Router Port Mirroring via Security Agent for Full Traffic Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Deploying large numbers of physical TAP devices for network traffic monitoring is costly and time-consuming, while using sampling protocols like NETFLOW results in data loss and requires specialized networking equipment.
Innovation Solution
A computing system that uses a server computing device to communicate with security agents on client devices, configuring router devices for port mirroring to forward network traffic to a security agent, minimizing the need for physical TAP appliances and reducing bandwidth load.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If large numbers of physical TAP devices are deployed for network traffic monitoring, then network visibility and deep packet inspection capability are improved, but deployment cost and time consumption increase significantly
Solution Approach 1:
The patent creates a virtual copy of the TAP device functionality by implementing a software-based network traffic mirror in the virtualization layer. This virtual mirror replicates the traffic copying capability of physical TAP devices without requiring physical hardware deployment, thereby maintaining network visibility while eliminating deployment time and cost associated with physical devices
Solution Approach 2:
The patent replaces the mechanical/physical TAP device system with a software-based virtual network function. The virtualization infrastructure substitutes physical hardware components with virtualized network functions that perform the same traffic mirroring and monitoring operations, eliminating the need for physical device installation and configuration
2Device complexity
If sampling protocols like NETFLOW are used for network traffic monitoring, then deployment complexity is reduced, but data loss occurs due to sampling
Solution Approach 1:
The patent introduces a virtual network mirror as an intermediary layer between the physical network and monitoring tools. This virtual mirror receives complete network traffic copies from the virtualized network infrastructure and forwards them to security monitoring tools, ensuring data completeness while keeping deployment simple through virtualization management
Solution Approach 2:
The virtual network mirror serves multiple functions simultaneously: it acts as a traffic copier, a data distributor to multiple monitoring tools, and a deployment simplifier. This multi-functional approach eliminates the need for specialized sampling equipment while maintaining data completeness and reducing deployment complexity
3Reliability
If conventional TAP appliances are connected to TAP ports of networking devices, then access privileges for traffic reading are improved, but the number of required devices and associated costs increase
Solution Approach 1:
The patent merges the TAP device functionality with the existing virtualization infrastructure. The virtual network mirror leverages the virtual switch and virtualization layer already present in modern networks, combining multiple functions into existing infrastructure components rather than adding separate physical devices for each monitoring point
Data Source
AI summary
A computing system is provided, including a server computing device configured to execute a security service that communicates with a security agent on a client computing device via a wide area network and an on-premises network on which the client computing device is provisioned, and receive and store, at the server computing device, administrator login credentials for a router device on the on-premises network. The processor is further configured to send a monitoring command to the security agent to cause the security agent to access the router device using the administrator login credentials and configure the router device to forward network traffic received by the router device to the security agent at the client computing device via port mirroring, and receive an on-premises network traffic monitoring report from the security agent based on the network traffic forwarded to the client computing device.


