Network Traffic Mirroring with Data Privacy Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network traffic mirroring duplicates data across locations not involved in the original communication, potentially exposing confidential or private information to unintended parties, as existing methods do not adequately ensure privacy and security of mirrored data.

Innovation Solution

The system encrypts and encapsulates network traffic using tunneling protocols, partially encrypts frames, blanks or scrambles sensitive data, and authenticates/authorizes mirror receiving devices to ensure privacy and security during mirroring, using techniques like encryption, encapsulation, frame modification, and authentication protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network traffic mirroring is implemented to monitor and analyze network traffic, then network troubleshooting and security monitoring capabilities are improved, but data privacy and confidentiality are compromised as sensitive information is exposed to unintended parties

Engineering Contradiction:
Improvenetwork monitoring capabilityVSAvoiddata privacy exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary device positioned between the network traffic source and the mirroring destination. This intermediary intercepts the mirrored traffic, selectively filters out sensitive information based on predefined criteria (such as data types, patterns, or classifications), and then forwards the sanitized traffic to the monitoring system. This mediator approach allows the system to maintain monitoring functionality while protecting privacy by removing harmful elements (sensitive data) from the mirrored stream.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts and removes sensitive information from the mirrored network traffic before it reaches the monitoring destination. The system identifies sensitive data elements (such as personal identifiable information, confidential business data, or privileged communications) and extracts them from the traffic stream, leaving only non-sensitive portions to be monitored. This extraction process directly addresses the privacy exposure problem by taking out the harmful components while preserving the useful monitoring functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If all network traffic is mirrored to ensure complete monitoring coverage, then monitoring completeness is improved, but data transmission overhead and network load increase

Engineering Contradiction:
Improvemonitoring completenessVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies different quality levels of mirroring to different portions of network traffic based on their characteristics and sensitivity. Instead of uniformly mirroring all traffic with the same level of detail, the system applies selective mirroring strategies: high-priority or suspicious traffic receives complete mirroring for thorough analysis, while routine or low-risk traffic receives partial or summarized mirroring. This local quality differentiation reduces overall bandwidth consumption while maintaining monitoring completeness for critical traffic.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial mirroring where only specific portions or aspects of network traffic are mirrored rather than the entire traffic stream. The system can mirror only certain protocol types, specific source/destination pairs, or particular data fields based on monitoring requirements. This partial action approach achieves sufficient monitoring coverage for security and troubleshooting purposes while significantly reducing the bandwidth overhead compared to complete traffic mirroring.

Inventive Principle:
Principle #16Partial or excessive action

3Object-affected harmful factors

If encryption is applied to protect mirrored data privacy, then data security is improved, but processing complexity and computational overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidprocessing complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing sensitive data identification and filtering operations on the mirrored traffic stream before it is transmitted to remote monitoring systems or stored. The intermediary device processes the traffic in real-time, redacting or removing sensitive information proactively before potential exposure occurs. This preliminary processing prevents the need for complex post-processing decryption and analysis, reducing overall computational overhead while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the state or parameters of the mirrored data by transforming sensitive information into non-sensitive forms. Instead of simply encrypting data (which would require key management and decryption complexity), the system applies parameter changes such as data masking, generalization, or aggregation that preserve statistical properties for monitoring purposes while removing identifying characteristics. This approach provides security through parameter transformation rather than traditional encryption, reducing processing complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7690040B2Method for network traffic mirroring with data privacy
Publication Date: 2010.03.30 EXTREME NETWORKS INC
  • US7690040B2 patent drawing
  • US7690040B2 patent drawing
  • US7690040B2 patent drawing

AI summary

Systems and methods are provided for preserving the privacy of data contained in mirrored network traffic. The mirrored network traffic may comprise data that may be considered confidential, privileged, private, or otherwise sensitive data. For example, the data payload of a frame of mirrored network traffic may include private Voice over IP (VoIP) communications between users on one or more networks. The present invention provides various techniques for securing the privacy of data contained in the mirrored network traffic. Using the techniques of the present invention, network traffic comprising confidential, privileged, private, or otherwise sensitive data may be mirrored in such a manner as to provide for the privacy of such data over at least a portion if not all of the mirrored communications between the mirror source point and the mirror destination point.