Wireless Mesh Traffic Analysis via Parallel Ad Hoc Probes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart Grid networks pose challenges for monitoring due to their distributed wireless nature, use of non-standard protocols, and real-time operations, which are not effectively addressed by traditional enterprise network monitoring solutions, resulting in limited visibility and potential network congestion.

Innovation Solution

A distributable, scalable adaptive real-time system for traffic analysis and visualization that processes multiple streams of wireless mesh traffic, utilizing parallel architecture, packet timestamps, and out-of-band transport to maintain network health, security, and performance indicators without disrupting the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If traditional enterprise network monitoring solutions are used to monitor Smart Grid networks, then monitoring coverage is limited to central points, but visibility into field network traffic is lost

Engineering Contradiction:
Improvevisibility into field network trafficVSAvoidmonitoring system architecture
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The monitoring system is segmented into distributed probe units deployed at multiple points within the field network, each independently capturing traffic locally. This eliminates the single central monitoring point limitation while maintaining system manageability through modular probe designs that can be independently configured and operated.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from centralized monitoring to a multi-dimensional distributed monitoring architecture where probes are positioned throughout the network space. This spatial distribution across multiple dimensions enables comprehensive field network visibility while the virtualized management layer provides centralized coordination without requiring physical centralization.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If millions of endpoints are queried continuously for status information, then real-time monitoring data is obtained, but network congestion and endpoint burden increase

Engineering Contradiction:
Improvereal-time monitoring accuracyVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The probe units operate autonomously, self-configuring and self-managing their monitoring functions without requiring continuous queries from central systems. They automatically capture and analyze traffic locally, eliminating the need for frequent endpoint polling while maintaining real-time monitoring capability through continuous passive traffic observation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Instead of continuous active querying, the system uses periodic passive traffic capture and analysis by distributed probes. This approach obtains real-time monitoring data through continuous observation of actual network traffic flows without injecting additional query traffic, thereby maintaining throughput while ensuring monitoring accuracy.

Inventive Principle:
Principle #19Periodic action

3Loss of information

If packet intercepts are backhauled over the same network, then traffic analysis is enabled, but network congestion is created

Engineering Contradiction:
Improvetraffic analysis capabilityVSAvoidnetwork throughput
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The probe units serve as intermediary devices that perform local traffic analysis and filtering before transmitting only essential metadata and aggregated statistics to central systems. This intermediary function enables comprehensive traffic analysis capability while minimizing backhaul traffic volume, as probes pre-process and summarize data locally rather than forwarding all raw packets.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system extracts only the essential monitoring data and metadata from captured traffic packets, separating this essential information from the bulk data traffic. Probes extract key performance indicators, anomalies, and aggregated statistics for transmission, while the majority of raw traffic data is processed locally or discarded, enabling traffic analysis without creating backhaul congestion.

Inventive Principle:
Principle #2Taking out (Extraction)

4Loss of information

If monitoring systems are deployed in Smart Grid field area networks, then network visibility is improved, but the distributed wireless nature and non-standard protocols increase system complexity

Engineering Contradiction:
Improvenetwork visibilityVSAvoidprotocol handling complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The probe units are designed with universal multi-functional capabilities to handle multiple wireless protocols and network types through integrated protocol stacks. Each probe can operate across different protocol environments (WiFi, mesh, proprietary protocols) without requiring protocol-specific hardware, simplifying deployment across diverse Smart Grid field networks while maintaining comprehensive visibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10230599B2System and method for network traffic profiling and visualization
Publication Date: 2019.03.12 PERSPECTA LABS INC
  • US10230599B2 patent drawing
  • US10230599B2 patent drawing
  • US10230599B2 patent drawing

AI summary

A computer program product, computer system, and method for performing traffic analysis on a wireless mesh network, includes intercepting a stream of real-time wireless from field probes on the wireless mesh network, wherein the stream comprises non-standard protocol elements and encrypted traffic, creating an ad hoc network parallel to the wireless mesh network, obtaining, from the ad hoc network, the intercepted stream (the analyzing is performed parallel to traffic flow on the wireless mesh network), pre-processing a portion of the intercepted stream the data, where the pre-processing comprises descrambling and processing headers in the stream to differentiate the packets in the stream and create a combined output stream, obtaining the combined output stream and creating indicators by selecting an analysis operator to apply to one or more dissected fields extracted from the output stream, analyzing the packets in the combined output stream utilizing the indicators, and obtaining results from the indicators and reporting, the results from the indicators.