Event-Based Packet Capture Logic for Network Flow Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network technologies lack efficient methods for capturing and analyzing packets from network flows in response to specific triggering events, limiting the ability to detect and respond to network security breaches and other events of interest in real-time.

Innovation Solution

A network device configured to monitor network flows for predetermined triggering events, capture relevant packets or portions thereof, and export them to an analysis server for further inspection, utilizing event detection logic, capture logic, and export logic to facilitate continuous data capture and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If continuous packet capture from all network flows is performed, then comprehensive network analysis capability is improved, but network device performance and resource consumption deteriorate

Engineering Contradiction:
Improvenetwork analysis capabilityVSAvoidnetwork device performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system pre-configures triggering events and capture parameters before network traffic arrives. When a triggering event is detected, the capture logic is already prepared to immediately capture packets without processing delays, thus achieving comprehensive analysis capability while minimizing impact on device performance

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts only the necessary packets related to triggering events from the overall network traffic flow. By selectively capturing only relevant packets rather than all packets, the system maintains comprehensive analysis capability for important events while significantly reducing the processing burden on network devices

Inventive Principle:
Principle #2Taking out (Extraction)

2Productivity

If packet capture is performed only when triggering events occur, then network resource consumption is reduced, but the ability to detect security breaches and events of interest deteriorates

Engineering Contradiction:
Improvenetwork resource efficiencyVSAvoidevent detection capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system continuously monitors network traffic for triggering events and uses this feedback to dynamically activate packet capture. This feedback mechanism ensures that packets are captured reliably when security breaches or events of interest occur, while maintaining resource efficiency during normal operation

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system pre-defines triggering events that indicate security breaches or events of interest before deployment. This preliminary configuration ensures that when such events occur, the capture logic can immediately and reliably capture relevant packets without missing critical security incidents

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If more packets are captured for analysis, then event detection accuracy is improved, but the time required for data processing and export increases

Engineering Contradiction:
Improveevent detection accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system extracts only the specific packets related to triggering events from the network traffic. By capturing only relevant packets rather than all packets, the system achieves high event detection accuracy for security breaches while minimizing the volume of data that requires processing and export

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The capture logic is pre-configured with capture parameters and event definitions. When triggering events occur, the system can immediately capture and export the predetermined number of packets without delay for configuration or parameter setting, thus achieving both high detection accuracy and fast processing

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8958318B1Event-based capture of packets from a network flow
Publication Date: 2015.02.17 CISCO TECHNOLOGY INC
  • US8958318B1 patent drawing
  • US8958318B1 patent drawing
  • US8958318B1 patent drawing

AI summary

An apparatus and method for event-based data capture from network flows are provided. At a network device, a network flow is received that comprises a plurality of packets each comprising control information and data. The network flow is monitored for the occurrence of at least one predetermined triggering event. In response to detecting the triggering event, at least a portion of one or more of the packets received after the triggering event is captured, and the captured portion is exported to an analysis server. The network device may comprise any device configured to forward flows of packets such as, for example, switches, routers, firewalls, etc.