Network Analytics System Enriching Flow Data for Security Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network telemetry systems are inadequate in providing comprehensive insights into network security, availability, and compliance due to limited knowledge of flow origins, destinations, and behaviors, relying on sampling which can miss malicious activity, and consuming significant resources while raising privacy concerns.

Innovation Solution

A network analytics system that captures and enriches flow data with contextual information using hardware assistance, generating multiple planes of enriched data to provide deeper insights into network elements and their interactions, supporting fault injection analysis and visualizations without over-extending computing resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If conventional network flow data collection is used, then resource consumption is reduced, but network visibility and analytical insights are insufficient

Engineering Contradiction:
Improvenetwork visibilityVSAvoidresource consumption
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The patent segments network data collection into two distinct layers: flow data collected by network devices (switches/routers) and contextual data collected by agents on endpoint devices. This segmentation allows comprehensive network visibility without requiring any single device to consume excessive resources, as the analytics system distributes the data collection burden across multiple components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary analytics system that receives data from multiple sources (network devices and endpoint agents) and synthesizes comprehensive network insights. This intermediary consolidates resources by centralizing the analytical processing, allowing individual network devices to maintain low resource consumption while achieving enhanced overall network visibility through the coordinated data collection architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If sampling methods are used for network monitoring, then resource consumption is reduced, but detection accuracy for malicious activity deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent implements preliminary action by having endpoint agents continuously collect and buffer contextual data locally before transmitting to the analytics system. This preliminary data collection at the source ensures complete information capture without requiring continuous high-resource processing during transmission and analysis phases, thereby maintaining detection accuracy while optimizing resource consumption patterns.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by collecting only the specific contextual data elements needed for security analysis (application identities, user information, device state) rather than monitoring all network traffic in detail. This selective data collection approach maintains high detection accuracy for malicious activities while consuming fewer resources compared to comprehensive packet-level monitoring.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If comprehensive flow data collection is implemented, then network analytics capability is improved, but device complexity increases

Engineering Contradiction:
Improveanalytics capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts complex analytical processing functions from individual network devices and relocates them to a centralized analytics system. Network devices only perform simple flow data collection and forwarding, while the analytics system handles the complex tasks of correlating flow data with contextual information, generating security insights, and providing network visibility. This extraction reduces device complexity at the network edge while maintaining enhanced analytics capability centrally.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a universal analytics system that handles multiple analytical functions (security monitoring, performance analysis, compliance checking) through a single centralized platform. This multi-functional approach improves overall analytics capability without requiring each individual network device to be complex, as the centralized system provides versatile analysis capabilities that serve multiple purposes across the network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11159386B2Enriched flow data for network analytics
Publication Date: 2021.10.26 CISCO TECHNOLOGY INC
  • US11159386B2 patent drawing
  • US11159386B2 patent drawing
  • US11159386B2 patent drawing

AI summary

Systems and methods provide for enriching flow data to analyze network security, availability, and compliance. A network analytics system can capture flow data and metadata from network elements. The network analytics system can enrich the flow data by in-line association of the flow data and metadata. The network analytics system can generate multiple planes with each plane representing a dimension of enriched flow data. The network analytics system can generate nodes for the planes with each node representing a unique value or set of values for the dimensions represented by planes. The network analytics system can generate edges for the nodes of the planes with each edge representing a flow between endpoints corresponding to the nodes. The network analytics system can update the planes in response to an interaction with the planes or in response to a query.