Automatic policy engine selection

Through the unified policy agent automatic selection and configuration of the policy enforcement engine, the complex problem of manual configuration in the existing technology is solved, and the optimization and seamless migration of policy enforcement are achieved.

CN115967517BActive Publication Date: 2025-05-16HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210399974.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-10-11
Filing Date
2022-04-15
Publication Date
2025-05-16
Estimated Expiration
2042-04-15

AI Technical Summary

Technical Problem

The prior art has difficulty in effectively managing and configuring different policy enforcement engines, especially in multiple interconnected network devices, resulting in complex and difficult manual configuration.

Method used

By providing a unified policy agent, automatically selecting a policy enforcement engine, standardizing terms, workflows, and capabilities across different policy engines, realizing automatic configuration and management.

Benefits of technology

Seamless migration across different policy enforcement engines and optimization policy enforcement is achieved, reducing the complexity and difficulty of user manual configuration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115967517B_ABST
    Figure CN115967517B_ABST
Patent Text Reader

Abstract

One aspect of the present application promotes automatic policy engine selection. During operation, a system can monitor a network including a group of network devices. The system can receive a set of attributes associated with the network based on the monitoring. At least two network devices are equipped with different policy enforcement engines for enforcing one or more given policy rules. The system can apply a unified policy model to determine the allocation of one or more given policy rules to a first policy enforcement engine and a second policy enforcement engine based on the set of attributes to provide optimized policy enforcement. The system can then select one or both of the first policy enforcement engine and the second policy enforcement engine based on the allocation. The system can activate the selected one or both policy enforcement engines for enforcing a given policy rule.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] The present disclosure generally relates to the field of network management and networking strategies. Typically, a network may include multiple interconnected network devices, wherein at least one or more network devices implement a policy enforcement engine. In a typical network, multiple different policy enforcement engines may exist along a network path to manage network traffic for enforcing networking strategies. Each policy enforcement engine may be associated with different performance characteristics and capabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0002] Figure 1 An example network environment including a computer system for facilitating automatic policy engine selection using a unified policy broker according to one aspect of the present application is illustrated.

[0003] Figure 2 An example system architecture for facilitating automatic policy engine selection based on a unified policy agent according to one aspect of the present application is illustrated.

[0004] Figure 3A An example network configuration with a selected first set of policy engines according to one aspect of the present application is illustrated.

[0005] Figure 3B An example network configuration with a selected second set of policy engines according to one aspect of the present application is illustrated.

[0006] Figure 4A A flow chart illustrating an example process for creating a unified policy agent according to one aspect of the present application is presented.

[0007] Figure 4B A flow chart illustrating an example process for performing automatic policy engine selection based on a unified policy agent according to one aspect of the present application is presented.

[0008] Figure 5 An example computer system that facilitates automatic policy engine selection based on a unified policy agent according to one aspect of the present application is illustrated.

[0009] In the drawings, like reference numerals refer to the same drawing elements. DETAILED DESCRIPTION

[0010] The following description is presented to enable any person skilled in the art to make and use these examples and is provided in the context of a specific application and its requirements. Various modifications to the disclosed examples will be apparent to those skilled in the art, and the general principles defined herein may be applied to other examples and applications without departing from the spirit and scope of the present disclosure. Therefore, the scope of the present disclosure is not limited to the examples shown but should be given the widest scope consistent with the principles and features disclosed herein.

[0011] Various network devices residing in the network may be equipped with a policy enforcement engine. A policy enforcement engine may be a software component or a hardware component that may implement a set of networking policies. For example, an access control list (ACL) may be a networking policy that may allow a user to specify rules using an application programming interface (API) to deny a particular type of business. In addition, a networking policy may also correspond to a forwarding rule, such as policy-based forwarding (PBF), or a firewall rule. Different policy enforcement engines may be associated with different types of APIs. For example, one API may support a certain way of describing or expressing a policy, while another API may use a different policy expression language.

[0012] Each policy enforcement engine can enforce one or more networking policies for managing network traffic. For example, one policy enforcement engine in a first network device along a network traffic path can enforce network security policies, and another policy enforcement engine in a second network device along the network traffic path can enforce traffic management policies. In other words, an ACL in a network switch can correspond to a first policy enforcement engine, and a firewall rule in a firewall device or distributed firewall can correspond to a second policy enforcement engine.

[0013] Different types of policy enforcement engines can be associated with different application programming interfaces (APIs). Each type of API can represent policies with different terms. For example, an API associated with a first policy enforcement engine can represent a policy function with specific terms, while another API associated with a second policy enforcement engine can represent a similar policy function with different terms. Although the existence of different types of policy enforcement engines along the network path can provide flexibility to network administrators, it may be difficult and complicated to manually configure them using different management APIs. This is because it may be difficult and complicated for users to learn different terms associated with different policy enforcement engines and then manually configure them. In addition, when determining which of these enforcers (or policy enforcement engines) are suitable for a given network traffic flow based on the management API, there may be additional complexity involved. This is because when configuring a policy for managing a network traffic flow, the user may have to consider a complex set of attributes, such as network path efficiency, available network device resources, device performance, and other device-related capabilities. In addition, given the different variants in the network, manually configuring the policy enforcement engine may be a difficult task.

[0014] Some aspects described in the present application provide a technical solution to the above-mentioned technical problems by providing a system and method for automatically selecting a policy enforcement engine via a unified policy agent. For example, the system can normalize different terms, workflows and capabilities across different policy enforcement engines. The system can then provide a set of standardized workflows across different policy enforcement engines so that the system can automatically configure network policies on these engines that can interact and complement each other. In other words, a system can provide users with the flexibility of creating policy rules using the same service group or qualifier (e.g., application). The system can then automatically change the policy type or enforcer to a network ACL type enforcer or a distributed firewall type enforcer based on monitoring. In response to selecting a specific type of enforcer, the system can ensure that the created policy rules are presented with the correct implementation. Specifically, given a unified language or API for defining rules, the system can automatically switch back and forth between different implementations (e.g., east-west firewalls) given a common set of capabilities. The system can also verify that the rule can be applied to a new target enforcer, thereby allowing seamless migration between different enforcers.

[0015] Specifically, the system can automatically monitor the network to obtain information associated with different policy models (or APIs) associated with corresponding policy enforcement engines in the network. In other words, the system can obtain information about how each policy model in the policy model creates policies, defines policies, and defines policy rules, etc. Based on this information, the system can create a mapping between a unified policy model and different policy models. Such a unified policy model can provide a unified API for configuring and managing different policy enforcement engines with different policy models via a user interface.

[0016] In another aspect described in the present application, the system can dynamically monitor the network to obtain a set of attributes related to the network and the network devices residing in the network. These attributes can include different capabilities, performance characteristics, service enforcement options, resource availability associated with corresponding policy enforcement engines, path efficiency, etc. The system can automatically select one or more policy enforcement engines based on a unified policy model (or unified API) and the set of attributes to enforce a given set of policy rules in a manner that results in optimized policy enforcement for a given network service flow.

[0017] The phrase "policy enforcement engine" refers to the software and / or hardware components within a network device that can enforce a set of policy rules.

[0018] The phrases "policy enforcement engine" and "enforcer" are used interchangeably in this application.

[0019] System Architecture

[0020] Figure 1 An example network environment including a computer system for facilitating automatic policy engine selection using a unified policy agent according to one aspect of the present application is illustrated. Figure 1 In the example shown in , environment 100 shows a group of network devices or network apparatuses, such as network devices 110-114, residing in network 126. Network devices 110-114 (e.g., network switches) can implement networking policies based on corresponding policy enforcement engines. These networking policies can include a set of forwarding rules that can be applied to packets when certain matching criteria are met.

[0021] For example, one network device may support an ACL type policy enforcement engine, while another network device may support a firewall type policy enforcement engine. In addition, a firewall type policy enforcement engine may have policy-related functionality similar to an ACL type policy enforcement engine. However, each policy enforcement engine may be associated with an API of its own type (e.g., APIs 116-120). In other words, an API associated with a policy enforcement engine may include different terms and representations for policy functions when compared to another API for similar policy functions, e.g., a policy function may be associated with a policy, a policy enforcement selection (allow, deny, reject, etc.), a policy rule, a business specification, etc.

[0022] Manually managing and configuring these different policy enforcement engines associated with a particular API can be complex and difficult. This is because a user may have to have knowledge of the different terminology used across different policy enforcement engines for different and similar policy functions. In addition, a user may have to have knowledge of the capabilities at the network devices, available computing and memory resources, and path efficiencies along the network paths to be able to configure the appropriate policy enforcement engine to deliver network flows in an efficient manner with desired performance attributes.

[0023] One aspect described in the present application can provide a technical solution to the above-mentioned technical problem by providing a unified policy agent for facilitating the automatic selection of a policy enforcement engine. A unified policy agent with automatic policy engine selection 106 can facilitate the management of different policy enforcement engines using a unified API via a user interface 104. For example, a computer system 102 implementing element 106 can provide a single control point to configure various types of policies across different policy enforcement engines using a unified or single set of policy definitions and structural elements. In addition, a unified policy agent with automatic policy engine selection 106 can, in addition to providing a unified API, also adapt to differences that exist across policy enforcement engines, such as different capabilities, performance characteristics, business enforcement options, resource availability, etc.

[0024] In addition, element 106 can provide a unified API 122 via a user interface (UI) 104 associated with a display device 124 to configure and manage different policy enforcement engines. In one aspect of the present application, system 102 can provide a visualization to user 108 via a graphical user interface about how different policies can be enforced for a given network traffic flow across multiple policy enforcement engines. Element 106 can also determine and select a set of enforcers based on one or more attributes, such as the available computing resources at the network device, the efficiency of possible network paths taken by a given network traffic flow, the latency added to the network traffic, etc. Therefore, element 106 can use a unified policy agent to facilitate automatic selection of a policy enforcement engine without the need for a user to manually make such a selection to ensure optimized policy enforcement given a network traffic flow and policy. Refer to below. Figure 2-Figure 5 The operation of a unified policy agent with automatic policy engine selection 106 is described.

[0025] Figure 2 An example system architecture for facilitating automatic policy engine selection based on a unified policy agent according to one aspect of the present application is illustrated. Figure 2 , system architecture 200 may include a computer system 202 having an integrated controller or unified policy agent with automatic policy engine selection 106 for configuring and managing different policy enforcement engines associated with network devices in a network 240. Network 240 may include a set of interconnected network devices, such as 222, 228, and 234. At least two or more network devices in network 240 may include a policy enforcement engine. For example, network devices 222, 228, and 234 may include policy enforcement engines 226, 232, and 236, respectively.

[0026] The unified policy agent with automatic policy selection (UAPS) 206 may include a network monitoring module 210 that may implement monitoring mechanisms to provide broad visibility into various attributes associated with the network 240, such as: virtual networking infrastructure running on the servers; other kinds of data that may help determine the paths taken by network traffic; configuration information associated with servers, network devices, and other configuration information associated with virtual networking.

[0027] The network monitoring module 210 can also monitor and retrieve: information associated with the capabilities and resource availability of network devices residing in the network; information related to the efficiency of the network path based on different policy enforcement engines along the network path, etc. For example, a network switch supporting an ACL type policy enforcement engine can provide limited resource capabilities, but a network device supporting a firewall type policy enforcement engine can support a large number of policy rules, such as policy rules of the order of thousands or millions, and can therefore provide enhanced resource capabilities. In addition, the network monitoring module 210 can retrieve network information that can provide end-to-end visibility, for example, monitoring the path taken by the network business so that the UAPS 206 can apply specific policy rules. For example, the UAPS 206 can determine different types of policy enforcement engines that exist along the path between the first virtual machine on the first host and the second virtual machine on the second host for a given network business flow. The UAPS 206 can then select one or more policy enforcement engines along the network path to apply specific policy rules for managing network business that traverses from the first virtual machine to the second virtual machine. The network monitoring module 210 may not be limited to monitoring the above-mentioned attributes, but may also be extended to provide visibility into the virtual machine networking stack and other network attributes, which may provide an improved perspective on the network environment to determine optimized selections for the policy enforcement engine.

[0028] In addition, the network monitoring module 210 can be used as a sensor to monitor the live changes in the network and network devices, that is, dynamic and real-time changes. In other words, the network monitoring module 210 can monitor the network to retrieve the information desired for automatically selecting one or more policy enforcement engines to provide optimized policy enforcement. The optimized policy enforcement can indicate that the enforcement of a set of policy rules by the selected policy enforcement engine can cause the optimized performance in terms of resource utilization, path efficiency, the delay involved, and other performance characteristics. For example, UAPS 206 can provide optimized performance when some performance standards are met. The performance standard can be related to ensuring that the enforcement of a policy rule by a policy enforcement engine does not conflict with another policy rule enforced by another policy enforcement engine; ensuring that the allocation of one or more policy rules among different policy enforcement engines along the network path for a given network traffic flow causes improved path efficiency; ensuring that the amount of delay added by the selected policy enforcement engine is lower than the delay threshold, etc.

[0029] Each policy enforcement engine has its own user interface and API. For example, policy enforcement engines 226, 232 and 236 can be associated with API 224, 230 and 238 respectively. API 224 associated with policy enforcement engine 226 can use specific terms for defining policy functions, such as policy rules, business specifications, enforcement selections, such as allow, deny, reject, etc. API 230 associated with policy enforcement engine 232 can use different terms for similar policy functions. In existing systems, users can apply policy enforcement engine-specific APIs to configure policy enforcement engines. In other words, it is expected that users understand the different terms and definitions used across different APIs for similar policy functions on different policy enforcement engines to be able to configure the policy enforcement engine.

[0030] In addition, due to the diverse set of APIs, users may find it difficult and complex to understand how different policy functions associated with different policy enforcement engines interact and / or relate to each other. Understanding such interrelationships between different policy enforcement engines that exist along a network path can be relevant to ensuring that the operations of the policy enforcement engines do not conflict with each other. In other words, a user can configure an ACL-type policy enforcement engine in a first network device to allow network traffic to be forwarded to a second network device. If the second network device is a firewall device, the user may have to ensure that the firewall-type policy enforcement engine is not configured to block network traffic.

[0031] As different types of policy enforcement engines increase in a network environment, each with its own interface and API, manual configuration and management of the policy enforcement engines can become difficult and complex. For example, because different types of policy enforcement engines can exist along an end-to-end physical or logical network, a user may have to go to each of these infrastructures and understand which types of policies can be associated with each other so that uniform and consistent policy enforcement is applied along the network path associated with the network traffic.

[0032] The unified policy model module 212 can provide a unified API that can be applied via the user interface 204 to configure and manage different types of policy enforcement engines deployed in the network environment, thereby enabling users to interact with different types of policy enforcement engines using a single control point or unified API. The UAPS 206 can apply the unified policy model module 212 to translate different descriptions or representations for similar policy functions into a unified description.

[0033] In other words, using a unified API and a single user interface, users can configure and manage different types of policy enforcement engines without the burden of learning and understanding different terminology used across different APIs. Specifically, the unified policy model module 212 can convert different terminology associated with different policy enforcement engines and their corresponding APIs into unified terminology based on information obtained by the network monitoring module 210, that is, translate the different terminology into a unified representation.

[0034] For example, the unified policy model module 212 can obtain existing policy definitions configured for different network devices in the network environment (wherein each network device provides different policy enforcement engines) and can create a mapping between the unified policy model and the different policy models associated with the corresponding policy enforcement engines. Such a unified policy model can be used to provide a unified API for configuring and managing different policy enforcement engines via a user interface. In other words, the unified policy model module 212 can create a unified object model for various policy enforcement engines that perform similar policy functions. In addition, the unified policy model module 212 can also adapt to and retain some differences in the relevant differences that exist among different policy enforcement engines, such as performance characteristics, business enforcement options, capabilities, etc.

[0035] The unified policy model module 212 can provide a unified policy agent, which can enable users to use a single control point or a unified API to configure and manage different policy enforcement engines. However, users may have to understand a complex set of attributes, such as network path efficiency, available network device resources, device performance, and other capabilities, to configure and manage different policy enforcement engines. In addition, given the potential changes in the network, it can be difficult to manually perform the configuration. In one aspect of the present application, the UAPS 206 can also include a mechanism that can automatically configure and manage different policy enforcement engines available in the network 240. For example, the UAPS 206 can apply the policy engine selection module 214 to automatically analyze the information retrieved by the network monitoring module 210, such as information related to the resources available at the network device (e.g., the amount of memory), the delay along the network path, the virtual machine along the network path, the path efficiency of the different policy enforcement engines given along the network path, etc.

[0036] In one aspect, the policy engine selection module 214 can determine the different types of policy enforcement engines that exist along the network path for a given network traffic flow based on information obtained from the network monitoring module 210 and the unified policy model module 212. For example, for a given network traffic flow, the network path may include a firewall type policy enforcement engine at one end and may not include such a firewall type policy enforcement engine at the other end, in which case the policy engine selection module 214 can determine other policy enforcement engines that the network traffic may traverse and select one or more policy enforcement engines to provide the desired policy enforcement.

[0037] In another example, network traffic may traverse a specific network path that includes an ACL type policy enforcement engine and a firewall type policy enforcement engine. In such a case, the policy engine selection module 214 may determine that a firewall type enforcement engine is suitable for a given type of network traffic and traffic flow based on information retrieved by the network monitoring module 210 and the unified API.

[0038] In another example, when the user specifies a layer 2 level of network traffic, the policy engine selection module 214 may select an ACL type enforcer instead of a firewall type enforcer because a firewall network device may support layer 3 from the networking concept.

[0039] In addition, the policy engine selection module 214 can select one or more policy enforcement engines based on the various attributes retrieved by the network monitoring module 210 to ensure that a given network traffic flow is delivered in an efficient manner with desired performance attributes. Therefore, the policy engine selection module 214 can apply different factors to select the appropriate enforcer for a given network traffic flow.

[0040] In another example, when there is a large amount of movement about a virtual machine, for example, a virtual machine migrates from one host to another in a data center, existing systems may often find it difficult to track such movement. In one aspect of the present application, the policy engine selection module 214 may apply different network attributes derived from the network (by the network monitoring module 210) to determine the current location of the virtual machine, and may then apply the appropriate policy rules associated with the policy enforcement engine deployed on the virtualized host and applicable to a given virtual machine. Therefore, UAPS206 may dynamically react to changes occurring in a given network environment. In other words, UAPS206 may dynamically move the enforcement point for a given policy from one location to another depending on the dynamic changes in the network and the movement of the virtual machine. The enforcement point may correspond to a network device interface, at which a policy enforcement engine may be used to enforce a given policy. For example, in a network switch, an ACL type policy enforcement engine may enforce an ACL type policy corresponding to a network switch interface (e.g., corresponding to a switch port). Typically, a networking policy may be created and applied to a network device interface, wherein the interface represents a physical enforcement point.

[0041] The policy engine selection module 214 can select one or more enforcers along an efficient path for a given network traffic flow and policy. For example, a user may desire communication between two specific groups of virtual machines residing on their respective virtualization hosts. In such a case, the user can create a suitable policy to enable such communication between groups of these virtual machines, and the policy engine selection module 214 can determine which enforcement point will be optimal for enforcing a given policy.

[0042] In one example, given a virtual machine associated with a virtualization host, UAPS 206 can determine at which switch port a given policy should be applied. However, if UAPS 206 determines that there is a firewall network device along the network path for a given network traffic flow, and the network switch connected to the virtualization host does not provide firewall-type policies, UAPS 206 can apply the given policy at the firewall network device instead of at the network switch.

[0043] In one aspect of the present application, a user may create policies to be applied and provide these policies to UAPS 206, for example, via user interface 204. UAPS 206 may then determine the best enforcement point to send these policies into the network environment for a given network traffic flow.

[0044] The configuration module 216 can configure the policy enforcement engines, i.e., 226, 232, and 236, on the network devices 222, 228, and 234, respectively, based on the unified API 208. For example, in response to the policy selection module 214 selecting a policy enforcement engine (e.g., the policy enforcement engine 232 associated with the network device 228) for enforcing a given policy, the configuration module 216 can send an API command based on the unified API 208 to the corresponding network device to add the given policy in a policy lookup table maintained at the network device 228. In another example, if the policy enforcement engine is to be deactivated, the configuration module 216 can send an API command to edit or remove an entry in the corresponding policy lookup table so that the network device including the policy enforcement engine does not serve as an enforcement point for applying the given policy.

[0045] In one aspect of the present application, the UAPS 206 can apply the unified policy model module 212 to convert the unified API commands into API commands specific to the policy enforcement engine.

[0046] Figure 3A An example network configuration with a selected first set of policy engines according to one aspect of the present application is illustrated. Figure 3A The example shown in illustrates a simple network configuration with multiple enforcement points where network policies can be enforced. Network ACLs can be configured on one or more switches (e.g., network switches 302-306). In other words, network switches 302-306 can be associated with ACL type policy enforcement engines 318-322, respectively. Firewall rules can be configured on firewall network device 308, that is, associated with firewall type policy enforcement engine 324. These policy enforcement engines can have different attributes. For example, switch ACLs may typically be limited in number but may have very low latency, and firewall devices may have much larger resource constraints but may have higher latency. Therefore, certain network traffic flows can traverse enforcers with different capabilities.

[0047] refer to Figure 3A , network switch 302 and network 306 may have a set of ACL capabilities, while network switch 304 may have a different set of capabilities in terms of available resources and performance characteristics. Given such a network environment or configuration (generally, network environments are complex and may include a large number of interconnected network devices), it may be desirable to determine an optimal set of enforcers for a given network traffic flow (e.g., from server 310 to server 314). The dotted lines from UAPS 316 to network devices 302-308 indicate that UAPS 316 can monitor, configure, and manage different policy enforcement engines.

[0048] One aspect described in the present application provides an automated UAPS 316 that can query the enforcers associated with the network switches 302-306 and the firewall network device 308 for their attributes (or can have those attributes encoded in the UAPS 316). In addition, given a network traffic flow for which enforcement is to be provided, the UAPS 316 can configure the enforcers in an efficient manner to pass the given network traffic flow with the desired performance attributes. In this example, the UAPS 316 can determine that for the first network traffic flow, the best option can be to apply ACLs on the network switches 302 and 306, that is, to apply ACL-type policy enforcement engines 318 and 322. This is because the UAPS 316 can determine that the policy enforcement engines 318 and 322 along the network path for the first network traffic flow can use scarce resources (network switch ACLs) but will provide very low latency flows.

[0049] Figure 3B An example network configuration with a selected second set of policy engines according to one aspect of the present application is illustrated. Figure 3B The example shown in Figure 3A 330-336. The dotted lines from UAPS 344 to network devices 330-336 indicate that UAPS 344 can monitor, configure, and manage different policy enforcement engines. UAPS 344 can determine that for the second network traffic flow, the most efficient path may be to direct the traffic through firewall network device 336 to provide the desired policy enforcement by applying policy enforcement engine 352.

[0050] Depending on the given network traffic, relevant performance characteristics, and available resources, ( Figure 3B UAPS 344 and ( Figure 3A The UAPS 316 in the example of FIG. 316 can create complex and interrelated configurations. The UAPS (316 and 344) can also automatically react to changing network characteristics and can modify policy configurations where appropriate to meet these dynamic changes in the network environment. Performing the above tasks manually can be complex, time-consuming, and difficult, so the UAPS (316 and 244) uses a unified policy agent to facilitate automatic selection of a policy enforcement engine.

[0051] Figure 4A A flowchart illustrating an example process for creating a unified policy agent according to one aspect of the present application is presented. Figure 4A400, during operation, the system can dynamically monitor the network (operation 402) to capture information associated with different policy enforcement engines. Based on the monitoring, the system can receive configuration information associated with different policy enforcement engines in the network (operation 404).

[0052] The system can learn different representations corresponding to a group of similar policy definitions of different policy enforcement engines across the network based on the configuration information (operation 406). The system can also learn different representations corresponding to groups of different capabilities, which are associated with corresponding policy enforcement engines. The system can then convert the different representations of the set of policy rules into a unified representation to create a unified policy model (operation 408). For example, the system can map the different representations corresponding to the set of similar policy definitions to a unified representation. The system can then map the different representations corresponding to the group of different capabilities to multiple unified representations, thereby retaining the useful differences existing among different policy enforcement engines. The system can create a unified policy model or a unified policy agent based on different mappings, thereby providing a unified API to the user via a user interface. Such a conversion can be desired so that the system can apply a unified policy model via a user interface to configure different policy enforcement engines (operation 410), and the operation then returns.

[0053] Figure 4B A flowchart illustrating an example process for performing automatic policy engine selection based on a unified policy agent according to one aspect of the present application is presented. One aspect described in the present application can provide an automatic policy selection engine that can automatically select one or more policy enforcement engines present along a network path based on a unified policy agent without requiring a user to manually select these policy enforcement engines.

[0054] refer to Figure 4BIn the flowchart 430 in FIG. 4 , the system can dynamically monitor a given network (operation 432) and can receive a set of attributes associated with the network (operation 434). For example, the set of attributes can include network-related attributes and network device-related attributes. Network device-related attributes can include the amount of memory available at the network device, the processing resource capacity at the network device, the number of policy rules supported by the policy enforcement engine associated with the network device, and the amount of latency that the network device can add to the network flow. Network-related attributes can include the efficiency of possible network paths taken by a given network traffic flow, different types of policy enforcement engines that exist along possible network paths, and the current location of a host that can be associated with one or more virtual machines under consideration. These network device-related attributes and network-related attributes can be related to determining whether an enforcement point can be enabled at one or more network devices along the network path taken by a given network traffic flow, and whether enabling the enforcement point can cause optimized policy enforcement for a given set of policy rules.

[0055] The system may determine, based on a set of attributes and the unified policy model, the assignment of one or more given policy rules to different network devices for enforcement by corresponding policy enforcement engines (operation 436). Figure 4A 430. The system may then determine whether such assignment of policy rules results in optimized policy enforcement (operation 438). For example, a first network device along a network path for a given network flow may support an ACL type policy enforcement engine, and a second network device along the network path may support a firewall type policy enforcement engine. The firewall type policy enforcement engine may include similar functionality as in an ACL type policy enforcement engine. The system may determine which type of policy enforcement engine may be activated or deactivated based on the set of attributes to achieve optimized policy enforcement.

[0056] For example, the set of attributes that the system can apply can include possible network paths taken by a given traffic flow, different types of infrastructure that can exist along the network path, different types of policy enforcement engines that exist along the network path, resource limitations (e.g., the number of ACLs that an ACL-type policy enforcement engine can provide), etc. In one example, the system can select a firewall-type policy enforcement engine if that choice is the best option for applying policy rules along the network path with optimal efficiency. The system can make such a choice because a firewall-type policy enforcement engine can provide a large amount of storage resources to accommodate a large group of policy rules. In another example, the system can configure an ACL-type policy enforcement engine with a first subset of policy enforcement rules and configure a firewall-type policy enforcement engine with a second subset of policy rules.

[0057] When the system determines that the conditions in operation 438 are met, the system can activate the policy enforcement engine that has been selected to apply the assigned policy rules (operation 440) and the operation returns. Activating the policy enforcement engine can involve sending one or more API commands to the policy enforcement engine to add the assigned policy rules to the policy lookup table. In one aspect, the system can apply a unified policy agent to generate one or more API commands specific to the policy enforcement engine. In other words, when generating one or more API commands, the system can convert the unified representation into a policy enforcement engine-specific representation. When the system determines that the conditions in operation 438 are not met, the system can deactivate one or more policy enforcement engines that may not contribute to optimized policy enforcement (operation 442) and the operation returns. Deactivating the policy enforcement engine can involve sending one or more API commands to the policy enforcement engine to remove one or more policy rules from the policy lookup table.

[0058] Computer system for facilitating automatic policy engine selection

[0059] Figure 5 An example computer system for facilitating automatic policy engine selection based on a unified policy agent according to one aspect of the present application is illustrated. In this example, a computer system 500 may include a processor 502, a memory 504, and a storage device 506. The computer system 500 may be coupled to a peripheral input / output (I / O) user device 516, such as a display device 508, a keyboard 510, and a pointing device 512. The storage device 506 may store instructions for operating the system 518, the automatic policy engine selection system 520, and data 532. The data 532 may include any data that is desired as input or generated as output by the methods and / or processes described in the present disclosure. The computer system 500 may be coupled to a network 514 via one or more network interfaces.

[0060] In one aspect of the present application, the automatic policy engine selection system 522 may include instructions that, when executed by the processor 502, may cause the computer system 500 to perform the methods and / or processes described in the present disclosure. The automatic policy engine selection system 520 may include a communication module 522 for sending network packets to other nodes in the network 514 via one or more network interfaces. The communication module 522 may also receive / obtain network packets from other network nodes in the network 514 via one or more network interfaces. The automatic policy engine selection system 520 may also include instructions for implementing a network monitoring module 524 for monitoring the network 514 and network devices residing in the network 514. In addition, the network monitoring module 524 may apply the communication module 522 to receive configuration information and a set of attributes associated with the network 514 being monitored.

[0061] The automatic policy engine selection system 520 may include a unified policy module 526 to determine a unified representation of a set of policy definitions. In other words, the policy enforcement engines associated with the corresponding network devices in the network 514 can be configured using a specific API, that is, different policy enforcement engines can be configured using different APIs. Each API may include different representations or descriptions of a set of policy definitions. For example, a first API associated with a first policy enforcement engine can provide a first representation of a policy definition (e.g., a policy rule), while a second API associated with a second policy enforcement engine can provide a second representation of a similar policy rule. Typically, a network may include multiple policy enforcement engines and multiple APIs. Configuring such a policy enforcement engine using different APIs can be complex and difficult.

[0062] The automatic policy engine selection system 520 can apply a unified policy module 526 to convert these different representations of policy definitions of different policy enforcement engines across the network into a unified representation or unified API. In other words, the unified policy module 526 can generate: a first type of mapping between different representations of similar policy definitions and a unified policy representation; and a second type of mapping between a set of different representations of different capabilities of the policy enforcement engine and a set of unified representations, rather than mapping such capability differences to a single unified representation. The first type of mapping provides a unified representation for different representations of similar policy functions, while the second type of mapping retains the differences in capabilities (e.g., performance characteristics, business enforcement options, etc.) that exist among different policy enforcement engines. Such a unified API can correspond to a unified policy agent that can be applied to configure different policy enforcement engines.

[0063] The automatic policy engine selection system 520 can apply a policy engine selection module 528 to determine based on the unified policy agent and the set of attributes: assigning a given subset of policy rules to one or more policy enforcement engines in the network 514 for enforcement will result in optimized policy enforcement. The policy engine selection module 528 can then select a policy enforcement engine to enforce the corresponding subset of the given policy rules. The configuration module 530 can configure the selected policy enforcement engines so that they can enforce the assigned policy rules. In one aspect, when a policy enforcement engine along a network path is not selected, the configuration module 530 can configure it in a manner that the policy enforcement engine does not enforce the unassigned subset of the given policy rules.

[0064] One aspect described in the present application can provide a system and method for facilitating automatic policy engine selection. During operation, the system can monitor a network including a group of network devices. The system can receive a set of attributes associated with the network based on monitoring. At least two network devices are equipped with different policy enforcement engines for enforcing one or more given policy rules. The system can apply a unified policy model to determine the allocation of one or more given policy rules to a first policy enforcement engine and a second policy enforcement engine based on the set of attributes to provide optimized policy enforcement. The system can then select one or both of the first policy enforcement engine and the second policy enforcement engine based on the allocation. The system can activate the selected one or both policy enforcement engines for enforcing one or more given policy rules.

[0065] In one variation on this aspect, the set of attributes includes one or more of the following network device-related attributes: the amount of memory available at the corresponding network device; the processing resource capabilities at the network device; the number of policy rules supported by a policy enforcement engine associated with the network device; and the latency added to a given network traffic flow.

[0066] In one variation on this aspect, the set of attributes includes one or more of the following network device-related attributes: efficiency of possible network paths taken by a given network traffic flow; different types of policy enforcement engines along the possible network paths; and current location(s) of one or more hosts corresponding to one or more virtual machines.

[0067] In a variation on this aspect, the system may create a unified policy model based on the set of attributes, comprising: receiving configuration information at a controller from a set of network devices residing in the network, wherein at least two of the network devices are equipped with different policy enforcement engines, wherein each policy enforcement engine is associated with a different application programming interface (API), wherein the API provides different representations of similar policy functions; determining different representations corresponding to a set of similar policy functions based on the configuration information; and performing a first mapping from the different representations corresponding to the set of similar policy functions to a single unified representation.

[0068] In a variation on this aspect, the system may determine different representations corresponding to a set of different capabilities across policy enforcement engines based on the configuration information. The system may perform a second mapping from the different representations corresponding to the set of different capabilities to a plurality of unified representations. In addition, the system may create a unified API including a first unified representation and a set of unified representations based on the first mapping and the second mapping. The system may then apply the unified API to configure and manage different policy enforcement engines in the network.

[0069] In a variation on this aspect, the system may activate the selected one or two policy enforcement engines for enforcing one or more given policy rules by sending one or more commands to the selected (multiple) policy enforcement engines based on the assignment to add the one or more given policy rules to a policy lookup table associated with the corresponding network device.

[0070] In a variation on this aspect, the system may apply a unified policy model to determine, based on a set of attributes, assignment of one or more given policy rules to a first policy enforcement engine and a second policy enforcement engine for providing optimized policy enforcement by: determining, based on the set of attributes and the given policy rules, that assigning the first policy rule to the first policy enforcement engine and assigning the second policy rule to the second policy enforcement engine results in optimized policy enforcement, wherein the optimized policy enforcement indicates that enforcement of the given policy rule by the corresponding policy enforcement engine satisfies one or more performance criteria.

[0071] In one variation on this aspect, the performance criteria may include one or more of the following: enforcement of a first policy rule by one policy enforcement engine does not conflict with enforcement of a second policy rule by another policy enforcement engine; distribution of one or more policy rules among different policy enforcement engines along a network path for a given network traffic flow provides improved path efficiency; and an amount of latency added by a selected policy enforcement engine is below a latency threshold.

[0072] In another variation, the system may, in response to determining that enforcement of at least one policy rule by the policy enforcement engine does not provide optimized policy enforcement, cause the policy enforcement engine to cease enforcing the policy rule.

[0073] In another variation, the system may deactivate the policy enforcement engine from enforcing the policy rule by sending one or more API commands to the policy enforcement engine to remove the policy rule from a policy lookup table in the corresponding network device.

[0074] The methods and processes described in the detailed description section may be embodied as code and / or data, which may be stored in a computer-readable storage medium as described above. When a computer system reads and executes the code and / or data stored on the computer-readable storage medium, the computer system executes the methods and processes embodied as data structures and codes and stored in the computer-readable storage medium.

[0075] In addition, the methods and processes described above may be included in hardware modules or devices. Hardware modules or devices may include, but are not limited to, ASIC chips, field programmable gate arrays (FPGAs), dedicated or shared processors that execute a specific software module or a piece of code at a specific time, and other programmable logic devices now known or later developed. When the hardware modules or devices are activated, they execute the methods and processes included in them.

[0076] The foregoing descriptions of various aspects have been presented for purposes of illustration and description. They are not intended to be exhaustive or to limit the scope of the present disclosure to the forms disclosed. Therefore, many modifications and variations will be apparent to those skilled in the art.

Claims

1. A computer-implemented method comprising: A network including a group of network devices is monitored by a controller; receiving a set of attributes associated with the network based on the monitoring; Creating a unified policy model based on the set of attributes, wherein creating the unified policy model comprises: receiving, at the controller, configuration information from the set of network devices, wherein at least two of the network devices are equipped with different policy enforcement engines, wherein each policy enforcement engine is associated with a different application programming interface (API), wherein the API provides different representations of similar policy functions; wherein the at least two network devices are respectively equipped with a first policy enforcement engine and a second policy enforcement engine for enforcing one or more given policy rules; applying the unified policy model to determine, based on the set of attributes, assignment of the one or more given policy rules to the first policy enforcement engine and the second policy enforcement engine for providing optimized policy enforcement; Based on the assignment, selecting one or both of the first policy enforcement engine and the second policy enforcement engine; and The selected one or both policy enforcement engines are activated by the controller for enforcing the one or more given policy rules.

2. The computer-implemented method of claim 1 , wherein the set of attributes includes one or more of the following network device-related attributes: an amount of memory available at the respective network device; processing resource capabilities at the network device; a number of policy rules supported by a policy enforcement engine associated with the network device; as well as The delay added to a given network traffic flow.

3. The computer-implemented method of claim 1 , wherein the set of attributes includes one or more of the following network-related attributes: the efficiency of possible network paths taken by a given network traffic flow; different types of policy enforcement engines along the possible network paths; and One or more current locations of one or more hosts corresponding to the one or more virtual machines.

4. The computer-implemented method of claim 1 , wherein creating the unified policy model further comprises: Based on the configuration information, determining different representations corresponding to a set of similar policy functions; as well as A first mapping is performed from the different representations corresponding to the set of similar policy functions to a single unified representation.

5. The computer-implemented method of claim 4, further comprising: determining, based on the configuration information, different representations corresponding to a different set of capabilities across the policy enforcement engine; performing a second mapping from the different representations corresponding to the set of different capabilities to a plurality of unified representations; creating the unified policy model based on the first mapping and the second mapping, the unified policy model comprising the single unified representation and the multiple unified representations; as well as The unified policy model is applied to configure and manage the different policy enforcement engines in the network.

6. The computer-implemented method of claim 1 , wherein activating, by the controller, the selected one or both policy enforcement engines for enforcing the one or more given policy rules comprises: Based on the assignment, one or more commands are sent to the selected one or both policy enforcement engines to add the one or more given policy rules in a policy lookup table associated with the corresponding network device.

7. The computer-implemented method of claim 1 , wherein applying the unified policy model to determine the assignment of the one or more given policy rules to the first policy enforcement engine and the second policy enforcement engine based on the set of attributes for providing the optimized policy enforcement further comprises: Based on the set of attributes and the given policy rule, determining that assigning the first policy rule to the first policy enforcement engine and assigning the second policy rule to the second policy enforcement engine results in optimized policy enforcement, wherein the optimized policy enforcement indicates that enforcement of the given policy rule by the corresponding policy enforcement engine satisfies one or more performance criteria.

8. The computer-implemented method of claim 7, wherein the performance criteria include one or more of: A first policy rule enforced by one policy enforcement engine does not conflict with a second policy rule enforced by another policy enforcement engine; distribution of the one or more policy rules among the different policy enforcement engines along a network path for a given network traffic flow provides improved path efficiency; and The amount of latency added by the selected policy enforcement engine is below a latency threshold.

9. The computer-implemented method of claim 1 , further comprising: In response to determining that enforcement of at least one policy rule by a policy enforcement engine does not provide the optimized policy enforcement, the policy enforcement engine is deactivated from enforcing the policy rule.

10. The computer-implemented method of claim 9, wherein deactivating the policy enforcement engine from enforcing the policy rule comprises sending one or more API commands to the policy enforcement engine to remove the policy rule from a policy lookup table in a corresponding network device.

11. A computer system comprising: processor; a memory coupled to the processor and storing instructions that, when executed by the processor, cause the processor to perform a method comprising: A network including a group of network devices is monitored by a controller; receiving a set of attributes associated with the network based on the monitoring; Creating a unified policy model based on the set of attributes, wherein creating the unified policy model comprises: receiving, at the controller, configuration information from the set of network devices, wherein at least two of the network devices are equipped with different policy enforcement engines, wherein each policy enforcement engine is associated with a different application programming interface (API), wherein the API provides different representations of similar policy functions; wherein the at least two network devices are respectively equipped with a first policy enforcement engine and a second policy enforcement engine for enforcing one or more given policy rules; applying a unified policy model to determine, based on the set of attributes, assignment of the one or more given policy rules to the first policy enforcement engine and the second policy enforcement engine for providing optimized policy enforcement; Based on the assignment, selecting one or both of the first policy enforcement engine and the second policy enforcement engine; and The selected one or both policy enforcement engines are activated by the controller for enforcing the one or more given policy rules.

12. The computer system of claim 11, wherein the set of attributes comprises one or more of the following network device related attributes: an amount of memory available at the respective network device; processing resource capabilities at the network device; a number of policy rules supported by a policy enforcement engine associated with the network device; as well as The delay added to a given network traffic flow.

13. The computer system of claim 11, wherein the set of attributes includes one or more of the following network-related attributes: the efficiency of possible network paths taken by a given network traffic flow; different types of policy enforcement engines along the possible network paths; and One or more current locations of one or more hosts corresponding to the one or more virtual machines.

14. The computer system of claim 11, wherein creating the unified policy model further comprises: Based on the configuration information, determining different representations corresponding to a set of similar policy functions; as well as A first mapping is performed from the different representations corresponding to the set of similar policy functions to a single unified representation.

15. The computer system of claim 14, wherein the method further comprises: determining, based on the configuration information, different representations corresponding to a different set of capabilities across the policy enforcement engine; performing a second mapping from the different representations corresponding to the set of different capabilities to a plurality of unified representations; creating the unified policy model based on the first mapping and the second mapping, the unified policy model comprising the single unified representation and the multiple unified representations; as well as The unified policy model is applied to configure and manage the different policy enforcement engines in the network.

16. The computer system of claim 11, wherein activating, by the controller, the selected one or both policy enforcement engines for enforcing the one or more given policy rules comprises: Based on the assignment, one or more commands are sent to the selected one or more policy enforcement engines to add the one or more given policy rules in a policy lookup table associated with the corresponding network device.

17. The computer system of claim 11, wherein applying the unified policy model to determine the assignment of the one or more given policy rules to the first policy enforcement engine and the second policy enforcement engine based on the set of attributes for providing the optimized policy enforcement further comprises: Based on the set of attributes and the given policy rule, determining that assigning the first policy rule to the first policy enforcement engine and assigning the second policy rule to the second policy enforcement engine results in optimized policy enforcement, wherein the optimized policy enforcement indicates that enforcement of the given policy rule by the corresponding policy enforcement engine satisfies one or more performance criteria.

18. The computer system of claim 17, wherein the performance criteria include one or more of the following: A first policy rule enforced by one policy enforcement engine does not conflict with a second policy rule enforced by another policy enforcement engine; distribution of the one or more policy rules among the different policy enforcement engines along a network path for a given network traffic flow provides improved path efficiency; and The amount of latency added by the selected policy enforcement engine is below a latency threshold.

19. The computer system of claim 11, wherein the method further comprises: In response to determining that enforcement of at least one policy rule by a policy enforcement engine does not provide the optimized policy enforcement, the policy enforcement engine is deactivated from enforcing the policy rule.

20. The computer system of claim 19, wherein deactivating the policy enforcement engine from enforcing the policy rule comprises sending one or more API commands to the policy enforcement engine to remove the policy rule from a policy lookup table in a corresponding network device.

Citation Information

Patent Citations

  • Automated generation of label-based access control rules

    CN105684391A

  • Generating a network-wide logical model for network policy analysis

    CN110710160A