Network Tap System for Packet Capture and Document Reconstruction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer network systems lack an effective mechanism to capture, analyze, and searchable store data packets for security, intellectual property, and corporate governance purposes, as existing routers only forward packets without the capability to intercept, reconstruct, and classify them.
Innovation Solution
A capture system that intercepts data packets, reconstructs documents, and stores them in a searchable format using a network interface module, packet capture module, object assembly module, and object store module, enabling classification and filtering based on protocols and content types.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If routers forward data packets without interception, then network data flow is maintained, but the capability to capture, analyze, and store packets for security purposes is lost
Solution Approach 1:
The patent introduces a network tap device as an intermediary component that couples between the network router and network switch. This tap device captures data packets without disrupting the normal network data flow, enabling security monitoring while maintaining network functionality. The intermediary device reconstructs captured packets and stores them in an database for later analysis.
2Reliability
If all data packets are captured and stored for security analysis, then comprehensive security monitoring is achieved, but system resource consumption and storage requirements increase
Solution Approach 1:
The patent extracts only the essential security-relevant information from captured data packets by reconstructing them into meaningful objects (such as email messages, web pages, or file contents). Instead of storing raw packet data, the system reconstructs and stores only the relevant information objects in a database, reducing storage requirements while maintaining security analysis capability.
3Reliability
If network packets are intercepted and reconstructed, then security analysis capability is enhanced, but real-time processing speed may be reduced
Solution Approach 1:
The patent performs preliminary packet capture and reconstruction in the background without blocking the main network data flow. The network tap device continuously captures packets and reconstructs them asynchronously, allowing security analysis to be performed in advance or in parallel, thus minimizing impact on real-time network performance.
Data Source
AI summary
In one embodiment, a method is provided and includes capturing a plurality of packet streams, recreating a plurality of flows from the packet streams, and analyzing the flows to identify one or more incidents. The incidents identify one or more pieces of data. The incidents are filtered and the incidents are rendered on a display for an end user that initiated the filtering operation. In other embodiments, the display allows the end user to view a selected one of a group of attributes for the incidents. The display allows the end user to open a captured object associated with a specific incident. In still other embodiments, the display allows a user to filter the incidents using a selected one of a group of group options such as content, destination IP, destination location, destination port, filename, host IP, etc.


