Configurable Monitoring Module for Selective Packet Field Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network monitoring methods face challenges such as high resource utilization, complex equipment management, and packet loss due to the need to monitor all network traffic, which is inefficient and costly, especially when dealing with large amounts of data.

Innovation Solution

A network apparatus with a configurable monitoring module that filters and transmits only selective information from network packets based on user-defined settings, reducing the need to monitor all packets and minimizing equipment requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all network traffic is monitored using network switch mirroring or tapping techniques, then complete network monitoring is achieved, but packet loss occurs and network switch performance deteriorates

Engineering Contradiction:
Improvepacket monitoring completenessVSAvoidnetwork switch performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts only the necessary monitoring information (such as source/destination IP addresses, ports, and protocols) from network packets rather than copying and transmitting entire packets. This extraction approach reduces the data volume significantly, allowing complete monitoring of network traffic without overwhelming the network switch resources, thus preventing packet loss and maintaining switch performance.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of monitoring all packet data completely (excessive action), the patent implements partial monitoring by selectively extracting only the essential fields needed for security analysis. This partial action approach provides sufficient monitoring capability for detecting security threats while avoiding the performance degradation and packet loss associated with full packet copying.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If network switch mirroring is used to monitor all traffic, then complete traffic analysis is enabled, but network switch resource consumption increases

Engineering Contradiction:
Improvetraffic monitoring completenessVSAvoidnetwork switch resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only essential packet fields (source/destination IP, ports, protocols) rather than copying entire packets through mirroring. This extraction significantly reduces the amount of data the network switch must process and transmit, thereby reducing CPU utilization and memory consumption while maintaining complete traffic monitoring capability for security analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a simplified copy of only the necessary packet information rather than creating a full packet copy through mirroring. This selective copying approach reduces the data volume by orders of magnitude, allowing the network switch to monitor all traffic without consuming excessive resources.

Inventive Principle:
Principle #26Copying

3Reliability

If tapping equipment is installed at each switch interface to monitor traffic, then complete packet copying is achieved, but equipment complexity and cost increase

Engineering Contradiction:
Improvepacket copying accuracyVSAvoidequipment management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal monitoring approach using a single network switch with integrated filtering and extraction capabilities, eliminating the need for separate tapping equipment at each interface. The network switch performs multiple functions: traffic receiving, packet filtering based on criteria, information extraction, and data transmission to the analysis system. This multi-functional approach reduces equipment complexity and management burden while maintaining accurate packet copying capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If all network packets are collected and transmitted to the traffic analysis system, then complete security analysis is enabled, but data processing capacity requirements increase

Engineering Contradiction:
Improvesecurity analysis completenessVSAvoiddata processing capacity
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent extracts only the essential security-relevant fields from network packets (source/destination IP addresses, ports, protocols) before transmitting data to the analysis system. This extraction reduces the data volume by a significant factor, enabling complete security analysis of all network traffic while keeping the data processing capacity requirements within manageable levels for the traffic analysis system.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9742699B2Network apparatus and selective information monitoring method using the same
Publication Date: 2017.08.22 ELECTRONICS & TELECOMM RES INST
  • US9742699B2 patent drawing
  • US9742699B2 patent drawing
  • US9742699B2 patent drawing

AI summary

The present invention presents a network apparatus and a selective information monitoring method using the network apparatus, which allow a user to monitor only required information (the field information of packets) from all received packets. The network apparatus one or more physical interfaces connected to a monitoring target host and configured to receive network packets from the monitoring target host, and a switch fabric module including a configurable monitoring module configured to perform filtering so that selective information is extracted from the network packets collected through the one or more physical interfaces.