Network Packet Broker Metadata Deduplication and Redirection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network packet brokers are limited to processing packets and cannot efficiently handle network flow metadata, leading to issues such as duplication, storage waste, and the inability to forward NetFlow statistics to multiple destinations or redirect them automatically when a primary destination fails.
Innovation Solution
A network packet broker system that processes network flow metadata by accessing a processing rules database to apply deduplication, replication, decryption, and format translation rules, allowing for the forwarding of metadata to multiple tools and automatic redirection to secondary destinations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If NetFlow statistics are forwarded to multiple destinations using single destination configuration, then network tool utilization is improved, but device complexity increases
Solution Approach 1:
The patent introduces a network packet broker as an intermediary device between NetFlow sources and multiple network tools. The broker receives NetFlow statistics from sources and automatically distributes them to multiple destinations based on configured rules, eliminating the need for manual configuration at each source device and enabling multi-destination forwarding through a single centralized point.
Solution Approach 2:
The network packet broker is designed with multi-functional capabilities to handle various NetFlow processing tasks including duplication, filtering, forwarding to multiple destinations, and automatic redirection. This universal device consolidates multiple functions that would otherwise require separate configurations or devices, improving versatility while managing complexity centrally.
2Adaptability or versatility
If NetFlow records are collected from multiple switches, then network monitoring coverage is improved, but storage and processing resources are wasted due to duplication
Solution Approach 1:
The network packet broker serves as an intermediary that receives duplicate NetFlow records from multiple switches and applies deduplication logic. By identifying and eliminating duplicate records before forwarding to network tools, the broker maintains comprehensive monitoring coverage while preventing waste of storage and processing resources at the tool level.
Solution Approach 2:
The system implements a deduplication mechanism that identifies duplicate NetFlow records and discards redundant copies while preserving unique records. This process recovers storage and processing resources that would otherwise be wasted on duplicate data, while maintaining complete monitoring coverage through the retention of all unique flow records.
3Reliability
If manual reconfiguration is performed when primary destination fails, then reliability is maintained, but loss of time occurs during redirection
Solution Approach 1:
The network packet broker implements automatic destination failure detection and redirection capabilities. When a primary destination becomes unavailable, the broker autonomously detects the failure and redirects NetFlow statistics to alternative destinations without requiring manual intervention. This self-service mechanism maintains system reliability while eliminating the time loss associated with manual reconfiguration.
Solution Approach 2:
The system incorporates feedback mechanisms where the network packet broker continuously monitors the status of destination tools. When feedback indicates a destination failure, the broker automatically responds by redirecting traffic to backup destinations. This closed-loop feedback system ensures reliable operation while minimizing downtime through automated responses to failure conditions.
Data Source
AI summary
A method for network flow metadata processing at a network packet broker includes, receiving, as input at the network packet broker, network flow metadata, the network flow metadata including a network flow statistic generated by a network device regarding packets in the network flow. The method further includes accessing, by the network packet broker, a network flow metadata processing rules database and identifying a network flow metadata processing rule to apply to the network flow metadata. The method further includes processing, by the network packet broker, the network flow metadata using the network flow metadata processing rule. The method further includes forwarding, by the network packet broker and based on results of the processing, egress network flow metadata to a network tool.


