Network Traffic Capture Clock Discrepancy Correction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network troubleshooting methods face challenges in synchronizing clocks of multiple capture agents to accurately sequence network traffic data in multi-tiered applications, particularly where each leg of the application flow lacks common packets, leading to difficulties in determining clock disparities and temporal relationships.

Innovation Solution

A system and method that utilize intrinsic constraints of network traffic, such as the temporal relationships between request and response packets, to determine clock offset and scale corrections, ensuring accurate temporal sequencing of packets across multiple capture agents by correlating data from different segments based on network architecture and protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple capture agents are used to monitor different segments of a network, then the ability to trace packet paths across the network is improved, but the clocks of the capture agents cannot be synchronized to the precision needed to reliably sequence packets

Engineering Contradiction:
Improveability to trace packet paths across network segmentsVSAvoidclock synchronization precision
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent introduces a correlation engine as an intermediary that receives packets from multiple capture agents with unsynchronized clocks, extracts timestamps, and uses a correlation algorithm to determine the correct temporal sequence without requiring the capture agents' clocks to be synchronized. This mediator resolves the contradiction by enabling cross-segment packet tracing while accommodating clock discrepancies through computational correction rather than requiring precise hardware synchronization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional troubleshooting systems require user input for clock difference parameters, then the system can attempt to correct timing discrepancies, but the user does not have a reliable way of determining the parameters and it does not address differences in clock speeds

Engineering Contradiction:
Improvetiming correction accuracyVSAvoidparameter determination difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by having the correlation engine automatically determine clock offset and scale parameters without user input. The system extracts timestamps from packets, identifies temporal relationships between packets captured at different segments, and computes correction factors autonomously. This eliminates the need for users to manually determine clock parameters while achieving reliable timing correction by leveraging the intrinsic temporal constraints of network traffic itself.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If automated methods correct timelines using systems of inequalities for timestamps, then timing accuracy is improved for traffic traversing multiple segments, but the method does not address multi-tier traffic where each leg has no common packets

Engineering Contradiction:
Improvetimestamp timing accuracyVSAvoidapplicability to multi-tier traffic
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent extends the timestamp correction approach by introducing a scale parameter (clock speed correction) in addition to the traditional offset parameter. This allows the system to handle multi-tier traffic where packets may not appear on all segments by modeling temporal relationships as linear transformations with both offset and scale components. The correlation algorithm solves for these parameters using observed packet timestamps, enabling accurate timing correction even when packets are missing from intermediate segments, thus achieving both precision and versatility.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9602366B1System and method for correcting clock discrepancy in simultaneous network traffic captures
Publication Date: 2017.03.21 NETSCOUT SYSTEMS INC
  • US9602366B1 patent drawing
  • US9602366B1 patent drawing
  • US9602366B1 patent drawing

AI summary

A system and method for correcting clock discrepancy in simultaneous network traffic data captures in a multi-tiered, multi-session environment. The invention uses intrinsic constraints imposed by the nature of the traffic onto the possible temporal sequence of the packets, The invention uses the intrinsic restraints of the network architecture and the protocols used at each segment along with the time stamps in the various segments to determine both an offset and scale correction to the clock readings (timestamps) in the traces in order to obtain a correct temporal sequence of packets when using multiple capture agents/engines/network monitors.