Event-Based Packet Mirroring for Network Congestion Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network traffic monitoring techniques, such as port mirroring and sFlow, are inadequate for analyzing phenomena like packet dropping, buffering, and congestion as they sample packets based on port identity and header information, failing to provide meaningful insights into event-specific occurrences within network devices.

Innovation Solution

A system and method for event-based mirroring of data packets, where packets are marked and sent to an analysis engine based on specific events such as queue overflow, packet dropping, or congestion within the network device, allowing for analysis independent of explicit packet parameters, enabling monitoring of transitory events and conditions within the device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional port mirroring or sFlow sampling is used, then packets can be monitored and analyzed, but the sampling is based on port identity and header information which fails to provide meaningful insights into event-specific occurrences like congestion, dropping, and buffering

Engineering Contradiction:
Improvemonitoring precisionVSAvoidevent-specific analysis capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent changes the sampling parameters from static port identity and header information to dynamic event-based criteria. The network device monitors internal events (congestion, dropping, buffering) and samples packets based on these events rather than fixed port or header parameters, enabling precise event-specific analysis.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces dynamic event monitoring within the network device that adapts packet sampling based on real-time network conditions. Instead of static sampling rules, the system dynamically identifies packets associated with specific events (congestion, dropping, buffering) and samples them accordingly, making the monitoring system responsive to actual network states.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If packets are sampled based on port identity and header information, then the existing mirroring techniques can operate, but they cannot provide meaningful information on switch phenomena like dropping, buffering, and congestion

Engineering Contradiction:
Improvemonitoring operationVSAvoidevent information
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent introduces an intermediary event monitoring mechanism within the network device that sits between packet forwarding and packet sampling. This intermediary monitors internal events (congestion, dropping, buffering) and uses them to trigger packet sampling, thereby preserving event information that would otherwise be lost in conventional port-based or header-based sampling.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If conventional sampling methods are used, then packet monitoring can be performed, but the sampled packets cannot provide meaningful information on the phenomena in the switch

Engineering Contradiction:
Improvepacket processing efficiencyVSAvoidphenomena analysis accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent performs preliminary event monitoring and packet marking within the network device before packets are sampled for analysis. By pre-identifying and marking packets associated with specific events (congestion, dropping, buffering), the system ensures that subsequent sampling captures relevant packets for phenomena analysis without compromising processing efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10389655B2Event-based packet mirroring
Publication Date: 2019.08.20 OLAERIS INC
  • US10389655B2 patent drawing
  • US10389655B2 patent drawing
  • US10389655B2 patent drawing

AI summary

Embodiments of the present invention include systems and methods for minoring data packets upon triggering of events in a network device. In the network device, a usage event is specified, where occurrence of the usage event is indeterminable, at least partially, from the information contained in the data packets. When the network device receives a data packet via an input port, it processes the data packet as the data packet flows along a pipeline in the network device. If a specified usage event is triggered while being processed, the data packet is mirrored via an output port of the network device so that the mirrored data packet may be analyzed by an analysis engine.