Packet Switch Appliance Meta-Data Tagging for Network Forensics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current packet-switching networks lack the capability to provide comprehensive information about packet traffic beyond source and destination addresses, limiting forensic analysis and retrieval efficiency.
Innovation Solution
A packet switch appliance is integrated into the network to create and manage meta-data tags for blocks of packets, which are then sent to data storage devices and a storage management server, enabling detailed information storage and retrieval across multiple devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If packet traffic is stored using standard packet format (header, payload, trailer), then bandwidth efficiency is maintained, but network information beyond source and destination address is limited
Solution Approach 1:
The patent embeds meta-data tags within the packet structure, nesting additional information layers inside the standard packet format. The meta-data tag contains source address, destination address, time stamp, and content information, all nested within the packet without disrupting the original header-payload-trailer structure
Solution Approach 2:
The patent introduces meta-data tags as intermediary elements that bridge the gap between standard packet format and comprehensive network information storage. These tags act as mediators that add forensic analysis capabilities while maintaining compatibility with existing packet switching infrastructure
2Measurement precision
If meta-data tags are created and sent to multiple storage devices, then information retrieval capability is enhanced, but network bandwidth and storage resources are consumed
Solution Approach 1:
The patent segments the storage architecture by directing different meta-data tags to different storage devices based on their content characteristics. This segmentation allows parallel storage operations and distributes the bandwidth load across multiple storage paths, reducing congestion on any single channel
Solution Approach 2:
The patent performs preliminary actions by creating and sending meta-data tags to storage devices during the packet forwarding process itself, rather than performing these operations afterward. This preliminary creation of forensic information enables immediate retrieval capabilities without requiring separate post-processing steps
Data Source
AI summary
A first instrument port of a packet switch appliance is connected to a first data storage device. A second port is configured as a first network port. A first meta-data tag is created for a first block of packets received through the first network port. The first block is sent to the first data storage device through the first instrument port. The first meta-data tag or copy is sent to the first data storage device and/or a storage management server. A second instrument port of the packet switch appliance is connected to a second data storage device. A second meta-data tag is created for a second block of packets received through the first network port. The second block is sent to the second data storage device through the second instrument port. The second meta-data tag or copy is sent to the second data storage device and/or the storage management server.


