IP Network Troubleshooting via Multi-Layer Trace Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IP network troubleshooting devices only decode messages at a single protocol layer and do not provide comprehensive trace files based on specific data or event criteria, failing to correlate traces across multiple protocol layers and network interfaces, which limits their ability to identify specific network issues.
Innovation Solution
A system and method that monitors packet streams on IP links, captures all relevant packets at a control node, and stores them in log files for post-processing, allowing for analysis of messages before and after troubleshooting criteria are detected, and correlating traces across multiple protocol layers and interfaces to identify specific problems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If existing IP network troubleshooting devices decode messages at a single protocol layer, then the device complexity is reduced, but the measurement precision and ability to correlate traces across multiple protocol layers deteriorates
Solution Approach 1:
The system segments the troubleshooting functionality into separate protocol layer processors (e.g., IP layer processor, Transport layer processor, Application layer processor) that operate independently but cooperate through a unified trace correlation mechanism. Each layer processes messages at its specific level while the system integrates these segmented traces through correlation identifiers to achieve multi-layer analysis without requiring a single monolithic complex device.
Solution Approach 2:
The troubleshooting device implements multi-functionality by enabling a single device to perform analysis across multiple protocol layers simultaneously. The system uses a universal trace correlation framework that can correlate traces from IP layer through Application layer, making the device capable of handling diverse troubleshooting scenarios at any protocol level without requiring separate specialized devices for each layer.
2Quantity of substance
If existing devices only collect trace data at the current protocol layer, then the data processing load is reduced, but the loss of information increases as messages before and after troubleshooting criteria are not captured
Solution Approach 1:
The system performs preliminary actions by capturing and storing trace data from multiple protocol layers in advance, maintaining a history buffer that includes messages before, during, and after troubleshooting criteria are detected. This preliminary collection ensures that when troubleshooting is needed, complete contextual information is already available, preventing information loss while managing data processing load through selective filtering and correlation.
Solution Approach 2:
The system implements feedback mechanisms where trace data collected at lower protocol layers is fed back to higher layer processors for correlation analysis. The troubleshooting criteria detection at one layer triggers feedback loops that retrieve related traces from previous layers, ensuring comprehensive information capture while controlling processing load through targeted feedback rather than processing all data uniformly.
3Ease of operation
If existing devices do not provide trace files based on specific data or event criteria, then the ease of operation is improved, but the productivity of troubleshooting decreases due to inability to filter and process traces efficiently
Solution Approach 1:
The system implements dynamic trace filtering capabilities where troubleshooting criteria can be dynamically adjusted based on specific data elements or events. The trace collection mechanism adapts its filtering behavior in real-time, allowing operators to specify dynamic criteria (e.g., specific IP addresses, protocol types, timing conditions) while maintaining ease of operation through automated correlation and processing of filtered traces across all protocol layers.
Data Source
AI summary
The present invention provides a system, method and apparatus for troubleshooting one or more communications between a first device and a second device. A monitoring device disposed between the first device and the second device receives a message associated with the communication(s), analyzes the received message and stores the analyzed message whenever the analyzed message satisfies one or more troubleshooting criteria. The one or more troubleshooting criteria may include one or more data element criteria, one or more event-based criteria, one or more time-based criteria, one or more logical operators or a combination thereof. The method can be implemented using a computer program embodied on a computer readable medium having one or more code segments to perform the method steps.


