Network Traffic Monitoring via Signed URL Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Lawful interception of network traffic often fails due to unavailability of content destination devices, leading to undetected and unaddressed fraudulent or dangerous activities, and wastage of computing resources.
Innovation Solution
A network device performs flow tapping by sending a traffic flow copy to a signed uniform resource locator (URL) platform instead of a content destination device, using a flow-tap filter to identify and process traffic flows, ensuring availability and reliability of the traffic flow copy for analysis by authorized user devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traffic flow copying is performed to a content destination device, then lawful interception capability is provided, but the system reliability deteriorates when the content destination device is unavailable
Solution Approach 1:
The patent introduces a signed URL platform as an intermediary between the network device and the ultimate destination. Instead of directly copying traffic to a content destination device that may be unavailable, the system uses a signed URL as a reliable intermediary storage mechanism. The network device copies traffic and stores it on the signed URL platform, which guarantees availability through cryptographic signing and persistent storage, eliminating the reliability dependency on the content destination device being online.
Solution Approach 2:
The system performs preliminary action by pre-generating signed URLs and pre-establishing storage capacity on the signed URL platform before traffic interception is needed. This allows the network device to immediately copy and store traffic flows without waiting for content destination devices to become available, ensuring that traffic copies are ready for analysis as soon as authorized users need them.
2Productivity
If traditional flow tapping to content destination device is used, then traffic interception is achieved, but computing resources are wasted when destination is unavailable
Solution Approach 1:
The signed URL platform provides self-service capabilities by automatically managing traffic flow copy storage, retrieval, and access control. When the network device copies traffic to the signed URL platform, the system automatically handles persistence, security signing, and authorized access without requiring continuous intervention or retry logic. This eliminates wasteful computing resources that would otherwise be spent on retrying failed transmissions to unavailable content destination devices.
Solution Approach 2:
The patent implements efficient copying by creating traffic flow copies and storing them on the signed URL platform, which is designed to handle copy operations reliably. Unlike traditional approaches that repeatedly attempt to send copies to potentially unavailable destinations, this system makes a single reliable copy to the signed URL platform, ensuring computing resources are used effectively without waste from failed transmission attempts.
3Ease of operation
If traffic flow copy is made available via signed URL, then accessibility for analysis is improved, but the system requires new infrastructure
Solution Approach 1:
The signed URL platform provides multi-functionality by serving as a universal storage and access mechanism for traffic flow copies from multiple network devices and multiple authorized users. Rather than requiring separate infrastructure for each interception instance, the signed URL platform handles diverse traffic flows and user access requests through a unified system, improving ease of operation while managing infrastructure complexity through consolidation.
Solution Approach 2:
The signed URL platform acts as an intermediary that simplifies access for authorized users. Instead of users needing to directly connect to network devices or manage complex interception infrastructure, they simply use signed URLs to access their authorized traffic flows. This intermediary layer abstracts the complexity away from end users, making the system easier to operate despite the underlying infrastructure.
Data Source
AI summary
A network monitoring device may receive flow-tap information that identifies a traffic flow characteristic and a signed URL associated with a signed URL platform from a mediation device. The network device may map the traffic flow characteristic to the signed URL in an entry of a flow-tap filter that is maintained within a data structure of the network device. The network device may analyze, using the flow-tap filter, network traffic of the network to detect a traffic flow that is associated with the traffic flow characteristic. The network device may generate, based on detecting the traffic flow in the network traffic, a traffic flow copy that is associated with the traffic flow. The network device may provide, based on the signed URL, the traffic flow copy to the signed URL platform, wherein the traffic flow copy is to be accessible to an authorized user device via the signed URL.


