Multicast Packet Header Extraction for Network Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network monitoring tools face challenges in efficiently analyzing and storing packet headers, identifying anomalies, and tracking network activities in real-time due to the vast volume of data, leading to inefficiencies and potential missed alerts, especially in detecting subtle attacks and multicast packet transmission issues.
Innovation Solution
A computer-based method and system for collecting, processing, and displaying unique packet headers across an IP network, including passive monitoring of multicast packets, to summarize traffic, identify anomalies, and track network activities, utilizing a security monitoring infrastructure system (SMIS) that captures and stores single instances of packet headers, calculates bandwidth, and provides user-selectable lists and maps for analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all packet headers are stored and analyzed in a database, then complete network monitoring is achieved, but storage space and hardware requirements become excessive
Solution Approach 1:
The patent extracts only the essential packet header fields (source IP, destination IP, source port, destination port, protocol, timestamp) from the complete packet data and stores only these summarized attributes in the database. This extraction approach maintains sufficient monitoring capability while dramatically reducing storage requirements compared to storing complete packets.
Solution Approach 2:
The patent segments the packet data into two parts: the essential header information stored in the database for analysis, and the complete packet data retained temporarily in memory or on disk for detailed inspection when needed. This segmentation allows the system to maintain complete monitoring capability while using storage efficiently.
2Measurement precision
If individual packet headers are stored separately, then detailed analysis is possible, but analysis time and processing complexity increase significantly
Solution Approach 1:
The patent merges multiple individual packet header records into summarized conversation entries that group packets by conversation identifier. This consolidation reduces the number of individual records that need to be processed and analyzed, significantly reducing analysis time while preserving the ability to examine detailed packet information when needed through the stored complete packet data.
3Reliability
If packet data is stored for detailed analysis, then network security monitoring is improved, but hardware expense and resource consumption increase
Solution Approach 1:
The patent extracts only the minimum necessary packet header fields for security analysis (source IP, destination IP, ports, protocol, timestamp) and stores only these summarized attributes in the database. This extraction maintains effective security monitoring capability while minimizing hardware and storage resource requirements.
Solution Approach 2:
The patent performs preliminary processing of packet data at the time of capture, extracting and summarizing essential header information immediately. This preliminary action reduces the complexity of subsequent storage and analysis operations, lowering hardware requirements while maintaining security monitoring effectiveness.
4Speed
If continuous real-time analysis is performed, then immediate threat detection is achieved, but processing load and system complexity increase
Solution Approach 1:
The patent performs preliminary extraction and summarization of packet header information at the time of capture, organizing data into conversation-based records with essential fields pre-processed. This preliminary action simplifies subsequent real-time analysis operations, enabling fast threat detection while reducing processing system complexity.
Solution Approach 2:
The patent segments packet processing into two stages: initial capture and summarization of essential headers into conversation records for rapid analysis, and detailed packet inspection only when threats are detected. This segmentation enables real-time detection speed while reducing overall processing system complexity by avoiding continuous detailed analysis of all packets.
Data Source
AI summary
A computer-based method for depicting the participating devices of a multicast group based on the transmit and the receive activities of the devices in a computer network is described. The method includes extracting, from a database, a single instance of each unique packet header associated with a plurality of multicast packets, the multicast packets having been transmitted across the computer network over a predefined period of time, calculating a number of bytes transferred for each source internet protocol (IP) to destination IP multicast tuple from the extracted packets, determining a location of the source IP address and a bandwidth associated with the source IP address from the extracted packets, determining a location of the devices subscribing to the packets and a bandwidth associated with each of the destination sites, and providing a display of all multicast traffic, wherein the multicast traffic is summarized in a user selectable list.


