Event-Based Packet Mirroring for Network Congestion Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network traffic monitoring techniques, such as port mirroring and sFlow, are inadequate for analyzing phenomena like packet dropping, buffering, and congestion as they sample packets based on port identity and header information, failing to provide meaningful insights into event-specific occurrences within network devices.
Innovation Solution
A system and method for event-based mirroring of data packets, where packets are marked and sent to an analysis engine based on specific events such as queue overflow, packet dropping, or congestion within the network device, allowing for analysis independent of explicit packet parameters, enabling monitoring of transitory events and conditions within the device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional port mirroring or sFlow sampling is used, then packets can be monitored and analyzed, but the sampling is based on port identity and header information which fails to provide meaningful insights into event-specific occurrences like congestion, dropping, and buffering
Solution Approach 1:
The patent changes the sampling parameters from static port identity and header information to dynamic event-based criteria. The network device monitors internal events (congestion, dropping, buffering) and samples packets based on these events rather than fixed port or header parameters, enabling precise event-specific analysis.
Solution Approach 2:
The patent introduces dynamic event monitoring within the network device that adapts packet sampling based on real-time network conditions. Instead of static sampling rules, the system dynamically identifies packets associated with specific events (congestion, dropping, buffering) and samples them accordingly, making the monitoring system responsive to actual network states.
2Ease of operation
If packets are sampled based on port identity and header information, then the existing mirroring techniques can operate, but they cannot provide meaningful information on switch phenomena like dropping, buffering, and congestion
Solution Approach 1:
The patent introduces an intermediary event monitoring mechanism within the network device that sits between packet forwarding and packet sampling. This intermediary monitors internal events (congestion, dropping, buffering) and uses them to trigger packet sampling, thereby preserving event information that would otherwise be lost in conventional port-based or header-based sampling.
3Productivity
If conventional sampling methods are used, then packet monitoring can be performed, but the sampled packets cannot provide meaningful information on the phenomena in the switch
Solution Approach 1:
The patent performs preliminary event monitoring and packet marking within the network device before packets are sampled for analysis. By pre-identifying and marking packets associated with specific events (congestion, dropping, buffering), the system ensures that subsequent sampling captures relevant packets for phenomena analysis without compromising processing efficiency.
Data Source
AI summary
Embodiments of the present invention include systems and methods for minoring data packets upon triggering of events in a network device. In the network device, a usage event is specified, where occurrence of the usage event is indeterminable, at least partially, from the information contained in the data packets. When the network device receives a data packet via an input port, it processes the data packet as the data packet flows along a pipeline in the network device. If a specified usage event is triggered while being processed, the data packet is mirrored via an output port of the network device so that the mirrored data packet may be analyzed by an analysis engine.


