Multicast Packet Header Extraction for Network Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network monitoring tools face challenges in efficiently analyzing and storing packet headers, identifying anomalies, and tracking network activities in real-time due to the vast volume of data, leading to inefficiencies and potential missed alerts, especially in detecting subtle attacks and multicast packet transmission issues.

Innovation Solution

A computer-based method and system for collecting, processing, and displaying unique packet headers across an IP network, including passive monitoring of multicast packets, to summarize traffic, identify anomalies, and track network activities, utilizing a security monitoring infrastructure system (SMIS) that captures and stores single instances of packet headers, calculates bandwidth, and provides user-selectable lists and maps for analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all packet headers are stored and analyzed in a database, then complete network monitoring is achieved, but storage space and hardware requirements become excessive

Engineering Contradiction:
Improvenetwork monitoring completenessVSAvoidstorage space
Core Design Contradiction:
ReliabilityVSVolume of stationary object

Solution Approach 1:

The patent extracts only the essential packet header fields (source IP, destination IP, source port, destination port, protocol, timestamp) from the complete packet data and stores only these summarized attributes in the database. This extraction approach maintains sufficient monitoring capability while dramatically reducing storage requirements compared to storing complete packets.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the packet data into two parts: the essential header information stored in the database for analysis, and the complete packet data retained temporarily in memory or on disk for detailed inspection when needed. This segmentation allows the system to maintain complete monitoring capability while using storage efficiently.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If individual packet headers are stored separately, then detailed analysis is possible, but analysis time and processing complexity increase significantly

Engineering Contradiction:
Improvepacket analysis detailVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent merges multiple individual packet header records into summarized conversation entries that group packets by conversation identifier. This consolidation reduces the number of individual records that need to be processed and analyzed, significantly reducing analysis time while preserving the ability to examine detailed packet information when needed through the stored complete packet data.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If packet data is stored for detailed analysis, then network security monitoring is improved, but hardware expense and resource consumption increase

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the minimum necessary packet header fields for security analysis (source IP, destination IP, ports, protocol, timestamp) and stores only these summarized attributes in the database. This extraction maintains effective security monitoring capability while minimizing hardware and storage resource requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary processing of packet data at the time of capture, extracting and summarizing essential header information immediately. This preliminary action reduces the complexity of subsequent storage and analysis operations, lowering hardware requirements while maintaining security monitoring effectiveness.

Inventive Principle:
Principle #10Preliminary action

4Speed

If continuous real-time analysis is performed, then immediate threat detection is achieved, but processing load and system complexity increase

Engineering Contradiction:
Improvereal-time detection speedVSAvoidprocessing system complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent performs preliminary extraction and summarization of packet header information at the time of capture, organizing data into conversation-based records with essential fields pre-processed. This preliminary action simplifies subsequent real-time analysis operations, enabling fast threat detection while reducing processing system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments packet processing into two stages: initial capture and summarization of essential headers into conversation records for rapid analysis, and detailed packet inspection only when threats are detected. This segmentation enables real-time detection speed while reducing overall processing system complexity by avoiding continuous detailed analysis of all packets.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8762515B2Methods and systems for collection, tracking, and display of near real time multicast data
Publication Date: 2014.06.24 THE BOEING CO
  • US8762515B2 patent drawing
  • US8762515B2 patent drawing
  • US8762515B2 patent drawing

AI summary

A computer-based method for depicting the participating devices of a multicast group based on the transmit and the receive activities of the devices in a computer network is described. The method includes extracting, from a database, a single instance of each unique packet header associated with a plurality of multicast packets, the multicast packets having been transmitted across the computer network over a predefined period of time, calculating a number of bytes transferred for each source internet protocol (IP) to destination IP multicast tuple from the extracted packets, determining a location of the source IP address and a bandwidth associated with the source IP address from the extracted packets, determining a location of the devices subscribing to the packets and a bandwidth associated with each of the destination sites, and providing a display of all multicast traffic, wherein the multicast traffic is summarized in a user selectable list.