Ephemeral Event Stream Linking for Cloud Network Capture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network data capture technologies are inflexible and challenging to deploy in cloud computing environments, as they require physical hardware and are often customized for specific purposes, making it difficult to adapt to changing business needs and remote data capture configurations.
Innovation Solution
The system employs remote capture agents installed on physical or virtual machines to capture network data, allowing for protocol-based capture and analysis of network packets, with a GUI for configuring and managing event streams, enabling dynamic configuration and security risk identification without the need for physical hardware connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical hardware network capture devices are deployed, then network data capture capability is achieved, but deployment complexity and infrastructure requirements increase
Solution Approach 1:
The patent replaces physical hardware capture devices with virtual copies implemented as software agents running on existing network infrastructure. These virtual agents replicate the functionality of physical TAPs and SPAN ports without requiring dedicated hardware, thereby reducing deployment complexity while maintaining capture capability.
Solution Approach 2:
The patent substitutes mechanical/physical hardware systems with software-based virtualization. Instead of physically connecting capture devices to network infrastructure via TAPs or SPAN ports, the system uses virtual network interfaces and software agents to capture and process network data, eliminating the need for physical hardware modifications.
2Reliability
If conventional hardware-based network capture devices are used, then network traffic monitoring is achieved, but adaptability to cloud environments and changing business needs is reduced
Solution Approach 1:
The patent implements dynamic, software-based network capture agents that can be deployed, configured, and relocated without physical hardware changes. These agents adapt to cloud environments by running on virtual machines and can be dynamically allocated to monitor different network segments, providing flexibility that fixed physical hardware cannot achieve.
Solution Approach 2:
The virtual network capture agents are designed to perform multiple functions across different environments (on-premises, cloud, hybrid). A single software agent can capture traffic, filter data, generate alerts, and integrate with various security tools, replacing the need for specialized hardware devices for each function.
3Reliability
If physical network capture devices are deployed in cloud environments, then network data capture is achieved, but deployment feasibility and management complexity increase
Solution Approach 1:
The patent uses virtualization to create software-based copies of network capture functionality that can be deployed in cloud environments without physical hardware. These virtual agents run on standard cloud infrastructure, making deployment feasible where physical device installation would be impossible or prohibitively complex.
4Ease of manufacture
If fixed-format network capture configurations are used, then initial deployment is achieved, but flexibility to configure and change data capture on-the-fly is reduced
Solution Approach 1:
The patent implements dynamic configuration capabilities where network capture agents can be reconfigured at runtime without redeployment. Users can modify capture filters, target networks, and alert thresholds through centralized management interfaces, allowing flexible adaptation to changing business needs while maintaining simple initial deployment through standardized agent installation.
Data Source
AI summary
The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements comprising event stream information for one or more ephemeral event streams used to temporarily generate the time-series event data from the network packets. The system then causes for display, in the GUI, a mechanism for navigating between the event stream information and creation information for one or more creators of the one or more ephemeral event streams.


