Dynamic Network Traffic Sniffer for Data Topology Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies face challenges in identifying and managing data stored across their computer networks due to unstructured data scattered across layers of networks, leading to poor visibility and difficulty in protecting sensitive information.

Innovation Solution

A dynamic network traffic sniffer is deployed for limited-time periods across different portions of the network to monitor and map data topology, allowing for the identification of data of interest and efficient deployment of data collectors, reducing resource costs and overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If a static traffic sniffer is connected to the aggregation switch to monitor network traffic, then the sniffer can capture traffic flowing through the switch, but it misses traffic that is forwarded directly by virtual switches within the network without hitting the aggregation switch

Engineering Contradiction:
Improvenetwork traffic visibilityVSAvoidsniffer deployment complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements a dynamic sniffer deployment approach where sniffers are not statically placed but are dynamically deployed to different network locations based on discovered topology. The system uses an orchestrator to manage multiple sniffers that can be moved or repositioned to capture traffic at optimal points, enabling the sniffers to adapt to changing network conditions and traffic patterns rather than being fixed at single aggregation points

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent divides the network monitoring function into multiple distributed sniffers rather than using a single centralized sniffer. Each sniffer is deployed to specific network segments or hosts and reports findings to a central controller, allowing comprehensive coverage of different network portions including traffic that bypasses aggregation switches

Inventive Principle:
Principle #1Segmentation

2Loss of information

If multiple traffic sniffers are deployed with at least one running on each TOR or hypervisor to capture all network traffic, then full network visibility is achieved, but management overhead and resource costs increase significantly

Engineering Contradiction:
Improvenetwork traffic coverageVSAvoidsniffer management overhead
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent creates a universal sniffer management system where a single orchestrator component handles the deployment, configuration, and coordination of multiple sniffers across the entire network. This centralized orchestrator provides multi-functional capabilities including topology discovery, sniffer placement optimization, and data aggregation, eliminating the need for separate management systems at each deployment point and reducing overall complexity despite multiple sniffers being deployed

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The orchestrator acts as an intermediary between the central control system and distributed sniffers. It receives topology information, determines optimal sniffer placements, deploys sniffers to appropriate locations, and collects data from them. This intermediary layer simplifies management by abstracting the complexity of coordinating multiple sniffers behind a single management interface

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If data is scattered across layers of the network with poor structuring, then data storage flexibility is maintained, but visibility and ability to identify and locate data deteriorates

Engineering Contradiction:
Improvedata storage flexibilityVSAvoiddata location visibility
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where sniffers continuously monitor network traffic and report discovered data locations and patterns back to the orchestrator. The orchestrator uses this feedback to build and update a map of data topology, identifying where sensitive data is stored across the network. This feedback loop enables the system to maintain awareness of data locations even as data moves or is scattered across different network layers, providing visibility without requiring rigid data structuring

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11671343B2Dynamic network traffic sniffer
Publication Date: 2023.06.06 HELIOS DATA INC
  • US11671343B2 patent drawing
  • US11671343B2 patent drawing
  • US11671343B2 patent drawing

AI summary

Techniques are disclosed relating to data discovery. A control program that is executing on a computer system may receiving a request to locate instances of data on a computer network having a plurality of computer systems that are managed by an orchestration program. The control program may perform multiple, limited-time-period deployments of a sniffer program to different portions of the computer network in order to sample network traffic from the different portions to determine whether instances of the data appear in the network traffic. The control program may receive, from the sniffer program, information that identifies one or more of the different portions of the computer network whose network traffic included instances of the data.