Network Device Filter Engine for Overlapping Packet Forwarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network monitoring systems face challenges in accessing network data due to the limitations of traditional methods like network hubs, TAPs, and SPAN ports, which are costly and impractical for widespread monitoring, and existing tool aggregation devices are hindered by single-forwarding-action behavior and complex manual configuration requirements for handling filter overlaps.

Innovation Solution

The development of network devices and tool optimizers with graphical user interfaces that allow users to create and manage filters, automatically generate filter rules, and perform multi-action packet forwarding, enabling parallel matching against multiple criteria and automatic handling of filter overlaps, thus simplifying the management and control of packet forwarding.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional data access methods (hubs, TAPs, SPAN ports) are used, then network data can be accessed for monitoring, but the cost and device complexity increase significantly

Engineering Contradiction:
Improvenetwork data accessVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network switch is enhanced to provide both traditional switching functions and monitoring functions with multiple SPAN ports, allowing a single device to serve multiple purposes and reducing the need for separate monitoring equipment

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates copies of network traffic packets and redirects them to monitoring tools through SPAN ports, allowing monitoring without interfering with the original network traffic flow

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If multiple monitoring tools are connected to limited network sources, then monitoring coverage is improved, but filter configuration complexity increases due to overlapping filters

Engineering Contradiction:
Improvemonitoring coverageVSAvoidfilter configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system automatically detects overlapping filter criteria and resolves conflicts without requiring manual intervention, allowing the monitoring system to self-configure and reducing administrative burden

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-processes filter configurations to identify and resolve overlaps before they cause problems, ensuring that multiple monitoring tools can operate simultaneously without configuration conflicts

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If manual filter configuration is used to handle overlapping filters, then packet forwarding accuracy can be maintained, but the time and operational complexity increase

Engineering Contradiction:
Improvepacket forwarding accuracyVSAvoidconfiguration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system automatically detects and resolves filter overlaps without requiring manual configuration, maintaining packet forwarding accuracy while eliminating the time-consuming manual setup process

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors filter configurations and automatically adjusts them to resolve overlaps, providing real-time feedback and correction to maintain accurate packet forwarding

Inventive Principle:
Principle #23Feedback

4Device complexity

If single-forwarding-action behavior is used in tool aggregation devices, then device simplicity is maintained, but the ability to share network sources among multiple tools is limited

Engineering Contradiction:
Improvedevice simplicityVSAvoidnetwork source sharing capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The network switch is enhanced to provide both traditional switching functions and monitoring functions with multiple SPAN ports, allowing a single device to serve multiple purposes and reducing the need for separate monitoring equipment

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments network traffic into different copies and redirects them to different monitoring tools through multiple SPAN ports, enabling one device to serve multiple monitoring functions simultaneously

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8934495B1Filtering path view graphical user interfaces and related systems and methods
Publication Date: 2015.01.13 KEYSIGHT TECH SINGAPORE (SALES) PTE LTD
  • US8934495B1 patent drawing
  • US8934495B1 patent drawing
  • US8934495B1 patent drawing

AI summary

Systems and methods are disclosed that allow for improved management and control of packet forwarding in network systems. Network devices and tool optimizers and a related systems and methods are disclosed for improved packet forwarding between network sources and destination tools in a network monitoring environment. The network devices and tool optimizers disclosed can include a graphical user interfaces (GUIs) through which a user can create and modify filters and select associated filter criteria for forwarding packets from input ports to output ports. The network devices and tool optimizers can also automatically generate filter rules and apply them to the appropriate filter engines so that packets are forwarded as desired by the user. The GUI can be configured to provide other features as well.