Legacy Network Monitoring via Packet Analysis and Session Mirroring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy environments lack effective monitoring and auditing capabilities to track network activity and generate meaningful insights from intercepted packets, especially in complex network protocols like SNA and TCP/IP, which limits operational efficiency and security.

Innovation Solution

An apparatus and method for monitoring and auditing legacy environments that analyze intercepted packets to generate data representative of sessions, audit events, and business events, utilizing an analyzer, mirror manager, and audit event analyzer to process and store relevant data for long-term analysis and reporting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If legacy environments use traditional monitoring methods, then device complexity is reduced, but measurement precision and information completeness deteriorate

Engineering Contradiction:
Improvepacket analysis precisionVSAvoidmonitoring apparatus complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The monitoring apparatus is divided into distinct functional modules: a packet capture component that intercepts network traffic, an analysis component that processes captured packets using protocol knowledge bases, and a reporting component that generates audit information. This segmentation allows each module to specialize in specific tasks, improving measurement precision while managing complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A protocol knowledge base acts as an intermediary between raw packet data and meaningful audit information. This knowledge base stores protocol-specific rules and patterns, enabling the analysis component to accurately interpret complex legacy protocols without requiring the monitoring apparatus itself to be overly complex. The intermediary translates low-level packet data into high-level business event insights.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If comprehensive packet analysis is performed on legacy protocols, then information completeness improves, but processing time increases

Engineering Contradiction:
Improveaudit information completenessVSAvoidprocessing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

Protocol knowledge bases are pre-populated with protocol-specific analysis rules, patterns, and validation criteria before monitoring begins. This preliminary preparation allows the analysis component to quickly match captured packets against known protocols without performing complex analysis in real-time, thereby maintaining information completeness while reducing processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts analysis parameters based on the detected protocol type. When a packet is identified as belonging to a specific legacy protocol, the system activates only the relevant analysis rules and parameters for that protocol, rather than applying comprehensive analysis to all packets uniformly. This selective parameter application reduces processing time while maintaining complete audit coverage.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If detailed audit trails are generated for all sessions, then reliability improves, but data volume and storage requirements increase

Engineering Contradiction:
Improveaudit trail reliabilityVSAvoidaudit data volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system applies different levels of audit detail to different types of sessions and events based on their importance and risk profile. Critical business transactions receive comprehensive audit trails with full packet-level detail, while routine sessions receive summarized audit information. This local differentiation maintains reliability for important events while reducing overall data volume through selective detail application.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system discards redundant or duplicate audit data that provides no additional value, such as identical sequential packets within a session. However, it recovers and retains essential session context and business logic information that enables meaningful audit analysis. This selective discarding and recovering reduces data volume while preserving the reliability needed for effective auditing.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS9529678B2Apparatus and method for monitoring and auditing activity of a legacy environment
Publication Date: 2016.12.27 BOTTOMLINE TECH LTD
  • US9529678B2 patent drawing
  • US9529678B2 patent drawing
  • US9529678B2 patent drawing

AI summary

An apparatus and a method for monitoring and auditing activity of a legacy environment. The apparatus includes an analyzer and a mirror manager. The analyzer is operative to analyze intercepted packets conveyed by entities in a network and to generate analyzed data based on information associated with at least some of the packets. The analyzed data is indicative of sessions. The mirror manager is responsive to the analyzed data for generating data representative of mirror sessions, each mirror session corresponding to a session.