Ingress Node Packet Marking for Network Flow Analytics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network analytics methods are inefficient, particularly in high-bandwidth environments, as they require examining each data packet, which is computationally intensive and can impact node performance, and sampling techniques limit end-to-end tracking and analysis due to non-overlapping packet samples across nodes.
Innovation Solution
Implementing a method where ingress nodes mark data packets for special processing, allowing intermediate nodes to collect and report characteristics, with marking labels inserted in MPLS or IP packets, enabling efficient data flow analytics and correlation across the network domain.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If each data packet is examined at network nodes for analytics, then measurement precision is improved, but device complexity and processing power requirements worsen
Solution Approach 1:
The ingress node performs preliminary actions by marking selected data packets with unique identifiers before they traverse the network. This preliminary marking enables intermediate and egress nodes to efficiently track and analyze specific packets without performing complex examination operations at each node, thereby reducing device complexity while maintaining measurement precision.
Solution Approach 2:
The patent extracts the computationally intensive packet analysis function from intermediate network nodes and concentrates it at the ingress and egress nodes. By marking packets at the ingress node and performing comprehensive analysis at the egress node, the system removes the burden of detailed packet examination from intermediate nodes, reducing their processing complexity while preserving analytical accuracy.
2Productivity
If sampling is performed to reduce processing load, then productivity is improved, but reliability of end-to-end tracking worsens
Solution Approach 1:
The patent introduces marking labels as intermediary elements that bridge the gap between sampled packets and comprehensive analysis. These markers act as mediators that enable selected packets to be tracked end-to-end across all network nodes without requiring full inspection of every packet. This intermediary mechanism maintains reliability of tracking for sampled packets while preserving productivity gains from selective analysis.
Solution Approach 2:
The system creates a simplified copy or representation of packet identification information through marking labels. Instead of copying and analyzing entire packets at each node, the patent uses compact marking identifiers that represent the full packet information needed for tracking. This copying approach maintains tracking reliability while significantly reducing the data processing burden, thereby improving productivity.
3Measurement precision
If comprehensive packet analysis is performed, then measurement precision is improved, but loss of time increases
Solution Approach 1:
The ingress node performs preliminary marking of selected packets with unique identifiers before they enter the network traversal. This preliminary action pre-prepares the packets for efficient tracking, eliminating the need for time-consuming analysis operations at intermediate nodes. The comprehensive analysis is performed once at the egress node using the pre-established markers, reducing total processing time while maintaining measurement precision.
Solution Approach 2:
The patent extracts the time-consuming packet examination operations from the time-critical path at intermediate nodes and relocates them to non-critical timing positions at the ingress and egress nodes. By marking packets in advance and performing detailed analysis after network traversal, the system removes processing delays from the packet forwarding path, thereby reducing loss of time while preserving analytical accuracy.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
A method is implemented by a node of a network domain having a plurality of nodes, where the node functions as an ingress node of the network domain for a data flow. The method enables data flow analysis across the network domain. The method includes receiving a data packet belonging to a data flow at an ingress node of the network domain, determining whether the data packet is to be marked for the data flow analysis, determining whether an egress node of the network domain for the data flow supports data packet marking, marking the data packet with a marking label indicating to supporting nodes in the network domain that the data packet is to be processed for data flow analysis, and forwarding the data packet toward the egress node of the network domain.