Network Traffic Distribution Device Packet Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional communication networks transmit full traffic flows to external monitoring devices, leading to increased resource burden and potential legal issues due to unnecessary data transmission, as these devices often receive unfiltered and unmodified data packets without awareness of originating ports or chronological entry into the network.

Innovation Solution

A network captured traffic distribution device analyzes data packets to identify predefined segments, modifies them as needed (e.g., deleting, truncating, or adding data) to comply with contracts, privacy policies, and laws, and determines appropriate egress ports for transmission, using a combination of ingress and egress ports, ASICs, and FPGAs to manage and manipulate data packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If full traffic flow of captured network traffic is transmitted to external monitoring devices, then all data including relevant and irrelevant information is available for analysis, but bandwidth and processing resources are increased and processing time is consumed

Engineering Contradiction:
Improveinformation completenessVSAvoidbandwidth consumption
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The patent extracts only the relevant portions of captured network traffic by identifying and separating predefined segments (such as VLAN tags, GTP information, MPLS information) from the full traffic flow. This extraction is performed by analyzing data packets to locate specific segments and transmitting only those relevant segments to external monitoring devices, thereby reducing bandwidth consumption while maintaining information completeness for analysis purposes.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the captured network traffic into predefined segments based on packet analysis. By dividing the full traffic flow into identifiable segments (VLAN tags, GTP information, MPLS information, and other data categories), the system can selectively transmit only the necessary segments to external monitoring devices, reducing overall bandwidth usage while preserving the ability to perform comprehensive analysis on the extracted segments.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If full traffic flow of captured network traffic is transmitted to external monitoring devices, then all data is available for analysis, but processing time is increased

Engineering Contradiction:
Improveinformation completenessVSAvoidprocessing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent performs preliminary analysis and segmentation of captured network traffic before transmission to external monitoring devices. By pre-identifying and separating predefined segments (VLAN tags, GTP information, MPLS information) from the full traffic flow, the system reduces the amount of data that needs to be processed externally, thereby decreasing processing time while maintaining information completeness for the segments that are transmitted.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If unmodified captured traffic flow is transmitted to external monitoring devices, then all original data is preserved, but inappropriate information may be transmitted causing legal issues

Engineering Contradiction:
Improvedata integrityVSAvoidlegal compliance
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and removes inappropriate information from captured network traffic by identifying predefined segments that may contain sensitive or illegal data (such as classified information, trade secrets, or data violating wire-tapping laws). By separating and filtering these segments before transmission to external monitoring devices, the system maintains the integrity of appropriate data while ensuring legal compliance by preventing transmission of inappropriate information.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If unmodified captured traffic flow is transmitted to external monitoring devices, then all original data is preserved, but external devices cannot identify originating ports or chronological entry

Engineering Contradiction:
Improvedata integrityVSAvoidport identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent performs preliminary modification of captured traffic flow by adding identifying information such as originating port numbers and timestamps before transmission to external monitoring devices. This preliminary action preserves the integrity of the original data while enabling external devices to identify originating ports and determine chronological entry order, thereby resolving the difficulty of detecting and measuring these attributes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8767727B2System, apparatus, and method for modifying captured data packets
Publication Date: 2014.07.01 NETSCOUT SYSTEMS INC
  • US8767727B2 patent drawing
  • US8767727B2 patent drawing
  • US8767727B2 patent drawing

AI summary

Systems, apparatus, and methods for modifying a captured data packet included in a traffic flow of captured data packets are described. A captured data packet may be analyzed in order to, for example, locate a predefined segment of data included in the received captured data packet, determine a type of data included in the data packet, and determine content included in the data packet. The data packet may then be modified based upon the analysis. Exemplary modifications include deleting a portion of the data included in the data packet, truncating the data packet, and modifying data included in the predefined segment.