Remote Capture Agents for Dynamic Network Data Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network data capture technologies are inflexible and difficult to deploy in cloud computing environments, as they require physical hardware and are tailored for specific purposes, making it challenging to adapt to changing business needs and remote data capture.

Innovation Solution

A system that uses remote capture agents distributed across a network to capture and process network data, enabling dynamic configuration and generation of time-series event data based on security risks, with a graphical user interface for risk identification and trigger activation, allowing for on-demand data capture and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical hardware-based network capture devices are used, then network data capture capability is provided, but deployment flexibility and adaptability to cloud environments deteriorate

Engineering Contradiction:
Improvenetwork data capture capabilityVSAvoiddeployment flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces physical hardware capture devices with software-based remote capture agents that can be deployed as virtual machine components or containers. These agents replicate the functionality of physical devices while enabling flexible deployment across cloud environments, eliminating the need for physical hardware installation and connection.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes mechanical/physical hardware systems with software-based solutions. Remote capture agents use software protocols and communication interfaces instead of physical network TAPs or SPAN ports, allowing deployment in virtualized and cloud-based infrastructure without physical hardware connections.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of manufacture

If fixed-purpose network capture technologies are used, then specific capture functions are achieved, but adaptability to changing business needs deteriorates

Engineering Contradiction:
Improvecapture function implementationVSAvoidadaptability to changing needs
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent designs remote capture agents with multi-functional capabilities that can perform various network data capture, filtering, and transformation tasks through configurable parameters. A single agent deployment can serve multiple purposes including security monitoring, performance analysis, and compliance auditing by adjusting configuration settings without requiring separate specialized devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements dynamic configuration capabilities that allow capture agents to adapt their behavior based on changing business requirements. Configuration parameters can be modified at runtime to change capture filters, data transformation rules, and analysis parameters, enabling the system to respond to evolving needs without redeployment.

Inventive Principle:
Principle #15Dynamics

3Loss of information

If comprehensive network data is captured, then complete security risk analysis is enabled, but data processing complexity and resource consumption increase

Engineering Contradiction:
Improvecompleteness of security dataVSAvoiddata processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent performs preliminary filtering and transformation of network data at the remote capture agents before transmission to central analysis systems. Configuration parameters define pre-processing rules that filter out irrelevant data and transform captured packets into standardized formats, reducing the volume and complexity of data requiring further processing while preserving security-relevant information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent divides the data processing function into distributed segments across multiple remote capture agents deployed throughout the network. Each agent independently processes local network traffic according to configuration parameters, performing initial filtering and transformation locally. This segmentation distributes processing complexity across multiple simple agents rather than concentrating it in a single complex system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10812514B2Configuring the generation of additional time-series event data by remote capture agents
Publication Date: 2020.10.20 CISCO TECHNOLOGY INC
  • US10812514B2 patent drawing
  • US10812514B2 patent drawing
  • US10812514B2 patent drawing

AI summary

The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system provides a risk-identification mechanism for identifying a security risk from time-series event data generated from network packets captured by one or more remote capture agents distributed across a network. Next, the system provides a capture trigger for generating additional time-series event data from the network packets on the one or more remote capture agents based on the security risk, wherein the additional time-series event data includes one or more event attributes.