VM Network Traffic Pre-classification via Packet Tagging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Monitoring packet traffic within virtual processing environments is challenging due to difficulties in identifying and forwarding relevant traffic for analysis to network monitoring tools both within and outside the virtual processing environment.
Innovation Solution
The system pre-classifies network traffic within virtual machine platforms by using client and tool packet monitor applications to encapsulate and de-encapsulate packets with tags, allowing for efficient forwarding of monitored packets to network destinations based on classifications, utilizing GRE headers and classification-to-tag mapping data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If packet monitoring is implemented in virtual processing environments using traditional methods (hubs, TAPs, SPAN ports), then network traffic can be monitored, but it becomes difficult to identify and forward relevant traffic for analysis to network monitoring tools
Solution Approach 1:
The patent applies preliminary action by pre-classifying network packets at the source (within the virtual processing environment) before they reach the monitoring tools. The classification is performed in advance using tags that mark packets with their category information, enabling monitoring tools to efficiently process only relevant traffic without having to analyze all packets. This resolves the contradiction by making traffic identification easier while maintaining reliable monitoring coverage.
Solution Approach 2:
The patent introduces an intermediary classification mechanism that sits between the network traffic source and the monitoring tools. This intermediary layer adds tags to packets and routes them to appropriate monitoring tools based on their classification. This mediator resolves the contradiction by bridging the gap between comprehensive packet capture and selective traffic analysis, making the system both reliable and easy to operate.
2Reliability
If all network packets are forwarded to monitoring tools for analysis, then complete monitoring coverage is achieved, but processing time and system resources increase significantly
Solution Approach 1:
The patent applies local quality by treating different packets differently based on their classification. Instead of applying the same processing approach to all packets, the system assigns specific tags and routing paths to different packet types. This allows monitoring tools to focus processing resources on packets that require analysis while maintaining complete coverage through the tagging system. The contradiction is resolved by achieving comprehensive monitoring without uniform processing of all packets.
Solution Approach 2:
The patent implements partial action by having monitoring tools process only the packets that are relevant to their specific monitoring functions. The classification system ensures that each tool receives a curated subset of packets matching its analysis capabilities, rather than all packets. This maintains reliable monitoring coverage across multiple specialized tools while significantly reducing the processing time for each individual tool.
3Productivity
If packet classification and routing is implemented within VM platforms, then traffic forwarding efficiency improves, but device complexity increases
Solution Approach 1:
The patent applies universality by designing a classification and tagging mechanism that can handle multiple packet types and routing scenarios through a single unified system. The same tagging infrastructure serves both classification and routing functions, and the system can accommodate various monitoring tools with different requirements. This multi-functionality improves forwarding efficiency while limiting complexity growth, as one universal mechanism replaces multiple specialized systems.
4Adaptability or versatility
If multiple monitoring tools access packets from multiple source links through packet brokers, then traffic aggregation and load balancing are achieved, but the complexity of identifying and forwarding relevant traffic increases
Solution Approach 1:
The patent applies preliminary action by performing classification and tag assignment at the source before packets enter the complex broker network. This pre-processing eliminates the need for complex forwarding rules in packet brokers, as packets arrive already marked with their classification information. The brokers can then use simple tag-based routing instead of complex packet analysis rules, achieving versatile tool accessibility while reducing forwarding complexity.
Data Source
AI summary
Methods and systems are disclosed that pre-classify network traffic monitored within virtual machine (VM) platforms. Client packet monitor applications operate within client VM platforms to monitor network packets, generate monitored packets representing traffic of interest, determine packet classifications for the monitored packets based upon packet contents, identify tags associated with the packet classifications, encapsulate monitored packets with encapsulation headers including the tags to form encapsulated packets, and forward the encapsulated packets to tool VM platforms. Tool packet monitor applications operate within the tool VM platforms to receive the encapsulated packets, identify packet classifications associated with the tags, remove the encapsulation headers from the encapsulated packets, and forward de-encapsulated packets to network destinations based upon the packet classifications. The tool packet monitor applications can also aggregate de-encapsulated packets having the same packet classification prior to forwarding the aggregated packets to one or more network destinations.


