Network Tap Buffering for Semantic Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network tapping technologies cannot provide a complete and accurate copy of traffic between network agents, leading to uncertainties in encapsulation, session multiplexing, order, and content of network conversations, making it difficult to detect performance issues and security gaps in database applications.

Innovation Solution

A method and system that utilize buffering from a network tap in conjunction with capture-and-analysis techniques to generate a detailed semantic description of operations between network agents, allowing for the detection and mitigation of performance issues and security gaps by reassembling packet-level traffic into byte streams and applying application-layer analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network tapping technologies are used to extract traffic copies, then network monitoring capability is improved, but the completeness and accuracy of traffic data deteriorates due to packet loss, damage, and third-party view limitations

Engineering Contradiction:
Improvetraffic data accuracyVSAvoidpacket stream completeness
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system performs preliminary reassembly of packet streams into complete byte streams before analysis, buffering packets and reconstructing the original data flow to ensure completeness and accuracy of the monitored traffic

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary processing layer that acts as a mediator between the captured packets and the analysis engine, reassembling packets into complete byte streams and resolving uncertainties before presenting data for analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If packet-level capture is performed to achieve detailed traffic analysis, then measurement capability is improved, but the complexity of processing and reassembling packets increases

Engineering Contradiction:
Improvetraffic analysis detailVSAvoidpacket processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the complex packet processing task into distinct stages: packet capture, buffering, reassembly into byte streams, and analysis, with each stage handling a specific aspect of the processing pipeline

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary processing layer that acts as a mediator between the captured packets and the analysis engine, reassembling packets into complete byte streams and resolving uncertainties before presenting data for analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If complete semantic description of network operations is generated, then security detection capability is improved, but the processing time and computational resources increase

Engineering Contradiction:
Improvesecurity analysis accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary reassembly of packet streams into complete byte streams before analysis, buffering packets and reconstructing the original data flow to ensure completeness and accuracy of the monitored traffic

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary processing layer that acts as a mediator between the captured packets and the analysis engine, reassembling packets into complete byte streams and resolving uncertainties before presenting data for analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2810412B1Systems and methods for extracting structured application data from a communications link
Publication Date: 2019.03.13 DB CYBERTECH INC
  • EP2810412B1 patent drawingFigure 1
  • EP2810412B1 patent drawingFigure 2
  • EP2810412B1 patent drawingFigure 3

AI summary

Systems and methods for generating a semantic description of operations between network agents. In an embodiment, packet-level traffic between two or more network agents is captured. The packet-level traffic is bundled into one or more messages, wherein each message comprises one or more elements. For each of the messages, the elements of the message are matched to one or more attributes, and the message is decoded into message data based on the matched attributes. The message data is then used to generate a semantic description of operations between the network agents.