Virtualized Network Capture Agents for Cloud Adaptability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network data capture technologies are inflexible and difficult to deploy in cloud computing environments, requiring physical hardware and fixed configurations, which limits their ability to adapt to changing business needs and hinders efficient data processing and analysis.

Innovation Solution

A system that uses remote capture agents to capture network data, generating time-series event streams that can be configured and managed through a GUI, allowing for on-the-fly changes and eliminating the need for physical hardware, with features like protocol-based capture, risk identification, and dynamic event stream management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical hardware-based network capture devices are used, then network data capture capability is provided, but deployment complexity and adaptability to cloud environments deteriorates

Engineering Contradiction:
Improvenetwork data capture capabilityVSAvoidadaptability to cloud environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces physical hardware capture devices with virtualized software-based capture agents that replicate network data capture functionality in cloud environments. These agents can be deployed as virtual machines or containers, eliminating the need for physical hardware while maintaining network data capture capability and enabling flexible deployment across cloud infrastructure.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes physical hardware-based network capture mechanisms with software-based virtualized systems. Instead of requiring physical TAPs or SPAN ports, the system uses virtual capture agents that run on cloud infrastructure, replacing mechanical/physical network capture hardware with software-based data capture and processing functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If physical network capture devices are deployed, then network data can be captured, but ease of deployment and configuration deteriorates

Engineering Contradiction:
Improvenetwork data captureVSAvoidease of deployment and configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent uses virtualized capture agents that can be copied and deployed through software imaging techniques. These agents can be provisioned as virtual machines or containers with pre-configured network capture capabilities, eliminating the need for complex physical hardware deployment and configuration while maintaining reliable network data capture functionality.

Inventive Principle:
Principle #26Copying

3Reliability

If fixed configuration network capture systems are used, then specific network capture functions are achieved, but adaptability to changing business needs deteriorates

Engineering Contradiction:
Improvenetwork capture functionVSAvoidadaptability to changing business needs
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic configuration capabilities in the virtualized capture system. The system allows runtime modification of capture parameters, filtering rules, and data processing configurations through software-based control planes. This enables the same infrastructure to adapt to changing business requirements without requiring hardware reconfiguration, while maintaining reliable network capture functions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal virtualized capture platform that can perform multiple network capture and data processing functions through software-defined capabilities. The same virtualized infrastructure can be configured for different capture scenarios, security analysis, performance monitoring, and other business needs, replacing fixed specialized hardware with a multi-functional universal system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11086897B2Linking event streams across applications of a data intake and query system
Publication Date: 2021.08.10 CISCO TECHNOLOGY INC
  • US11086897B2 patent drawing
  • US11086897B2 patent drawing
  • US11086897B2 patent drawing

AI summary

The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements comprising event stream information for one or more ephemeral event streams used to temporarily generate the time-series event data from the network packets. The system then causes for display, in the GUI, a mechanism for navigating between the event stream information and creation information for one or more creators of the one or more ephemeral event streams.