Packet Tagging for Network Traffic Capture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Diagnosing network connectivity issues in data centers is challenging due to complex topologies and the difficulty in identifying intermittent packet drops, which can lead to poor network performance and revenue loss, especially in virtualized environments where traditional troubleshooting methods are time-consuming and labor-intensive.

Innovation Solution

A method and system for tagging packets at end hosts and entry points in the network, allowing devices on the data path to automatically capture and report packet counters for tagged traffic, enabling quick identification of packet drops by using reserved header fields like DSCP in IP headers and implementing an API for per-user/VM/flow-level tagging and packet capture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If packet capture is enabled hop by hop on each switch to diagnose network issues, then packet loss can be identified, but the troubleshooting process becomes time-consuming and labor-intensive

Engineering Contradiction:
Improvepacket loss identification accuracyVSAvoidtroubleshooting time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the network troubleshooting process by introducing flow-specific identifiers that divide the complex network traffic into identifiable segments. Each flow is tagged with unique identifiers allowing precise tracking through the network without requiring manual capture at every hop, thus maintaining measurement precision while reducing time loss.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism - flow identifiers and tagging systems - that mediate between the network traffic and the diagnostic process. These tags act as intermediaries that carry flow information through the network, enabling automated tracking and identification of packet loss sources without manual intervention at each switch.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If traditional packet capture methods are used in complex data center topologies, then network issues can be diagnosed, but the complexity of multiple paths and devices makes troubleshooting difficult and error-prone

Engineering Contradiction:
Improvenetwork issue diagnosis accuracyVSAvoidnetwork topology complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning specific flow identifiers and tags to individual traffic flows at local points in the network. This allows each flow to be uniquely identified and tracked through the complex topology, enabling precise diagnosis without requiring operators to manage the overall network complexity manually.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter space by introducing flow identifier tags as new parameters that accompany packets through the network. These additional parameters enable automated tracking and correlation of packets across multiple paths and devices, transforming the complex diagnostic problem into a manageable parameter-matching task.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If packet drop counters are used on routers and switches, then some packet loss can be detected, but the counters are not specific enough to identify the source of issues for particular traffic flows

Engineering Contradiction:
Improvepacket loss detection capabilityVSAvoidtraffic flow identification information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts flow-specific information from the packet data by introducing flow identifiers and tags that are attached to packets. This extraction of identifying information allows the system to separate and track individual flows, enabling precise identification of packet loss sources for specific traffic without losing flow identification information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements feedback mechanisms where flow identifiers are tracked throughout the network path, and diagnostic information is fed back to identify the specific source of packet loss. This feedback loop provides detailed information about which specific flow is experiencing issues, rather than just aggregate packet loss counts.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3854033B1Packet capture via packet tagging
Publication Date: 2023.10.04 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3854033B1 patent drawingFigure 1
  • EP3854033B1 patent drawingFigure 2
  • EP3854033B1 patent drawingFigure 3

AI summary

Techniques are disclosed for capturing network traffic in a virtualized computing environment. A packet to be captured in the virtualized environment is identified. The packet is tagged using a pattern of one or more bits in a header of the packet. The pattern indicates that the packet is to be traced. The pattern is propagated to an outer layer during encapsulation of the packet. A header of the encapsulated packet includes the pattern of one or more bits. At least one network device is caused to mirror identified packets based on the reserved bit.