Network Traffic Analysis via Probe Whitelisting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for monitoring network traffic data are impractical due to the vast amounts of data captured, making it burdensome or impossible to analyze, especially since current solutions rely on manual selection of data for analysis using light-weight session tracking (LST).

Innovation Solution

A communication network monitoring system with programmable probes that detect transactional procedure failures, determine end-user device identities, and share these identities to perform detailed analysis on whitelisted data, automating the selection and analysis process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If virtual probes are deployed to capture network traffic data, then the ease of deployment and data capture capability is improved, but the burden and complexity of analyzing the captured data increases

Engineering Contradiction:
Improveease of deploymentVSAvoiddata analysis complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent extracts and isolates only the critical data packets from the vast amount of captured network traffic. By using detection rules to identify specific failure-related packets and creating whitelists of relevant end-user device identities, the system separates the essential analysis targets from the overwhelming bulk of unnecessary data, making analysis feasible and manageable

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the data analysis process into two distinct phases: lightweight analysis for all captured data to detect failure patterns, and detailed analysis only for whitelisted critical data. This segmentation allows the system to handle vast amounts of traffic efficiently while focusing computational resources only on the most relevant subsets of data

Inventive Principle:
Principle #1Segmentation

2Device complexity

If manual selection of data for analysis is performed using light-weight session tracking, then the analysis burden is reduced, but the automation and efficiency of the monitoring process deteriorates

Engineering Contradiction:
Improveanalysis burdenVSAvoiddata selection automation
Core Design Contradiction:
Device complexityVSExtent of automation

Solution Approach 1:

The system implements self-service automation where probes automatically perform lightweight analysis on captured data, automatically detect transactional failures, automatically determine end-user device identities, automatically create whitelists of critical data targets, and automatically perform detailed analysis on whitelisted packets without any manual intervention, thereby maintaining low analysis burden while achieving full automation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements feedback mechanisms where detection results from lightweight analysis feed into automatic whitelist creation, which then guides subsequent detailed analysis. The system continuously monitors, detects failures, updates whitelists based on detected patterns, and refines analysis focus, creating an automated feedback loop that reduces manual burden while enhancing automation

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9929930B2Reducing an amount of captured network traffic data to analyze
Publication Date: 2018.03.27 NETSCOUT SYSTEMS TEXAS LLC
  • US9929930B2 patent drawing
  • US9929930B2 patent drawing
  • US9929930B2 patent drawing

AI summary

A system and method for monitoring a communication network is provided. The method includes capturing network data from network traffic of the communication network by a plurality of probes monitoring the communication network. The method further includes detecting by lightweight analysis a data packet of the captured network data that includes information related to a transactional procedure failure transacted by an end-user device and determining an identity of the end-user device. The method further includes sharing the identity of the end-user device with other probes of the plurality of probes, adding the end-user device's identity to respective whitelists associated with the probes of the plurality of probes, and performing, for end-user device identities included in the respective whitelists, detailed analysis of network data during a predetermined time period.