centralizes the heavy computational tasks of comprehensive analysis while distributing the data collection and preliminary processing functions, reducing the complexity required at each individual device and lowering overall system cost.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250310223A1Traffic statistic information acquisition system and method
Publication Date: 2025.10.02 NIPPON TELEGRAPH & TELEPHONE CORP
  • US20250310223A1 patent drawing
  • US20250310223A1 patent drawing
  • US20250310223A1 patent drawing

AI summary

A traffic statistical information acquisition system includes a plurality of data collection devices that analyze packets flowing on a network to generate traffic statistical information for each fixed aggregation period and to generate traffic variation notification information when detecting the traffic variation, and a data accumulation device that constructs a database based on the traffic statistical information and the traffic variation notification information generated by the plurality of data collection devices.