Session-Aware Packet Filtering for Network Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network switch devices are limited in their ability to efficiently process and monitor network traffic by identifying sessions and routing packets to instrument ports based on complex criteria, particularly in out-of-band configurations, where packets from different types of network traffic need to be distinguished and managed.

Innovation Solution

A network device that receives packets, identifies sessions based on matching criteria, and performs packet processing actions such as forwarding, dropping, or modifying packets, using a processing unit that can analyze packets for regular expressions and user-defined criteria, and buffers packets for retroactive processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network switch devices use complex criteria to identify sessions and route packets to instrument ports, then network monitoring capabilities are improved, but device complexity increases

Engineering Contradiction:
Improvenetwork monitoring capabilitiesVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments packet processing into distinct stages: initial packet reception, session identification based on first criteria, and subsequent packet routing based on second criteria. This segmentation allows complex monitoring functions to be implemented through modular, manageable processing steps rather than a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary session identification using first criteria before applying second criteria for packet routing. By pre-establishing session contexts and buffering packets during the identification phase, the system simplifies subsequent routing decisions and reduces real-time processing complexity.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If packets are buffered for retroactive processing after session identification, then packet processing accuracy is improved, but loss of time increases

Engineering Contradiction:
Improvepacket processing accuracyVSAvoidprocessing delay
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent buffers packets during the session identification phase before final routing decisions are made. This preliminary buffering allows the system to accurately match packets to sessions using multiple criteria without losing packets, ensuring processing accuracy while managing time through controlled buffering rather than repeated processing attempts.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11165682B2Session aware adaptive packet filtering
Publication Date: 2021.11.02 GIGAMON INC
  • US11165682B2 patent drawing
  • US11165682B2 patent drawing
  • US11165682B2 patent drawing

AI summary

A method performed by a network device includes: receiving a first packet by the network device, wherein the first packet is tapped from a network; identifying a session to which the first packet belongs when the first packet has one or more values that at least partially match one or more terms, wherein the act of identifying the session is performed by the network device; receiving a second packet by the network device; determining whether the second packet belongs to the session; and performing a packet processing action by the network device based on the identified session; wherein the session is identified based on a first criterion, and the act of determining whether the second packet belongs to the session is performed based on a second criterion that is different from the first criterion.