Session-Aware Packet Filtering for Network Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network switch devices are limited in their ability to efficiently process and monitor network traffic by identifying sessions and routing packets to instrument ports based on complex criteria, particularly in out-of-band configurations, where packets from different types of network traffic need to be distinguished and managed.
Innovation Solution
A network device that receives packets, identifies sessions based on matching criteria, and performs packet processing actions such as forwarding, dropping, or modifying packets, using a processing unit that can analyze packets for regular expressions and user-defined criteria, and buffers packets for retroactive processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network switch devices use complex criteria to identify sessions and route packets to instrument ports, then network monitoring capabilities are improved, but device complexity increases
Solution Approach 1:
The patent segments packet processing into distinct stages: initial packet reception, session identification based on first criteria, and subsequent packet routing based on second criteria. This segmentation allows complex monitoring functions to be implemented through modular, manageable processing steps rather than a monolithic complex system.
Solution Approach 2:
The patent performs preliminary session identification using first criteria before applying second criteria for packet routing. By pre-establishing session contexts and buffering packets during the identification phase, the system simplifies subsequent routing decisions and reduces real-time processing complexity.
2Measurement precision
If packets are buffered for retroactive processing after session identification, then packet processing accuracy is improved, but loss of time increases
Solution Approach 1:
The patent buffers packets during the session identification phase before final routing decisions are made. This preliminary buffering allows the system to accurately match packets to sessions using multiple criteria without losing packets, ensuring processing accuracy while managing time through controlled buffering rather than repeated processing attempts.
Data Source
AI summary
A method performed by a network device includes: receiving a first packet by the network device, wherein the first packet is tapped from a network; identifying a session to which the first packet belongs when the first packet has one or more values that at least partially match one or more terms, wherein the act of identifying the session is performed by the network device; receiving a second packet by the network device; determining whether the second packet belongs to the session; and performing a packet processing action by the network device based on the identified session; wherein the session is identified based on a first criterion, and the act of determining whether the second packet belongs to the session is performed based on a second criterion that is different from the first criterion.


