Network Device Session Visibility via TCP Header Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack visibility into session information and traffic flow in client-server communications, making networks vulnerable to session-based attacks and compromising security.

Innovation Solution

Implementing a computing system with network devices that detect and analyze sessions using TCP header information, generating statistical data, and performing load balancing to manage and secure client-server communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If session information is monitored and analyzed in network devices, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an administrative module as an intermediary component that separates the session monitoring and analysis functions from the core network device operations. This module acts as a mediator that receives session information from the network device, performs the complex analysis and statistical generation, and sends control instructions back to the network device, thereby improving security without significantly increasing the complexity of the network device itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is divided into distinct functional modules: the network device that handles packet forwarding and basic session tracking, and the administrative module that performs advanced session analysis, statistics generation, and security policy management. This segmentation allows each component to focus on specific tasks, improving overall security while distributing complexity across multiple specialized components.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If session detection and analysis is implemented, then visibility into traffic flow is improved, but processing time increases

Engineering Contradiction:
Improvevisibility into session informationVSAvoidprocessing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The network device performs preliminary session detection and extracts basic session information from packet headers as packets arrive, before forwarding them to the administrative module. This preliminary action ensures that session information is captured and organized in advance, allowing the administrative module to perform more efficient analysis without significant delays in packet processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts only the essential session information from packet headers (such as source/destination addresses, ports, and protocol types) rather than analyzing the complete packet content. This extraction approach provides sufficient visibility into session information while minimizing the processing time required for analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

3Loss of information

If statistical information is generated for all sessions, then network performance monitoring is improved, but energy consumption increases

Engineering Contradiction:
Improvenetwork performance visibilityVSAvoidenergy consumption
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The administrative module generates statistical information selectively for specific sessions or session groups based on predefined criteria, rather than processing all sessions uniformly. This partial action approach focuses computational resources on sessions that are most relevant for performance monitoring and security analysis, improving network performance visibility while reducing overall energy consumption.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system allows dynamic adjustment of statistical generation parameters, such as the level of detail, update frequency, and session selection criteria. By changing these parameters based on current network conditions and requirements, the system can optimize the balance between performance monitoring quality and energy consumption, generating detailed statistics only when necessary.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11848766B2Session detection and inference
Publication Date: 2023.12.19 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11848766B2 patent drawing
  • US11848766B2 patent drawing
  • US11848766B2 patent drawing

AI summary

Sessions are core components of communication between communicating systems, which may include, for example, a client device and a server. A network device can be used to monitor and analyze session information that is transmitted in a client-server communication. Visibility into the session information and the traffic flow of a network device is critical to improve the performance and security of the network device and the transmission of information in the client-server communication. A lack of visibility into the session information can reduce security, leading to viruses, malware, and malfunctions.