Network Traffic Capture Clock Discrepancy Correction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network troubleshooting methods face challenges in synchronizing clocks of multiple capture agents to accurately sequence network traffic data in multi-tiered applications, particularly where each leg of the application flow lacks common packets, leading to difficulties in determining clock disparities and temporal relationships.
Innovation Solution
A system and method that utilize intrinsic constraints of network traffic, such as the temporal relationships between request and response packets, to determine clock offset and scale corrections, ensuring accurate temporal sequencing of packets across multiple capture agents by correlating data from different segments based on network architecture and protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple capture agents are used to monitor different segments of a network, then the ability to trace packet paths across the network is improved, but the clocks of the capture agents cannot be synchronized to the precision needed to reliably sequence packets
Solution Approach 1:
The patent introduces a correlation engine as an intermediary that receives packets from multiple capture agents with unsynchronized clocks, extracts timestamps, and uses a correlation algorithm to determine the correct temporal sequence without requiring the capture agents' clocks to be synchronized. This mediator resolves the contradiction by enabling cross-segment packet tracing while accommodating clock discrepancies through computational correction rather than requiring precise hardware synchronization.
2Reliability
If conventional troubleshooting systems require user input for clock difference parameters, then the system can attempt to correct timing discrepancies, but the user does not have a reliable way of determining the parameters and it does not address differences in clock speeds
Solution Approach 1:
The patent implements self-service by having the correlation engine automatically determine clock offset and scale parameters without user input. The system extracts timestamps from packets, identifies temporal relationships between packets captured at different segments, and computes correction factors autonomously. This eliminates the need for users to manually determine clock parameters while achieving reliable timing correction by leveraging the intrinsic temporal constraints of network traffic itself.
3Measurement precision
If automated methods correct timelines using systems of inequalities for timestamps, then timing accuracy is improved for traffic traversing multiple segments, but the method does not address multi-tier traffic where each leg has no common packets
Solution Approach 1:
The patent extends the timestamp correction approach by introducing a scale parameter (clock speed correction) in addition to the traditional offset parameter. This allows the system to handle multi-tier traffic where packets may not appear on all segments by modeling temporal relationships as linear transformations with both offset and scale components. The correlation algorithm solves for these parameters using observed packet timestamps, enabling accurate timing correction even when packets are missing from intermediate segments, thus achieving both precision and versatility.
Data Source
AI summary
A system and method for correcting clock discrepancy in simultaneous network traffic data captures in a multi-tiered, multi-session environment. The invention uses intrinsic constraints imposed by the nature of the traffic onto the possible temporal sequence of the packets, The invention uses the intrinsic restraints of the network architecture and the protocols used at each segment along with the time stamps in the various segments to determine both an offset and scale correction to the clock readings (timestamps) in the traces in order to obtain a correct temporal sequence of packets when using multiple capture agents/engines/network monitors.


