Network Visibility Testing for Reliable Service Path Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional methods for assessing the effectiveness of a service path in a networked computing environment are limited, as they often rely on outside-perspective monitoring that does not provide a reliable measure of actual system performance, particularly for data security appliances that need to identify and process malicious data.
Innovation Solution
Incorporating a method where a computing device generates and injects test data into network routes upstream from visibility points, verifying its identification and processing at each point, and potentially modifying it to simulate real-world scenarios, such as blocking or reshaping, to assess the system's ability to recognize and handle data effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Area of stationary object
If outside-perspective monitoring is used to assess service path effectiveness, then monitoring coverage is improved, but measurement reliability deteriorates
Solution Approach 1:
Instead of monitoring from outside the service path, the patent inverts the approach by having monitoring components embedded within the service path itself. Test data is injected into the service path and tracked as it passes through each component, allowing internal verification of data processing and identification at each visibility point, thereby achieving reliable measurements while maintaining comprehensive coverage.
2Measurement precision
If test data is injected into each network route to verify identification at visibility points, then system effectiveness measurement is improved, but device complexity increases
Solution Approach 1:
The patent employs a universal test data structure that can be injected into any network route and recognized by any visibility point. The test data contains identifying characteristics that allow it to be tracked through different service path configurations, enabling a single testing mechanism to assess multiple visibility points and network routes without requiring separate complex testing systems for each component.
3Reliability
If visibility points are deployed at multiple locations to monitor data traffic, then detection capability is improved, but system complexity increases
Solution Approach 1:
The patent segments the service path into multiple visibility points deployed at different locations, with each visibility point independently monitoring and processing data traffic at its specific position. This segmentation allows comprehensive detection coverage across the entire service path while maintaining manageable complexity at each individual visibility point, as each operates semi-independently to identify and process test data passing through its location.
Data Source
AI summary
In an example, a computer-implemented method includes generating test data that is configured to be identified as data of interest at one or more visibility points in a network having a plurality of network routes. The method also includes injecting the test data into each network route of the plurality of network routes at a location upstream from the one or more visibility points, and determining, for each network route through which the test data travels, whether the test data is identified at the one or more visibility points. The method also includes outputting, for each network route through which the test data travels, data that indicates whether the test data is identified at the one or more visibility points as data of interest.


