Configurable Monitoring Module for Selective Packet Field Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network monitoring methods face challenges such as high resource utilization, complex equipment management, and packet loss due to the need to monitor all network traffic, which is inefficient and costly, especially when dealing with large amounts of data.
Innovation Solution
A network apparatus with a configurable monitoring module that filters and transmits only selective information from network packets based on user-defined settings, reducing the need to monitor all packets and minimizing equipment requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all network traffic is monitored using network switch mirroring or tapping techniques, then complete network monitoring is achieved, but packet loss occurs and network switch performance deteriorates
Solution Approach 1:
The patent extracts only the necessary monitoring information (such as source/destination IP addresses, ports, and protocols) from network packets rather than copying and transmitting entire packets. This extraction approach reduces the data volume significantly, allowing complete monitoring of network traffic without overwhelming the network switch resources, thus preventing packet loss and maintaining switch performance.
Solution Approach 2:
Instead of monitoring all packet data completely (excessive action), the patent implements partial monitoring by selectively extracting only the essential fields needed for security analysis. This partial action approach provides sufficient monitoring capability for detecting security threats while avoiding the performance degradation and packet loss associated with full packet copying.
2Reliability
If network switch mirroring is used to monitor all traffic, then complete traffic analysis is enabled, but network switch resource consumption increases
Solution Approach 1:
The patent extracts only essential packet fields (source/destination IP, ports, protocols) rather than copying entire packets through mirroring. This extraction significantly reduces the amount of data the network switch must process and transmit, thereby reducing CPU utilization and memory consumption while maintaining complete traffic monitoring capability for security analysis.
Solution Approach 2:
The patent creates a simplified copy of only the necessary packet information rather than creating a full packet copy through mirroring. This selective copying approach reduces the data volume by orders of magnitude, allowing the network switch to monitor all traffic without consuming excessive resources.
3Reliability
If tapping equipment is installed at each switch interface to monitor traffic, then complete packet copying is achieved, but equipment complexity and cost increase
Solution Approach 1:
The patent implements a universal monitoring approach using a single network switch with integrated filtering and extraction capabilities, eliminating the need for separate tapping equipment at each interface. The network switch performs multiple functions: traffic receiving, packet filtering based on criteria, information extraction, and data transmission to the analysis system. This multi-functional approach reduces equipment complexity and management burden while maintaining accurate packet copying capability.
4Reliability
If all network packets are collected and transmitted to the traffic analysis system, then complete security analysis is enabled, but data processing capacity requirements increase
Solution Approach 1:
The patent extracts only the essential security-relevant fields from network packets (source/destination IP addresses, ports, protocols) before transmitting data to the analysis system. This extraction reduces the data volume by a significant factor, enabling complete security analysis of all network traffic while keeping the data processing capacity requirements within manageable levels for the traffic analysis system.
Data Source
AI summary
The present invention presents a network apparatus and a selective information monitoring method using the network apparatus, which allow a user to monitor only required information (the field information of packets) from all received packets. The network apparatus one or more physical interfaces connected to a monitoring target host and configured to receive network packets from the monitoring target host, and a switch fabric module including a configurable monitoring module configured to perform filtering so that selective information is extracted from the network packets collected through the one or more physical interfaces.


