Virtual Network Taps for Cloud Data Capture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network data capture technologies are inflexible and difficult to deploy in cloud computing environments, as they require physical hardware and are often customized for specific purposes, making it challenging to adapt to changing business needs and remote deployment.
Innovation Solution
A system that uses remote capture agents to capture network data, generating time-series event streams which can be configured and managed through a GUI, allowing for on-the-fly changes and eliminating the need for physical hardware, with configuration information updated dynamically to support various protocols and security risk-based capture triggers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical hardware-based network capture devices are used, then reliable network data capture can be achieved, but deployment in cloud computing environments becomes difficult and inflexible
Solution Approach 1:
The patent uses software-based virtual network taps (vTaps) that create virtual copies of network interfaces, allowing network data capture without physical hardware. The virtual tap device driver creates a virtual network interface that mirrors actual network traffic, enabling reliable capture while being easily deployable in cloud environments through software installation rather than physical hardware deployment.
Solution Approach 2:
The patent replaces physical hardware-based network taps with software-based virtual network taps. Instead of requiring physical network capture devices with dedicated hardware, the system uses software drivers and virtual interfaces to capture network data, eliminating the need for mechanical/physical hardware while maintaining capture reliability and enabling flexible cloud deployment.
2Ease of manufacture
If customized network capture technologies are built for specific purposes, then specialized functionality is achieved, but adaptability to different business needs deteriorates
Solution Approach 1:
The patent implements a universal network capture platform using virtual network taps that can serve multiple purposes. The same virtual tap infrastructure supports various capture scenarios including security monitoring, performance analysis, QoS measurement, and intrusion detection, allowing one system to replace multiple specialized devices and adapt to different business needs through software configuration.
Solution Approach 2:
The patent enables dynamic configuration of network capture parameters through software-based control. Instead of fixed hardware configurations, the system allows real-time adjustment of capture filters, data formats, and processing parameters through software interfaces, enabling the same infrastructure to adapt to changing business requirements without hardware reconfiguration.
3Productivity
If ETL processes are used to process captured network data, then data extraction and transformation can be achieved, but processing complexity and time consumption increase
Solution Approach 1:
The patent performs data extraction and transformation actions at the time of network data capture rather than in subsequent batch ETL processes. The virtual network tap driver extracts relevant information from network packets and transforms it into structured event data immediately during capture, eliminating the need for time-consuming post-capture ETL processing and enabling real-time data availability.
Solution Approach 2:
The patent introduces a virtual network tap intermediary layer between the physical network interface and the data processing system. This virtual tap acts as a mediator that performs initial data extraction and transformation, converting raw network packets into structured events before they reach the processing system, thereby reducing the complexity and time of subsequent ETL operations.
Data Source
AI summary
The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display, on a computer system, a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements for managing one or more ephemeral event streams that contain temporarily generated time-series event data from the network packets, wherein managing the one or more ephemeral event streams comprises modifying an end time for terminating the capture of time-series event data in an ephemeral event stream. The system then updates the configuration information based on input received through the first set of user-interface elements.


