Rolling Buffer Network Threat Trace Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern networking equipment struggles to keep pace with high-speed network traffic exceeding 40-100 Gbps/sec, making it impractical for network security devices to capture and store all network traffic for tracing purposes, especially in large virtual environments.

Innovation Solution

Implementing a rolling buffer system that tags and stores network packets with expirable trace time values, allowing machine learning algorithms and malware detectors to analyze and extend or modify these values based on host identification, thereby efficiently managing memory by removing uninteresting packets and focusing on sensitive or anomalous traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If all network traffic is captured and stored for tracing purposes, then complete forensic detail is achieved, but storage requirements become impractical and network performance degrades at speeds exceeding 40-100 Gbps/sec

Engineering Contradiction:
Improveforensic detailVSAvoidstorage requirements
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent segments network traffic into two categories: suspicious traffic that requires detailed tracing and stored in long-term storage, and normal traffic that is processed more efficiently with minimal storage. This segmentation allows the system to maintain complete forensic detail for relevant packets while avoiding the impractical requirement of storing all network traffic at high speeds

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different quality levels of packet capture and storage to different types of network traffic. Suspicious packets receive full forensic detail and long-term retention, while normal packets receive reduced processing and minimal storage. This local quality approach ensures complete forensic detail is preserved where needed without the excessive storage requirements of universal capture

Inventive Principle:
Principle #3Local quality

2Reliability

If network security devices capture and store all network traffic, then comprehensive threat analysis is enabled, but the devices cannot keep pace with high-speed network traffic exceeding 40-100 Gbps/sec

Engineering Contradiction:
Improvethreat analysisVSAvoidnetwork processing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system performs preliminary analysis of network packets using heuristics and machine learning models to identify suspicious traffic before committing resources to full capture and storage. This preliminary action enables reliable threat analysis by focusing resources on potentially malicious packets while maintaining the ability to process high-speed network traffic without bottlenecking

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of applying full packet capture and analysis to all traffic, the system applies partial action by selectively capturing and analyzing only suspicious packets. This approach maintains reliable threat analysis for relevant traffic while allowing the system to keep pace with high-speed network traffic that would be impossible to process if all packets were captured

Inventive Principle:
Principle #16Partial or excessive action

3Loss of information

If packet capture is implemented in large virtual environments with multitudes of virtualized computers, then complete network monitoring is achieved, but it becomes impractical if not infeasible to capture and store all traffic

Engineering Contradiction:
Improvenetwork monitoring coverageVSAvoidsystem feasibility
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments the large virtual environment into manageable components using distributed tracing agents deployed across virtualized computers. Each agent independently identifies and reports suspicious packets, enabling complete network monitoring coverage across the entire virtual environment without the impractical complexity of centralized capture of all traffic

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Individual virtualized computers or network segments perform self-service packet analysis using local heuristics and machine learning models to identify suspicious traffic. This self-service approach enables complete monitoring coverage across large virtual environments by distributing the analysis workload, making the system feasible where centralized capture would be impractical

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10404730B1High-volume network threat trace engine
Publication Date: 2019.09.03 VECTRA NETWORKS
  • US10404730B1 patent drawing
  • US10404730B1 patent drawing
  • US10404730B1 patent drawing

AI summary

An approach for high-volume network threat tracing and detection may be implemented by storing network communications received from a plurality of hosts in an initial recording data structure, such as a rolling buffer. Identifiers may be generated for the plurality of hosts associated with the network communications by according to host identity or the behavior of a given host. Extended trace time values may be assigned to a portion of the plurality of hosts based at least in part on the identifiers, and storing the portion of the network communications that have extended trace time values may be recorded as packet capture files in long term memory.