Remote Capture Agents for Dynamic Network Data Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network data capture technologies are inflexible and difficult to deploy in cloud computing environments, as they require physical hardware and are tailored for specific purposes, making it challenging to adapt to changing business needs and remote data capture.
Innovation Solution
A system that uses remote capture agents distributed across a network to capture and process network data, enabling dynamic configuration and generation of time-series event data based on security risks, with a graphical user interface for risk identification and trigger activation, allowing for on-demand data capture and analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical hardware-based network capture devices are used, then network data capture capability is provided, but deployment flexibility and adaptability to cloud environments deteriorate
Solution Approach 1:
The patent replaces physical hardware capture devices with software-based remote capture agents that can be deployed as virtual machine components or containers. These agents replicate the functionality of physical devices while enabling flexible deployment across cloud environments, eliminating the need for physical hardware installation and connection.
Solution Approach 2:
The patent substitutes mechanical/physical hardware systems with software-based solutions. Remote capture agents use software protocols and communication interfaces instead of physical network TAPs or SPAN ports, allowing deployment in virtualized and cloud-based infrastructure without physical hardware connections.
2Ease of manufacture
If fixed-purpose network capture technologies are used, then specific capture functions are achieved, but adaptability to changing business needs deteriorates
Solution Approach 1:
The patent designs remote capture agents with multi-functional capabilities that can perform various network data capture, filtering, and transformation tasks through configurable parameters. A single agent deployment can serve multiple purposes including security monitoring, performance analysis, and compliance auditing by adjusting configuration settings without requiring separate specialized devices.
Solution Approach 2:
The patent implements dynamic configuration capabilities that allow capture agents to adapt their behavior based on changing business requirements. Configuration parameters can be modified at runtime to change capture filters, data transformation rules, and analysis parameters, enabling the system to respond to evolving needs without redeployment.
3Loss of information
If comprehensive network data is captured, then complete security risk analysis is enabled, but data processing complexity and resource consumption increase
Solution Approach 1:
The patent performs preliminary filtering and transformation of network data at the remote capture agents before transmission to central analysis systems. Configuration parameters define pre-processing rules that filter out irrelevant data and transform captured packets into standardized formats, reducing the volume and complexity of data requiring further processing while preserving security-relevant information.
Solution Approach 2:
The patent divides the data processing function into distributed segments across multiple remote capture agents deployed throughout the network. Each agent independently processes local network traffic according to configuration parameters, performing initial filtering and transformation locally. This segmentation distributes processing complexity across multiple simple agents rather than concentrating it in a single complex system.
Data Source
AI summary
The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system provides a risk-identification mechanism for identifying a security risk from time-series event data generated from network packets captured by one or more remote capture agents distributed across a network. Next, the system provides a capture trigger for generating additional time-series event data from the network packets on the one or more remote capture agents based on the security risk, wherein the additional time-series event data includes one or more event attributes.


