Network Device Flow Tagging for Traffic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional tools for capturing network traffic flow information lack the necessary detail for meaningful analysis, hindering network administrators' ability to understand and manage network traffic effectively.
Innovation Solution
A method and network device that generate a lookup key from packet internal qualifiers, obtain flow values and user-defined metadata, and export detailed flow tracking information, enhancing indexing and retrieval for faster analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If conventional tools are used to capture network traffic flow information, then the capture process is simple, but the detail level of captured information is insufficient for meaningful analysis
Solution Approach 1:
The patent segments flow tracking information into multiple categories including flow identification information, flow measurement information, and user-defined metadata. This segmentation allows comprehensive capture of detailed flow information while organizing data in a structured manner that manages complexity through modular information architecture.
Solution Approach 2:
The patent adds a new dimension to flow information capture by incorporating user-defined metadata key-value pairs alongside traditional flow information. This dimensional expansion enables rich, multi-faceted analysis of network traffic by tagging flows with custom attributes that provide contextual meaning beyond standard protocol fields.
2Productivity
If detailed flow tracking information is captured and exported, then analysis capability is improved, but data processing and retrieval complexity increases
Solution Approach 1:
The patent performs preliminary actions by generating lookup keys from packet internal qualifiers and pre-organizing flow information into structured categories before export. This pre-processing enables rapid retrieval and analysis by establishing an efficient indexing system in advance, reducing the computational burden during actual analysis operations.
Solution Approach 2:
The patent introduces lookup keys as intermediary elements that bridge raw packet data and flow tracking information. These keys serve as mediators that enable efficient indexing and retrieval by translating packet characteristics into searchable identifiers, simplifying the complexity of direct data processing.
3Loss of information
If user-defined metadata is incorporated into flow tracking, then meaningful analysis is enabled, but information processing overhead increases
Solution Approach 1:
The patent implements self-service by allowing users to define their own metadata keys and values based on their specific analysis needs. This enables the system to capture only the contextual information that is actually required for each user's purposes, avoiding the processing overhead of capturing and managing unnecessary metadata while still enabling meaningful analysis.
Data Source
AI summary
A method and system for exported flow tracking information is disclosed. The method includes receiving, by a network device, a network traffic flow comprising a data packet, and transmitting, by the network device, a message comprising a network device identifier (NDID), a template set, and an options template set using a traffic analysis protocol. The message is received by a flow collector, and a template record comprising a flow template identifier (FTID) and at least one flow key is extracted from the template set. An options template record comprising a metadata template identifier (MTID) and at least one metadata key is extracted from the options template set. The method includes generating a new repository entry using the NDID, the FTID, the at least one flow key, the MTID, and the at least one metadata key, and storing, by the flow collector, the new repository entry in the Flow Tracking Repository (FTR).


