Network Traffic Analysis with Multiple Parent-Dependency Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network analysis systems are poorly suited to identify multiple dependencies in networks that use intermediate nodes configured to avoid strict sequential communication techniques, such as WAN accelerators, leading to difficulties in ascertaining causal relationships and parent-dependencies in traffic flow.
Innovation Solution
A system and method that identifies multiple parent-dependencies for messages in networks with intermediate/proxy nodes by distinguishing messages from destination nodes and other nodes, and defining dependencies for each message transmitted from a forwarding node, assuming these nodes may introduce multiple dependencies, thereby facilitating accurate traffic flow analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If conventional network analysis systems assume single dependency paths for each message, then the analysis process is simple and straightforward, but the analysis accuracy deteriorates when intermediate nodes (such as WAN accelerators) introduce multiple dependencies
Solution Approach 1:
The patent segments the dependency analysis by distinguishing between forwarding nodes and non-forwarding nodes. Each node type is analyzed separately with appropriate dependency rules, allowing the system to handle multiple dependencies from forwarding nodes while maintaining simple single-dependency analysis for non-forwarding nodes.
Solution Approach 2:
The patent applies different dependency analysis rules to different parts of the network based on node function. Forwarding nodes (intermediate nodes) are analyzed with multi-dependency rules, while end nodes are analyzed with single-dependency rules, making the analysis quality appropriate for each local context.
2Speed
If intermediate nodes (such as WAN accelerators) are used to enhance network performance by avoiding strict sequential communication, then network speed improves, but the difficulty of detecting and measuring causal relationships deteriorates
Solution Approach 1:
The patent introduces the concept of a forwarding node as an intermediary that mediates between the strict sequential communication model and the accelerated communication model. By identifying and analyzing forwarding nodes separately, the system can detect and measure their multiple dependencies while preserving the speed benefits of avoided sequential communication.
Solution Approach 2:
The patent makes the dependency analysis dynamic by adapting the analysis rules based on the node type. The system dynamically switches between single-dependency analysis for end nodes and multi-dependency analysis for forwarding nodes, allowing accurate causal relationship detection across different network segments.
3Ease of operation
If network analysis tools are configured to assume strict sequential order for message dependencies, then clock alignment and conditional analyses are simplified, but the reliability of analysis deteriorates in networks with intermediate nodes that introduce multiple dependencies
Solution Approach 1:
The patent segments the network into forwarding nodes and non-forwarding nodes, applying different dependency assumptions to each segment. This segmentation allows the system to maintain simple sequential assumptions where applicable while ensuring reliable analysis in segments with multiple dependencies.
Solution Approach 2:
The patent applies different dependency analysis qualities to different parts of the network based on local node characteristics. End nodes use simple sequential dependency assumptions for ease of operation, while forwarding nodes use comprehensive multi-dependency analysis for reliability.
Data Source
AI summary
Multiple parent-dependencies are identified for messages that are received on a network that includes nodes that are configured to avoid the conventional strictly-sequential communications techniques and protocols, in order to accelerate network performance. If a network is known, or assumed, to include intermediate/proxy nodes that are configured to provide acceleration, access control, and other services, the system that analyzes traffic on the network is configured to assume that these nodes may/will provide such features, and thereby introduce multiple dependencies among the messages communicated across the network. For each message transmitted from a forwarding node, messages received at the forwarding node are assessed to distinguish messages from the destination node and messages from an other node, and a dependency is defined for each.


