Remote Capture Agents for Cloud Network Data Event Streams

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network data capture technologies are inflexible and difficult to deploy in cloud computing environments, as they require physical hardware appliances and are often customized for specific purposes, making it challenging to adapt to changing business needs or deploy in distributed and remote locations.

Innovation Solution

A system that uses remote capture agents to process network data by obtaining protocol classifications, building event streams from packet flows, and transmitting them over a network for storage and processing, with configuration information dynamically updated to enable flexible data capture and analysis, eliminating the need for physical hardware and allowing on-the-fly configuration changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical hardware appliances are used for network data capture, then capture reliability is improved, but device complexity and ease of deployment deteriorate

Engineering Contradiction:
Improvecapture reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates virtual copies of network capture functionality through software agents that replicate the capture and processing capabilities of physical hardware appliances. These virtual agents can be deployed on standard servers and cloud instances, eliminating the need for specialized physical equipment while maintaining capture reliability through software-based packet interception and analysis.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces physical hardware-based network capture mechanisms with software-based virtualization. Instead of using dedicated physical tap devices or hardware appliances, the system uses software agents that run on standard computing platforms to perform packet capture, protocol analysis, and data processing functions traditionally requiring specialized hardware.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If physical network capture devices are deployed, then data capture capability is improved, but ease of operation and adaptability deteriorate

Engineering Contradiction:
Improvedata capture capabilityVSAvoidadaptability to changing needs
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic configuration capabilities where the network capture system can be reconfigured in real-time based on changing business requirements. The virtualized architecture allows capture agents to be dynamically deployed, scaled, and repositioned without physical reinstallation, enabling the system to adapt to varying network conditions and analytical needs.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal network capture platform that can serve multiple functions and vertical markets through a single software-based architecture. The same virtualized capture infrastructure can be configured for security analysis, performance monitoring, QoS measurement, and other purposes by changing software parameters rather than requiring different physical devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If ETL processes are used for data processing, then data analysis capability is improved, but loss of time and productivity deteriorate

Engineering Contradiction:
Improvedata analysis capabilityVSAvoidprocessing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent performs preliminary data processing and transformation actions at the point of capture within the virtualized environment itself. Rather than collecting raw data and later processing it through time-consuming ETL processes, the system pre-processes packets for relevant information extraction, filtering, and transformation closer to the network source, reducing the time required for subsequent analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces virtualized processing layers as intermediaries between network capture and final data analysis. These virtual processing agents perform intermediate transformation and aggregation operations that bridge the gap between raw packet capture and business intelligence, eliminating the need for heavy-duty ETL processes by processing data in a more integrated manner.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11936764B1Generating event streams based on application-layer events captured by remote capture agents
Publication Date: 2024.03.19 CISCO TECHNOLOGY INC
  • US11936764B1 patent drawing
  • US11936764B1 patent drawing
  • US11936764B1 patent drawing

AI summary

The disclosed embodiments provide a system that processes network data. During operation, the system obtains, at a remote capture agent, a first protocol classification for a first packet flow captured by the remote capture agent. Next, the system uses configuration information associated with the first protocol classification to build a first event stream from the first packet flow at the remote capture agent, wherein the first event stream comprises time-series event data generated from network packets in the first packet flow based on the first protocol classification. The system then transmits the first event stream over a network for subsequent storage and processing of the first event stream by one or more components on the network.