Network Appliance Adaptive Traffic Collection for Abnormal Events
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network traffic monitoring systems face challenges in efficiently managing data collection, leading to resource wastage and inefficiency, particularly at high speeds like 1 Gb/s and 10 Gb/s, as they collect and process large amounts of data without differentiation based on network events, thus needing a system that varies data monitoring types and conserves resources.
Innovation Solution
A network traffic management system that adjusts data collection based on detected abnormal conditions, increasing data collection when needed and storing it in memory, using a central management system to regulate traffic between computing devices and appliances.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If network traffic data is collected continuously at high speed (1 Gb/s and 10 Gb/s), then network visibility and data richness are improved, but network resources are wasted and processing burden increases
Solution Approach 1:
The patent implements dynamic data collection by adjusting the collection rate based on network conditions. During normal operation, data is collected at a baseline rate, but when abnormal conditions are detected (such as errors, congestion, or security events), the collection rate is automatically increased to capture detailed information only when needed, thus maintaining network visibility while conserving resources.
Solution Approach 2:
The system changes the parameter of data collection intensity based on detected network conditions. By monitoring traffic patterns and detecting anomalies, the system dynamically adjusts the amount and detail of data collected, transitioning from standard collection to enhanced collection mode, which optimizes the balance between information quality and resource consumption.
2Measurement precision
If detailed network traffic data is collected and stored, then problem diagnosis capability is improved, but data processing time and storage requirements increase
Solution Approach 1:
The system performs preliminary filtering and analysis of network traffic to identify abnormal conditions before detailed data collection is activated. By detecting patterns such as errors, congestion, or security events in real-time, the system prepares to collect detailed data only when necessary, avoiding the continuous processing burden while maintaining diagnostic capability.
Solution Approach 2:
The patent applies partial data collection by gathering detailed information only during abnormal network conditions rather than continuously. This selective approach collects excessive data only when needed for diagnosis, reducing overall processing time and storage requirements while maintaining the ability to thoroughly investigate problems when they occur.
3Loss of information
If NetFlow records are generated for all traffic, then traffic visibility is improved, but extra traffic volume (10-15%) and processing load increase
Solution Approach 1:
The system implements periodic data collection at standard intervals during normal operation, then switches to enhanced periodic collection when abnormal conditions are detected. This rhythmic adjustment of collection intensity maintains traffic visibility through regular monitoring while improving processing efficiency by reducing the frequency of detailed data generation during stable network conditions.
Data Source
AI summary
A method and system for increasing the collection of network traffic data in a network based on the occurrence of predetermined criteria. A network appliance manages network traffic in the network and passes data traffic on the network. Network traffic data is collected based on the data traffic passing through the network appliance at a normal level. It is determined whether the network traffic data indicates an abnormal condition. The collection of network traffic data is increased through the network traffic appliance when an abnormal condition is detected. The network traffic data from the increased collection is stored in a memory device.


