VM Network Traffic Pre-classification via Packet Tagging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Monitoring packet traffic within virtual processing environments is challenging due to difficulties in identifying and forwarding relevant traffic for analysis to network monitoring tools both within and outside the virtual processing environment.

Innovation Solution

The system pre-classifies network traffic within virtual machine platforms by using client and tool packet monitor applications to encapsulate and de-encapsulate packets with tags, allowing for efficient forwarding of monitored packets to network destinations based on classifications, utilizing GRE headers and classification-to-tag mapping data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If packet monitoring is implemented in virtual processing environments using traditional methods (hubs, TAPs, SPAN ports), then network traffic can be monitored, but it becomes difficult to identify and forward relevant traffic for analysis to network monitoring tools

Engineering Contradiction:
Improvepacket monitoring reliabilityVSAvoidtraffic identification and forwarding ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-classifying network packets at the source (within the virtual processing environment) before they reach the monitoring tools. The classification is performed in advance using tags that mark packets with their category information, enabling monitoring tools to efficiently process only relevant traffic without having to analyze all packets. This resolves the contradiction by making traffic identification easier while maintaining reliable monitoring coverage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary classification mechanism that sits between the network traffic source and the monitoring tools. This intermediary layer adds tags to packets and routes them to appropriate monitoring tools based on their classification. This mediator resolves the contradiction by bridging the gap between comprehensive packet capture and selective traffic analysis, making the system both reliable and easy to operate.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all network packets are forwarded to monitoring tools for analysis, then complete monitoring coverage is achieved, but processing time and system resources increase significantly

Engineering Contradiction:
Improvemonitoring coverage completenessVSAvoidpacket processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies local quality by treating different packets differently based on their classification. Instead of applying the same processing approach to all packets, the system assigns specific tags and routing paths to different packet types. This allows monitoring tools to focus processing resources on packets that require analysis while maintaining complete coverage through the tagging system. The contradiction is resolved by achieving comprehensive monitoring without uniform processing of all packets.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by having monitoring tools process only the packets that are relevant to their specific monitoring functions. The classification system ensures that each tool receives a curated subset of packets matching its analysis capabilities, rather than all packets. This maintains reliable monitoring coverage across multiple specialized tools while significantly reducing the processing time for each individual tool.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If packet classification and routing is implemented within VM platforms, then traffic forwarding efficiency improves, but device complexity increases

Engineering Contradiction:
Improvetraffic forwarding efficiencyVSAvoidVM platform complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a classification and tagging mechanism that can handle multiple packet types and routing scenarios through a single unified system. The same tagging infrastructure serves both classification and routing functions, and the system can accommodate various monitoring tools with different requirements. This multi-functionality improves forwarding efficiency while limiting complexity growth, as one universal mechanism replaces multiple specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If multiple monitoring tools access packets from multiple source links through packet brokers, then traffic aggregation and load balancing are achieved, but the complexity of identifying and forwarding relevant traffic increases

Engineering Contradiction:
Improvemonitoring tool accessibilityVSAvoidpacket forwarding rule complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing classification and tag assignment at the source before packets enter the complex broker network. This pre-processing eliminates the need for complex forwarding rules in packet brokers, as packets arrive already marked with their classification information. The brokers can then use simple tag-based routing instead of complex packet analysis rules, achieving versatile tool accessibility while reducing forwarding complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10652112B2Network traffic pre-classification within VM platforms in virtual processing environments
Publication Date: 2020.05.12 KEYSIGHT TECH SINGAPORE (SALES) PTE LTD
  • US10652112B2 patent drawing
  • US10652112B2 patent drawing
  • US10652112B2 patent drawing

AI summary

Methods and systems are disclosed that pre-classify network traffic monitored within virtual machine (VM) platforms. Client packet monitor applications operate within client VM platforms to monitor network packets, generate monitored packets representing traffic of interest, determine packet classifications for the monitored packets based upon packet contents, identify tags associated with the packet classifications, encapsulate monitored packets with encapsulation headers including the tags to form encapsulated packets, and forward the encapsulated packets to tool VM platforms. Tool packet monitor applications operate within the tool VM platforms to receive the encapsulated packets, identify packet classifications associated with the tags, remove the encapsulation headers from the encapsulated packets, and forward de-encapsulated packets to network destinations based upon the packet classifications. The tool packet monitor applications can also aggregate de-encapsulated packets having the same packet classification prior to forwarding the aggregated packets to one or more network destinations.