Remote Capture Agents for Cloud Network Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network data capture technologies are inflexible and difficult to deploy in cloud computing environments, as they require physical hardware appliances and are often tailored for specific vertical markets, making it challenging to adapt to changing business needs and remote data capture in distributed networks.
Innovation Solution
A system comprising remote capture agents and a configuration server that dynamically captures and processes network data across distributed networks, allowing for real-time configuration and transformation of event data, reducing the need for physical hardware and enabling flexible data capture and processing in cloud environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical hardware appliances are used for network data capture, then network traffic can be captured and processed, but device complexity and difficulty of deployment increase
Solution Approach 1:
The patent replaces physical hardware appliances with software-based virtual network capture agents that replicate network capture functionality in virtual environments. These agents can be deployed as virtual machines or containers within cloud infrastructure, eliminating the need for dedicated physical hardware while maintaining network data capture capabilities.
Solution Approach 2:
The patent substitutes physical mechanical network capture devices with software-based virtualization mechanisms. Instead of using physical TAPs, SPAN ports, or dedicated capture appliances, the system employs virtual capture agents that intercept network traffic through software protocols, replacing hardware-based mechanisms with software-based alternatives.
2Reliability
If conventional network capture devices are used, then network traffic can be monitored, but adaptability to changing business needs is reduced
Solution Approach 1:
The patent implements dynamic configuration capabilities where network capture agents can be programmatically adjusted to monitor different network protocols, traffic patterns, and data formats based on changing business requirements. The system allows runtime modification of capture parameters, filtering rules, and data collection methodologies without requiring hardware reconfiguration.
Solution Approach 2:
The patent creates a universal network capture platform that can perform multiple functions including traffic monitoring, security analysis, performance measurement, and compliance auditing through a single versatile software framework. The system supports various vertical markets and use cases through configurable agents rather than requiring specialized dedicated devices for each function.
3Reliability
If ETL processes are performed after data capture, then data can be processed and transformed, but processing time and overhead increase
Solution Approach 1:
The patent performs data transformation, filtering, and aggregation operations at the network capture agents in real-time as traffic is captured, rather than waiting to process data after collection. This preliminary processing reduces the volume of data that needs to be transmitted and processed later, decreasing overall ETL time and processing overhead.
Solution Approach 2:
The patent divides the data processing function across multiple segments: capture agents perform initial filtering and transformation at the network edge, central processing systems handle aggregation and analysis, and storage systems manage data retention. This segmentation allows parallel processing and reduces the processing burden on any single system component.
Data Source
AI summary
The disclosed embodiments provide a method and system for facilitating the processing of network data. During operation, the system obtains, at a remote capture agent, configuration information for the remote capture agent from a configuration server over a network. Next, the system uses the configuration information to configure the generation of event data from network packets at the remote capture agent. Upon receiving an update to the configuration information from the configuration server, the system uses the update to reconfigure the generation of the event data by the remote capture agent during runtime of the remote capture agent.


