Network Edge Discovery Protocol Metadata Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security and visibility technologies face challenges due to excessive filtering and bandwidth constraints, particularly in dynamic network topologies, leading to insufficient coverage and inefficient resource utilization.
Innovation Solution
The implementation of discovery protocols such as DHCP, DNS, mDNS, and LLDP to gather low-volume, high-value metadata for analytics, allowing for better network context and behavioral profiling, and the strategic placement of tap points near the network edge for enhanced visibility and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If discovery protocols are used to gather metadata for network analytics, then network visibility and detection precision are improved, but bandwidth consumption and computational resources increase
Solution Approach 1:
The patent extracts only the essential metadata fields from discovery protocol traffic that are most relevant for network analytics, such as source/destination addresses, port information, and service types. By selectively extracting only these critical fields rather than capturing complete packet data, the system achieves high network visibility while minimizing bandwidth consumption and processing overhead.
Solution Approach 2:
The patent segments the network monitoring function into distributed network edge devices that independently perform discovery protocol analysis. Each edge device processes local discovery traffic and generates analytics, eliminating the need to centralize all discovery protocol data. This segmentation reduces bandwidth consumption by keeping processing distributed while maintaining comprehensive network visibility through aggregated insights from multiple edge points.
2Loss of energy
If filtering is applied to reduce bandwidth consumption, then resource efficiency is improved, but network coverage and detection capability deteriorate
Solution Approach 1:
The patent performs preliminary filtering and classification of discovery protocol traffic at the network edge before data leaves the local network segment. By pre-processing discovery packets locally to identify and retain only analytically valuable metadata, the system achieves efficient resource utilization while maintaining comprehensive network coverage through distributed edge processing that prevents any single filtering point from blocking legitimate traffic.
3Measurement precision
If centralized analytics processing is used, then comprehensive analysis is improved, but bandwidth strain and processing time increase
Solution Approach 1:
The patent segments the centralized analytics architecture into distributed network edge analytics functions. Each network edge device independently performs discovery protocol analysis and generates local analytics results. This segmentation eliminates the need to transport all raw discovery data to a central processor, thereby reducing bandwidth strain and processing time while maintaining comprehensive analysis capabilities through distributed intelligent processing at the edge.
4Reliability
If more tap points are deployed for network monitoring, then network coverage is improved, but device complexity and deployment difficulty increase
Solution Approach 1:
The patent designs network edge devices with multi-functional capabilities that can simultaneously perform discovery protocol analysis, general network traffic monitoring, and security functions. By making edge devices universal and multi-functional, the system achieves comprehensive network coverage without requiring specialized dedicated monitoring equipment at each tap point, thereby reducing deployment complexity while maintaining extensive network visibility.
Data Source
AI summary
A system may retrieve a packet in a network edge of a computer network. The system may identify a source address of the packet and a domain name that is being resolved that is associated with the packet and determining a time to live for the domain name, based at least in part on a record associated with the domain name. The server may further determine a relevance value indicative of an importance of a server associated with the domain name based at least in part on a frequency of the domain name in a domain name system list comprising a plurality of servers associated with a plurality of domain names, wherein the frequency is normalized by the time to live for the domain name. The system may sort the domain name system list according to the relevance value.


