Remote Capture Agents for Dynamic Network Event Stream Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network data capture technologies are inflexible and challenging to deploy in cloud computing environments, as they require physical hardware and fixed configurations, limiting their ability to adapt to changing business needs and remote data processing.

Innovation Solution

A system that uses remote capture agents to capture and process network data, allowing for protocol-based capture and analysis, and provides a graphical user interface for configuring and managing event streams, enabling dynamic configuration and storage management without the need for physical hardware, facilitating on-the-fly changes and efficient data processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical hardware-based network capture devices are used, then network data capture can be performed with established reliability, but deployment in cloud computing environments becomes impossible or extremely challenging

Engineering Contradiction:
Improvenetwork data capture reliabilityVSAvoiddeployment flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces physical hardware-based network capture devices with a software-based virtual capture agent that runs within the cloud computing environment. This substitution eliminates the need for physical hardware deployment while maintaining network data capture functionality, thereby resolving the contradiction between reliability and deployment flexibility.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a virtual copy of the network capture functionality through software agents that replicate the data collection and processing capabilities of physical devices. These virtual agents can be deployed anywhere in the cloud environment without requiring physical hardware, enabling flexible deployment while maintaining capture reliability.

Inventive Principle:
Principle #26Copying

2Ease of manufacture

If fixed configuration network capture technologies are used, then implementation is straightforward, but modification to address different and changing business needs becomes precluded

Engineering Contradiction:
Improveimplementation simplicityVSAvoidconfiguration flexibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic configuration capabilities where the virtual capture agent can be remotely configured and reconfigured without requiring physical hardware changes. Users can modify capture parameters, data types, and processing rules through software interfaces, enabling the system to adapt to changing business needs while maintaining implementation simplicity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal network capture platform that can perform multiple functions including security monitoring, performance analysis, and data collection. The single virtual agent can be configured for different business needs and vertical markets, eliminating the need for multiple specialized devices and enabling flexible adaptation to various requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If remote capture agents are deployed across the network, then data capture configuration can be changed on-the-fly, but management and processing of large volumes of event data becomes complex

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoiddata management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the data processing workload by deploying virtual capture agents at distributed locations across the network, each responsible for capturing and initially processing local data. This segmentation enables on-the-fly configuration changes at each agent while distributing the management complexity across multiple independent units rather than requiring centralized control of all data streams.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized management system that acts as an intermediary between users and the distributed capture agents. This management system handles the complexity of data processing, aggregation, and analysis, while providing simplified interfaces for configuration changes. The intermediary layer abstracts the complexity from end users while enabling flexible on-the-fly configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Quantity of substance

If traditional ETL processes are used for data processing, then data can be filtered and transformed, but the processes are cumbersome and time-consuming

Engineering Contradiction:
Improvedata processing capabilityVSAvoidprocessing time
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The patent performs data filtering, transformation, and aggregation operations at the virtual capture agent in advance, before data reaches the central processing system. This preliminary action reduces the volume of data that requires subsequent processing, making the overall ETL process more efficient and less time-consuming while maintaining comprehensive data processing capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous data processing where the virtual capture agents continuously filter, transform, and prepare data streams in real-time as data is captured. This continuous processing eliminates the need for batch ETL operations, reducing processing time and enabling faster data availability while maintaining the ability to handle large volumes of data.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10700950B2Adjusting network data storage based on event stream statistics
Publication Date: 2020.06.30 CISCO TECHNOLOGY INC
  • US10700950B2 patent drawing
  • US10700950B2 patent drawing
  • US10700950B2 patent drawing

AI summary

The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements for managing one or more event streams containing the time-series event data, wherein managing the one or more event streams includes enabling the generation of a set of statistics from an event stream without subsequently storing and processing at least a first portion of the event stream by one or more components on a network. The GUI then updates the configuration information based on input received through the first set of user-interface elements.