Network Capture Element Timestamp Correction in Virtualized Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtual machine systems, the use of artificial timing introduces inaccuracies that hinder the placement of traffic capture elements on virtual machines, making it impractical for precise network analysis, as virtual machines are unaware of real-time gaps and require customized solutions for each type of actual machine, increasing overhead and development time.
Innovation Solution
A network capture element is embodied on an actual device hosting a virtual machine manager, using a utility function to store communication event identifiers and retrieve actual times from the actual machine, minimizing interference and overhead by performing filtering and data processing tasks within the virtual machine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a traffic capture element is placed on a virtual machine, then transportability and independence from the actual machine are improved, but timing accuracy deteriorates due to artificial timing gaps introduced by the virtual machine manager
Solution Approach 1:
The patent introduces an intermediary mechanism between the virtual machine and the actual machine's clock system. The virtual machine manager acts as a mediator that captures actual timing information from the physical machine and translates it into virtual machine time, allowing the traffic capture element to obtain accurate timing data without being directly coupled to the physical machine's hardware clock.
Solution Approach 2:
The patent creates a copy of the actual machine's timing information within the virtual machine environment. By duplicating the timing data from the physical machine and making it available to the virtual machine, the system preserves timing accuracy while maintaining the virtualization benefits of transportability and independence.
2Measurement precision
If a traffic capture element is collocated with each node of interest on the actual machine, then timing accuracy is improved, but device complexity and overhead increase
Solution Approach 1:
The patent merges the timing function with the existing virtual machine manager infrastructure. Instead of adding separate timing mechanisms to each virtual machine or node, the timing functionality is integrated into the virtual machine manager, which already exists to manage virtual machine operations. This consolidation avoids increasing overall system complexity while providing accurate timing to all virtual machines.
Solution Approach 2:
The virtual machine manager is given a multi-functional role, serving both its traditional purpose of managing virtual machine operations and the additional function of providing accurate timing information to traffic capture elements. This universal approach eliminates the need for separate dedicated timing devices at each node.
3Adaptability or versatility
If the virtual machine manager buffers timing interrupts to service multiple virtual machines, then adaptability is improved, but timing precision deteriorates due to time gaps between actual and virtual timing
Solution Approach 1:
The patent applies preliminary action by having the virtual machine manager capture and preserve actual timing information at the moment interrupts occur, before the virtual machine is ready to process them. The timing data is stored in advance and made available to the virtual machine when it becomes active, ensuring that the timing precision is maintained despite the buffering delay.
Data Source
AI summary
A network capture element is embodied on a virtual machine, and a utility function is embodied on the actual device, preferably within the virtual machine manager. Both the utility function and the traffic capture element are configured to monitor communication events. To minimize the overhead imposed, the utility function is configured to merely store the time that the event occurred on the actual machine, corresponding to an identifier of the event. The network capture element, on the other hand, performs the time consuming tasks of filtering the communications, selectively storing some or all of the data content of the communications, characterizing the data content, and so on. Instead of storing the virtual time that the communication event occurred at the virtual machine, the network capture element uses the identifier of the communication event to retrieve the actual time that the communication event occurred on the actual machine.


