Network Packet Broker Metadata Deduplication and Redirection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network packet brokers are limited to processing packets and cannot efficiently handle network flow metadata, leading to issues such as duplication, storage waste, and the inability to forward NetFlow statistics to multiple destinations or redirect them automatically when a primary destination fails.

Innovation Solution

A network packet broker system that processes network flow metadata by accessing a processing rules database to apply deduplication, replication, decryption, and format translation rules, allowing for the forwarding of metadata to multiple tools and automatic redirection to secondary destinations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If NetFlow statistics are forwarded to multiple destinations using single destination configuration, then network tool utilization is improved, but device complexity increases

Engineering Contradiction:
Improveforwarding to multiple destinationsVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a network packet broker as an intermediary device between NetFlow sources and multiple network tools. The broker receives NetFlow statistics from sources and automatically distributes them to multiple destinations based on configured rules, eliminating the need for manual configuration at each source device and enabling multi-destination forwarding through a single centralized point.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network packet broker is designed with multi-functional capabilities to handle various NetFlow processing tasks including duplication, filtering, forwarding to multiple destinations, and automatic redirection. This universal device consolidates multiple functions that would otherwise require separate configurations or devices, improving versatility while managing complexity centrally.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If NetFlow records are collected from multiple switches, then network monitoring coverage is improved, but storage and processing resources are wasted due to duplication

Engineering Contradiction:
Improvemonitoring coverageVSAvoidstorage and processing resources
Core Design Contradiction:
Adaptability or versatilityVSLoss of substance

Solution Approach 1:

The network packet broker serves as an intermediary that receives duplicate NetFlow records from multiple switches and applies deduplication logic. By identifying and eliminating duplicate records before forwarding to network tools, the broker maintains comprehensive monitoring coverage while preventing waste of storage and processing resources at the tool level.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a deduplication mechanism that identifies duplicate NetFlow records and discards redundant copies while preserving unique records. This process recovers storage and processing resources that would otherwise be wasted on duplicate data, while maintaining complete monitoring coverage through the retention of all unique flow records.

Inventive Principle:
Principle #34Discarding and recovering

3Reliability

If manual reconfiguration is performed when primary destination fails, then reliability is maintained, but loss of time occurs during redirection

Engineering Contradiction:
Improvedestination failoverVSAvoidredirection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The network packet broker implements automatic destination failure detection and redirection capabilities. When a primary destination becomes unavailable, the broker autonomously detects the failure and redirects NetFlow statistics to alternative destinations without requiring manual intervention. This self-service mechanism maintains system reliability while eliminating the time loss associated with manual reconfiguration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback mechanisms where the network packet broker continuously monitors the status of destination tools. When feedback indicates a destination failure, the broker automatically responds by redirecting traffic to backup destinations. This closed-loop feedback system ensures reliable operation while minimizing downtime through automated responses to failure conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11190417B2Methods, systems, and computer readable media for processing network flow metadata at a network packet broker
Publication Date: 2021.11.30 KEYSIGHT TECHNOLOGIES INC
  • US11190417B2 patent drawing
  • US11190417B2 patent drawing
  • US11190417B2 patent drawing

AI summary

A method for network flow metadata processing at a network packet broker includes, receiving, as input at the network packet broker, network flow metadata, the network flow metadata including a network flow statistic generated by a network device regarding packets in the network flow. The method further includes accessing, by the network packet broker, a network flow metadata processing rules database and identifying a network flow metadata processing rule to apply to the network flow metadata. The method further includes processing, by the network packet broker, the network flow metadata using the network flow metadata processing rule. The method further includes forwarding, by the network packet broker and based on results of the processing, egress network flow metadata to a network tool.