Network Traffic Statistics Collection via Connection Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for collecting and analyzing IP network traffic statistics, such as Netflow, are inefficient at high traffic rates, often relying on sampling techniques that miss a majority of traffic data, leading to incomplete network insights.
Innovation Solution
A system that collects and displays comprehensive network traffic statistics for active IP destinations using a network device with a connection tracker module and a flowstats module, generating a table of statistics that includes a ranked list of top IP destinations based on traffic metrics, without requiring storage of entire traffic flows.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If sampling techniques are used to collect network traffic statistics, then processing efficiency is improved, but measurement precision deteriorates
Solution Approach 1:
The patent extracts only the essential statistics needed for network analysis (byte counts, packet counts, connection counts) from the full traffic flow data. Instead of processing entire Netflow records, the system extracts aggregated statistics at IP destination level, significantly reducing processing overhead while maintaining measurement accuracy for key metrics.
Solution Approach 2:
Rather than sampling packets and trying to infer overall traffic characteristics (which loses data), the patent inverts the approach by collecting complete traffic statistics through connection tracking and then selectively analyzing only the most significant IP destinations. This ensures 100% traffic accounting while focusing computational resources on top contributors.
2Loss of information
If Netflow data is stored and analyzed, then comprehensive traffic information is obtained, but device complexity increases
Solution Approach 1:
The patent extracts only the most relevant statistics (bytes in/out, packets in/out, connection counts) from complete Netflow data. By focusing on aggregated metrics at IP destination level rather than storing individual flow records, the system maintains comprehensive traffic information while dramatically reducing storage and processing requirements.
Solution Approach 2:
The patent implements partial action by collecting complete connection tracking data for all traffic but then selectively analyzing only the top N IP destinations by traffic volume. This approach ensures no information is lost in the collection phase while applying analysis resources efficiently to the most significant destinations.
3Measurement precision
If sampling rate is increased to capture more traffic, then measurement precision improves, but use of energy increases
Solution Approach 1:
The patent extracts aggregated statistics from connection tracking data rather than processing individual packets or flows. By computing byte counts, packet counts, and connection counts at the connection tracker level and then analyzing only top IP destinations, the system achieves complete traffic accounting with minimal processing energy.
Solution Approach 2:
The system performs complete connection tracking for all traffic (ensuring 100% accounting accuracy) but then applies energy-intensive analysis only to the top N destinations by traffic volume. This partial analysis approach maintains measurement precision while dramatically reducing energy consumption compared to analyzing all traffic.
Data Source
AI summary
Disclosed embodiments include a system for displaying access market network device network traffic statistics for active Internet Protocol (IP) destinations. The system includes a network device having a connection tracker module that maintains connection-based traffic flows in a packet forwarding path, and a flowstats module that receives data for connection-based traffic flows from the connection tracker module and communicates with an analysis module to generate a table of network traffic statistics for active IP destinations.


