Network Traffic Statistics Collection via Connection Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for collecting and analyzing IP network traffic statistics, such as Netflow, are inefficient at high traffic rates, often relying on sampling techniques that miss a majority of traffic data, leading to incomplete network insights.

Innovation Solution

A system that collects and displays comprehensive network traffic statistics for active IP destinations using a network device with a connection tracker module and a flowstats module, generating a table of statistics that includes a ranked list of top IP destinations based on traffic metrics, without requiring storage of entire traffic flows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If sampling techniques are used to collect network traffic statistics, then processing efficiency is improved, but measurement precision deteriorates

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidtraffic data completeness
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent extracts only the essential statistics needed for network analysis (byte counts, packet counts, connection counts) from the full traffic flow data. Instead of processing entire Netflow records, the system extracts aggregated statistics at IP destination level, significantly reducing processing overhead while maintaining measurement accuracy for key metrics.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Rather than sampling packets and trying to infer overall traffic characteristics (which loses data), the patent inverts the approach by collecting complete traffic statistics through connection tracking and then selectively analyzing only the most significant IP destinations. This ensures 100% traffic accounting while focusing computational resources on top contributors.

Inventive Principle:
Principle #13The other way round (Inversion)

2Loss of information

If Netflow data is stored and analyzed, then comprehensive traffic information is obtained, but device complexity increases

Engineering Contradiction:
Improvetraffic information completenessVSAvoidstorage and processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent extracts only the most relevant statistics (bytes in/out, packets in/out, connection counts) from complete Netflow data. By focusing on aggregated metrics at IP destination level rather than storing individual flow records, the system maintains comprehensive traffic information while dramatically reducing storage and processing requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements partial action by collecting complete connection tracking data for all traffic but then selectively analyzing only the top N IP destinations by traffic volume. This approach ensures no information is lost in the collection phase while applying analysis resources efficiently to the most significant destinations.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If sampling rate is increased to capture more traffic, then measurement precision improves, but use of energy increases

Engineering Contradiction:
Improvetraffic accounting accuracyVSAvoidprocessing energy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts aggregated statistics from connection tracking data rather than processing individual packets or flows. By computing byte counts, packet counts, and connection counts at the connection tracker level and then analyzing only top IP destinations, the system achieves complete traffic accounting with minimal processing energy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs complete connection tracking for all traffic (ensuring 100% accounting accuracy) but then applies energy-intensive analysis only to the top N destinations by traffic volume. This partial analysis approach maintains measurement precision while dramatically reducing energy consumption compared to analyzing all traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11811628B2Systems and methods to collect and store network traffic statistics of IP destinations in time-series format
Publication Date: 2023.11.07 CRADLEPOINT INC
  • US11811628B2 patent drawing
  • US11811628B2 patent drawing
  • US11811628B2 patent drawing

AI summary

Disclosed embodiments include a system for displaying access market network device network traffic statistics for active Internet Protocol (IP) destinations. The system includes a network device having a connection tracker module that maintains connection-based traffic flows in a packet forwarding path, and a flowstats module that receives data for connection-based traffic flows from the connection tracker module and communicates with an analysis module to generate a table of network traffic statistics for active IP destinations.