Legacy Network Monitoring via Packet Analysis and Session Mirroring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy environments lack effective monitoring and auditing capabilities to track network activity and generate meaningful insights from intercepted packets, especially in complex network protocols like SNA and TCP/IP, which limits operational efficiency and security.
Innovation Solution
An apparatus and method for monitoring and auditing legacy environments that analyze intercepted packets to generate data representative of sessions, audit events, and business events, utilizing an analyzer, mirror manager, and audit event analyzer to process and store relevant data for long-term analysis and reporting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If legacy environments use traditional monitoring methods, then device complexity is reduced, but measurement precision and information completeness deteriorate
Solution Approach 1:
The monitoring apparatus is divided into distinct functional modules: a packet capture component that intercepts network traffic, an analysis component that processes captured packets using protocol knowledge bases, and a reporting component that generates audit information. This segmentation allows each module to specialize in specific tasks, improving measurement precision while managing complexity through modular design.
Solution Approach 2:
A protocol knowledge base acts as an intermediary between raw packet data and meaningful audit information. This knowledge base stores protocol-specific rules and patterns, enabling the analysis component to accurately interpret complex legacy protocols without requiring the monitoring apparatus itself to be overly complex. The intermediary translates low-level packet data into high-level business event insights.
2Loss of information
If comprehensive packet analysis is performed on legacy protocols, then information completeness improves, but processing time increases
Solution Approach 1:
Protocol knowledge bases are pre-populated with protocol-specific analysis rules, patterns, and validation criteria before monitoring begins. This preliminary preparation allows the analysis component to quickly match captured packets against known protocols without performing complex analysis in real-time, thereby maintaining information completeness while reducing processing time.
Solution Approach 2:
The system dynamically adjusts analysis parameters based on the detected protocol type. When a packet is identified as belonging to a specific legacy protocol, the system activates only the relevant analysis rules and parameters for that protocol, rather than applying comprehensive analysis to all packets uniformly. This selective parameter application reduces processing time while maintaining complete audit coverage.
3Reliability
If detailed audit trails are generated for all sessions, then reliability improves, but data volume and storage requirements increase
Solution Approach 1:
The system applies different levels of audit detail to different types of sessions and events based on their importance and risk profile. Critical business transactions receive comprehensive audit trails with full packet-level detail, while routine sessions receive summarized audit information. This local differentiation maintains reliability for important events while reducing overall data volume through selective detail application.
Solution Approach 2:
The system discards redundant or duplicate audit data that provides no additional value, such as identical sequential packets within a session. However, it recovers and retains essential session context and business logic information that enables meaningful audit analysis. This selective discarding and recovering reduces data volume while preserving the reliability needed for effective auditing.
Data Source
AI summary
An apparatus and a method for monitoring and auditing activity of a legacy environment. The apparatus includes an analyzer and a mirror manager. The analyzer is operative to analyze intercepted packets conveyed by entities in a network and to generate analyzed data based on information associated with at least some of the packets. The analyzed data is indicative of sessions. The mirror manager is responsive to the analyzed data for generating data representative of mirror sessions, each mirror session corresponding to a session.


