Network Traffic Monitoring via Content Data Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network traffic monitoring systems are inefficient as they copy and analyze all network traffic from specific sources and destinations, even if it does not contain content associated with fraudulent or dangerous activities, leading to unnecessary resource consumption.
Innovation Solution
Implementing a network device that uses a flow-tap content filter to identify and monitor specific content data associated with keywords or patterns indicative of fraudulent or dangerous activities, thereby performing flow tapping only on relevant traffic flows and conserving resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all network traffic is copied and analyzed, then comprehensive monitoring coverage is achieved, but resource consumption increases unnecessarily
Solution Approach 1:
The patent extracts and filters only the relevant content data from network traffic using a content filter before copying and analyzing. The content filter is configured with keywords or patterns indicative of fraudulent or dangerous activities, so only traffic containing such content is selected for flow tapping. This extraction principle resolves the contradiction by removing unnecessary traffic from the monitoring process while retaining all relevant content.
Solution Approach 2:
The patent applies different processing quality to different portions of network traffic. Instead of uniform analysis of all traffic, the system applies content-based filtering to identify and selectively process only those portions containing suspicious content. This local quality approach ensures comprehensive monitoring of relevant content while conserving resources on benign traffic.
2Reliability
If flow tapping is performed on all traffic from specific sources and destinations, then complete interception capability is maintained, but processing time increases
Solution Approach 1:
The patent performs preliminary content filtering on network traffic before the flow tapping and analysis stages. The content filter pre-processes traffic to identify and flag only those packets containing content matching suspicious keywords or patterns. This preliminary action resolves the contradiction by preparing the traffic in advance, so that subsequent flow tapping and analysis operations can focus exclusively on relevant content, significantly reducing processing time while maintaining complete interception capability for suspicious activities.
3Productivity
If content-based filtering is implemented, then resource efficiency improves, but system complexity increases
Solution Approach 1:
The patent introduces a content filter as an intermediary component between the network traffic source and the flow tapping mechanism. This content filter acts as a mediator that receives all network traffic, applies content-based filtering using configurable keywords or patterns, and forwards only matching traffic to the flow tapping and analysis stages. The intermediary resolves the contradiction by providing a modular, configurable filtering layer that improves resource efficiency without significantly complicating the overall system architecture.
Data Source
AI summary
A network monitoring device may receive, from a mediation device, flow-tap content data (generated by the mediation device based on current and/or previous investigation reports associated with flow tapping) that needs to be monitored. The network monitoring device may map the content data to a flow-tap content destination address of a content destination device in an entry of a flow-tap content filter. The network monitoring device may analyze, using the flow-tap content filter, network traffic of the network to detect a traffic flow that includes the content data. The network monitoring device may generate, based on successfully detecting a traffic flow that includes the content data, a traffic flow copy and may provide the traffic flow copy to the flow-tap content destination address, wherein the traffic flow copy is to be accessible to the content destination device to enable a context analysis of the content data.


