Network Tap System for Packet Capture and Document Reconstruction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network systems lack an effective mechanism to capture, analyze, and searchable store data packets for security, intellectual property, and corporate governance purposes, as existing routers only forward packets without the capability to intercept, reconstruct, and classify them.

Innovation Solution

A capture system that intercepts data packets, reconstructs documents, and stores them in a searchable format using a network interface module, packet capture module, object assembly module, and object store module, enabling classification and filtering based on protocols and content types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If routers forward data packets without interception, then network data flow is maintained, but the capability to capture, analyze, and store packets for security purposes is lost

Engineering Contradiction:
Improvenetwork security monitoring capabilityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network tap device as an intermediary component that couples between the network router and network switch. This tap device captures data packets without disrupting the normal network data flow, enabling security monitoring while maintaining network functionality. The intermediary device reconstructs captured packets and stores them in an database for later analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all data packets are captured and stored for security analysis, then comprehensive security monitoring is achieved, but system resource consumption and storage requirements increase

Engineering Contradiction:
Improvesecurity monitoring comprehensivenessVSAvoiddata storage volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential security-relevant information from captured data packets by reconstructing them into meaningful objects (such as email messages, web pages, or file contents). Instead of storing raw packet data, the system reconstructs and stores only the relevant information objects in a database, reducing storage requirements while maintaining security analysis capability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If network packets are intercepted and reconstructed, then security analysis capability is enhanced, but real-time processing speed may be reduced

Engineering Contradiction:
Improvepacket analysis capabilityVSAvoiddata processing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent performs preliminary packet capture and reconstruction in the background without blocking the main network data flow. The network tap device continuously captures packets and reconstructs them asynchronously, allowing security analysis to be performed in advance or in parallel, thus minimizing impact on real-time network performance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8667121B2System and method for managing data and policies
Publication Date: 2014.03.04 MAGENTA SECURITY HOLDINGS LLC
  • US8667121B2 patent drawing
  • US8667121B2 patent drawing
  • US8667121B2 patent drawing

AI summary

In one embodiment, a method is provided and includes capturing a plurality of packet streams, recreating a plurality of flows from the packet streams, and analyzing the flows to identify one or more incidents. The incidents identify one or more pieces of data. The incidents are filtered and the incidents are rendered on a display for an end user that initiated the filtering operation. In other embodiments, the display allows the end user to view a selected one of a group of attributes for the incidents. The display allows the end user to open a captured object associated with a specific incident. In still other embodiments, the display allows a user to filter the incidents using a selected one of a group of group options such as content, destination IP, destination location, destination port, filename, host IP, etc.