LAN Switch Control Plane Packet Mirroring for Traffic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Ethernet network switches pose challenges in network traffic analysis due to their design, which makes it difficult to support multiple network traffic analysis devices and generate exact copies of packets, leading to inefficiencies and increased costs.
Innovation Solution
The implementation of a packet processing module with a first port logic module that generates and forwards duplicate packets, identified by a control traffic tag, and a control traffic routing module that uses a look-up table to direct these packets to the appropriate port logic module, ensuring exact copies are sent to network traffic analysis devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a LAN switch is used instead of a hub, then network traffic analysis capability is improved, but packet copying complexity increases
Solution Approach 1:
The patent implements packet copying by generating duplicate packets from the original packets received at ingress ports. The packet processing module creates copies of packets that need to be monitored by network traffic analysis devices, allowing the switch to maintain its directed forwarding capability while enabling multiple analysis devices to access packet data without requiring physical hub-like shared media.
2Adaptability or versatility
If multiple network traffic analysis devices are supported, then monitoring versatility is improved, but hardware cost increases
Solution Approach 1:
The patent enables a single LAN switch to serve multiple network traffic analysis devices by implementing a universal packet copying mechanism. The packet processing module can identify which packets need to be copied and forwarded to different analysis devices based on configuration, allowing one switch to support multiple monitoring functions without requiring separate dedicated hardware for each analysis device.
Solution Approach 2:
Instead of providing each network traffic analysis device with dedicated hardware copies of packets through complex physical connections, the patent uses software-based packet copying within the switch's packet processing module. This allows multiple analysis devices to receive packet copies from a single switch port without requiring additional costly hardware infrastructure.
3Adaptability or versatility
If packet copies are generated for multiple analysis devices, then monitoring coverage is improved, but processing burden increases
Solution Approach 1:
The patent applies partial action by selectively copying only those packets that require monitoring by network traffic analysis devices, rather than copying all packets. The packet processing module identifies packets based on their destination ports and monitoring requirements, generating copies only for packets that need to be forwarded to analysis devices, thereby reducing unnecessary processing overhead.
Data Source
AI summary
An Ethernet network device includes a port logic module that is associated with a device port of the Ethernet network device. A packet processing module includes an ingress processing module that receives an incoming packet and that generates a control traffic tag. An ingress command execution module receives the incoming packet and the control traffic tag, generates a duplicate packet that is identical to the incoming packet, and generates a device interface code that identifies the port logic module based on the control traffic tag. A control traffic routing module receives the duplicate packet and the device interface code and forwards the duplicate packet to the port logic module. A network traffic analysis device receives the duplicate packet. The port logic module replaces a first destination header of the duplicate packet with a second destination header that is identical to a destination header of the incoming packet.


