Change effect simulation analysis

The network change simulation method addresses the complexity of VPC network management by simulating parameter changes in a Virtual Private Cloud, allowing for predictive analysis and efficient network configuration adjustments.

JP2025072390AActive Publication Date: 2025-05-09GOOGLE LLC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2025005613
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2020-12-02
Filing Date
2025-01-15
Publication Date
2025-05-09
Estimated Expiration
2041-11-04

Smart Images

  • Figure 2025072390000001_ABST
    Figure 2025072390000001_ABST
Patent Text Reader

Abstract

To provide a method and system for network change simulation.SOLUTION: In a system 10, a cloud network 200 includes data processing hardware 204 and memory hardware 206 for communicating with the data processing hardware. The memory hardware stores a command for causing the data processing hardware to execute operations. The operations include: receiving one or more parameter changes 84 to a production network model 354 of the cloud network; generating a simulation network model 356 including one or more parameter changes; analyzing a simulated network flow 362 in the simulation network model; generating a report; and simulating a production workflow of a production network log 322 in the simulation network model to generate a simulated network log.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present disclosure relates to change impact simulation analysis in cloud networks. Summary of the Invention [Problem to be solved by the invention]

[0002] background A virtual private cloud (VPC) is a public cloud. A VPC is an on-demand, configurable pool of shared computing resources allocated within a cloud environment. A VPC isolates users from other cloud users. A VPC provides a virtual private network (VPN) to allow users to A VPC can run one or more virtual machines (VMs) that can communicate with a remote network or other remote resources. A VPC can contain any number of VMs, networks, Due to its size and complexity, a VPC often requires significant network configuration to operate and maintain. [Means for solving the problem]

[0003] overview Certain aspects of the present disclosure provide a method for simulating network changes. The method includes receiving, in data processing hardware, one or more parameter changes to a production network model of a network. The method further includes the data processing hardware generating a simulated network model including the one or more parameter changes. The method further includes the data processing hardware analyzing simulated network flows in the simulated network model and the data processing hardware generating a report including an impact of the parameter changes on the network.

[0004] This aspect of the disclosure may include one or more of any of the following features. In some examples, the method further includes receiving, at the data processing hardware, a production network log including a recorded workflow for the production network model, and the data processing hardware simulating the production workflow of the production network log in the simulated network model to generate a simulated network log. In some examples, analyzing the simulated network flow includes the data processing hardware comparing the production network log to the simulated network log, and the data processing hardware identifying differences between the production network log and the simulated network log. Optionally, the production network log is one of a virtual private connection flow log and a firewall rule log.

[0005] In some examples, the method may include the data processing hardware determining an impact of a proposed parameter change on the production network model, where determining the impact of the proposed parameter change may include determining an impact on at least one of network reachability, firewall shadow rules and predicted firewall hit rates, search intent rules, security compliance rules, and resource quota and utilization rates.

[0006] In some configurations, generating the simulation network model includes data processing hardware incrementally incorporating one or more proposed parameter changes into the production network model. In some examples, the method further includes the data processing hardware incrementally incorporating one or more proposed parameter changes into the production network model. , receiving one or more immutable parameters of the production network model. The method may further include, if an impact of the parameter changes on the network is acceptable, the data processing hardware altering a configuration of the network.

[0007] Another aspect of the present disclosure provides a system. The system includes data processing hardware and memory hardware in communication with the data processing hardware. The memory hardware stores instructions that, when executed by the data processing hardware, cause the data processing hardware to perform operations. The operations include receiving one or more parameter changes to a production network model of a network. The operations further include generating a simulated network model that includes the one or more parameter changes. Another operation includes analyzing a simulated network flow in the simulated network model. The operations further include generating a report that includes an impact of the parameter changes on the network.

[0008] This aspect of the disclosure may include one or more of any of the following features: In one example, an operation includes receiving a production network log including a recorded workflow for a production network model. Another operation includes simulating the production workflow of the production network log in a simulated network model to generate a simulated network log. Here, analyzing the simulated network flow may include comparing the production network log to the simulated network log and identifying differences between the production network log and the simulated network log. Optionally, the production network log is one of a virtual private connection flow log and a firewall rule log.

[0009] In some configurations, the operations further include determining an impact of the proposed parameter change on the production network model, where determining the impact of the proposed parameter change includes determining an impact on at least one of network reachability, firewall shadow rules and predicted firewall hit rates, search intent rules, security compliance rules, and resource quota and utilization rates.

[0010] In some examples, generating the simulation network model includes data processing hardware incrementally incorporating one or more proposed parameter changes into the production network model. In some implementations, the operations further include the data processing hardware receiving one or more immutable parameters of the production network model. In some configurations, the operations include altering a configuration of the network if an impact of the parameter changes on the network is acceptable.

[0011] Another aspect of the disclosure is a computer program product encoded on a non-transitory computer readable medium including instructions that, when executed by a data processing apparatus, cause the data processing apparatus to perform operations. The operations include receiving one or more parameter changes to a production network model of the network. Another operation includes generating a simulated network model including the one or more parameter changes. The operations include receiving the one or more changes to the production network model of the network. The operations further include generating a simulated network model including the one or more parameter changes. Another operation includes analyzing a simulated network flow in the simulated network model. The operations further include generating a report including an impact of the parameter changes on the network.

[0012] This aspect of the disclosure may include one or more of any of the following features. In one example, the operations include a production network log that includes a recorded workflow for a production network model. Another operation includes simulating a production workflow of the production network log in a simulated network model to generate a simulated network log, where analyzing the simulated network flow includes comparing the production network log with the simulated network log and identifying differences between the production network log and the simulated network log. Optionally, the production network log is one of a virtual private connection flow log and a firewall rule log.

[0013] In some configurations, the operations further include determining an impact of the proposed parameter change on the production network model, where determining the impact of the proposed parameter change includes determining an impact on at least one of network reachability, firewall shadow rules and predicted firewall hit rates, search intent rules, security compliance rules, and resource quota and utilization rates.

[0014] In some examples, generating the simulation network model includes data processing hardware incrementally incorporating the proposed one or more parameter changes into the production network model. In some implementations, the operations include data processing hardware receiving one or more immutable parameters of the production network model. In some configurations, the operations include modifying a configuration of the network if an impact of the parameter changes on the network is acceptable.

[0015] The details of one or more implementations of the disclosure are set forth in the accompanying drawings and the description below. Other aspects, features, and advantages will become apparent from the description and drawings, and from the claims. [Brief description of the drawings]

[0016] [Figure 1]FIG. 1 is a schematic diagram illustrating an example system for performing change impact simulation analysis in a cloud network. [Diagram 2] FIG. 2 is a schematic diagram illustrating example components of a virtual machine of the system of FIG. 1. [Diagram 3] 2 is a flowchart illustrating an example workflow for using the network change simulator of the system of FIG. 1. [Figure 4] 4 is a flow chart illustrating an example sequence of operations for a method of performing a change impact simulation analysis. [Diagram 5] FIG. 1 is a schematic diagram illustrating an example computing device that can be used to implement the systems and methods described herein. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0017] Detailed Description A Virtual Private Cloud (VPC) is an on-demand, configurable pool of shared computing resources allocated within a public cloud environment to isolate users from other cloud users. Such isolation is achieved through the allocation of private Internet Protocol (IP) subnets and / or virtual communication structures. This may be done by assigning a unique IP address to a VPC. A VPC can run one or more virtual machines (VMs) and can communicate with a user's on-premises network or other remote resources through a virtual private network (VPN) to ensure secure access to the VPC environment. Because some VPC environments can be very large and highly complex (containing many VMs, network gateways, load balancers, etc.), significant network configuration is often required to operate and maintain the VPC.

[0018] Implementations herein allow users to configure network parameters (e.g., firewalls, In one embodiment, a network change simulator is provided that enables a network administrator to specify one or more changes to a VPC (e.g., route rules, VPC peering, provisioning or deprovisioning of network resources) and simulate at least one production workflow through the VPC. The network change simulator provides configuration information for each simulation route, including, for example, route rules and firewall rules.

[0019] Here, the network change simulator builds a simulated network model by incrementally incorporating the proposed parameter changes into a production network model of the VPC. The network change simulator then simulates workflows logged from the VPC within the simulated network model, compares the results of the simulated workflow to the production workflow, and generates output (e.g., reports) that indicate the impact or effect of the proposed configuration, events, and / or network changes on the VPC. A user or administrator of the VPC can use the output to decide whether to proceed with the incorporation of the proposed parameter changes based on the acceptability of the impact to the VPC.

[0020] 1, in some implementations, an exemplary system 10 includes a user device 20 associated with a respective user 12 and in communication with a cloud network 200 via a network 30 (e.g., the Internet) and an on-premise network 40 (i.e., a local network that the user device 20 uses to connect to the network 30). The on-premise network 40 includes a network gateway 42 (e.g., a router) that serves as a forwarding host for the on-premise network 40. The user device 20 may correspond to any computing device, such as a desktop workstation, a laptop workstation, or a mobile device (e.g., a smartphone or tablet). The user device 20 includes computing resources 22 (e.g., data processing hardware) and / or storage resources 24 (e.g., memory hardware).

[0021] The cloud network 200 may be a single computer, multiple computers, or a distributed system (e.g., a cloud environment) having scalable / elastic resources 202 including computing resources 204 (e.g., data processing hardware) and / or storage resources 206 (e.g., memory hardware). A data store (i.e., a remote storage device) may be overlaid on the storage resources 206 to enable scalable use of the storage resources 206 by one or more of the clients or computing resources 204. The cloud network 200 is configured to implement and run one or more virtual machines (VMs) 250, 250a-n. One or more of the VMs are securely executed in a virtual private cloud (VPC) environment or VPC 208 associated with or operated by the user 12. The VPC 208 may include various other network elements such as load balancers, gateways, front-ends, and back-ends.

[0022] In the example shown in FIG. 2, a distributed system 200 includes a collection 210 of resources 110 (e.g., hardware resources 110h), a virtual machine monitor (VM Each hardware resource 110h may include one or more physical central processing units (pCPUs) 204 ("physical processors 204") and memory hardware 206. Although each hardware resource 110h is shown as having a single physical processor 204, any hardware resource 110h may include one or more physical central processing units (pCPUs) 204 ("physical processors 204") and memory hardware 206. The collection 210 of resources 110 may include multiple physical processors 204. An operating system 212 may run on the collection 210 of resources 110.

[0023] In some examples, the VMM 220 corresponds to a hypervisor 220 (e.g., a computation engine) that includes at least one of software, firmware, or hardware configured to create and run the VMs 250. A computer (i.e., data processing hardware 204) associated with the VMM 220 that runs one or more VMs 250 may be referred to as a host machine, and each VM 250 may be referred to as a guest machine. Here, the VMM 220 or hypervisor is configured to provide each VM 250 with a corresponding guest operating system (OS) 212g having a virtual operating platform and manage the execution of the corresponding guest OS 212g on the VM 250. As used herein, each VM 250 may be referred to as an "instance" or "VM instance." In some examples, multiple instances of various operating systems may share virtualization resources. For example, a first VM 250 of a Linux® operating system, a second VM 250 of a Windows® operating system, and a third VM 250 of an OS X® operating system may all run on a single physical x86 machine.

[0024] The VM layer 240 includes one or more virtual machines 250. The distributed system 200 allows the user 12 to launch the VMs 250 on demand. The VMs 250 emulate real computer systems, operate based on the computer architecture and functionality of the real or virtual computer systems, and may include dedicated hardware, software, or a combination thereof. In some examples, the distributed system 200 authorizes and authenticates the user 12 before launching one or more VMs 250. An instance of software, or simply an instance, refers to a VM 250 hosted (executed) on the data processing hardware 204 of the distributed system 200.

[0025] Each VM 250 may include one or more virtual central processing units (vCPUs) 252 ("virtual processors"). In the illustrated example, a first virtual machine 250a includes a first set 252a of one or more virtual processors 252, and a second virtual machine 250b includes a second set 252b of one or more virtual processors 252. Although the second set 252b is shown as including only one virtual processor 252, any number of virtual processors 252 are possible. Each virtual processor 252 emulates one or more physical processors 204. For example, the first set 252a of one or more virtual processors 252 emulates the first set 204a of one or more physical processors 204, and the second set 252b of one or more virtual processors 252 emulates the second set 204b of one or more physical processors 204. The application layer 260 includes software resources 110s, 110sa, 110sb (software applications) that may be executed on the virtual machine(s) 250.

[0026] Typically, each instance of the software (e.g., virtual machine 250) includes at least one virtual storage device 262 that provides volatile and non-volatile storage capacity for the services on the physical memory hardware 206. For example, the storage capacity on the physical memory hardware 206 may be a persistent disk (PD) that stores data for user 12 across multiple physical disks (e.g., memory region 620 (FIG. 9)) of the memory hardware 206, or a random access virtual disk (VSD ... More specifically, each virtual storage device 262 of a corresponding VM 250 may have an associated physical Data is moved in sequences of bytes or bits (blocks) to the block storage volume V to provide non-volatile memory. Thus, the virtual storage device 262 of the corresponding VM instance 250 provides storage capacity that is mapped to a corresponding physical block storage volume V on the memory hardware 206. In some examples, the virtual storage device 262 supports random access to data on the memory hardware 206, typically using buffered I / O. Examples include hard disks, CD-ROM drives, and flash drives. Similarly, a portion of the volatile memory (e.g., RAM) of the physical memory hardware 206 may be carved out across the virtual storage device 262.

[0027] Within the guest operating system 212g resides a guest kernel 214g. The kernel is a computer program that is the core of the OS and has full access and control over the operating system. That is, the kernel is the intermediary between the applications 110s and the hardware resources 110h of the host machine. Most modern computing systems separate virtual memory into a protected kernel space and a user space 216g. The kernel typically resides in volatile memory in the protected kernel space and is separated from the user space 216g. To increase safety and reliability, the applications 110s and other software services typically run in the guest user space 216g and do not have the necessary privileges to interact with the protected kernel space.

[0028] With continued reference to FIG. 1 , the cloud network 200 may also execute a VPC intelligence system 300 that provides different modules for monitoring and managing the VPC 208. As generally shown in FIG. 1 , the network simulation system 300 includes a network monitor 310 configured to monitor the health, security, and operation of the VPC 208, a network logger 320 configured to record traffic flows and firewall events within the VPC 208, and a network change simulator 330 operable to identify the impact of proposed changes 84 to the network parameters 82 of the VPC 208. The network change simulator 330 analyzes whether the proposed changes 80 to one or more network parameters 82 of the cloud network 200 will affect the performance of the cloud network 200. Using the analysis, the user 12 can decide to accept, reject, or modify the proposed changes 84 prior to actual implementation in the cloud network 200.

[0029] The network monitor 310 may be incorporated into the change analysis system 304 or as a stand-alone module of the network simulation system 300. The network monitor 310 is operable to assess the overall health of the VPC 208. For example, the network monitor 310 may perform configuration checks, identify network failures and broken connections, monitor resource utilization and quotas within the VPC 208, perform IP address duplication checks within the VPC 208, and / or identify resource capacity reductions due to suboptimal network health. The network monitor 310 may also monitor firewall rules and firewall hits of the VPC 208 to identify potential issues with the security of the VPC 208. The network monitor 310 may also be configured to monitor the VPC 208 to identify whether elements of the VPC 208, such as subnets, firewalls, and load balancers, are underutilized. If included, the network monitor 310 may be configured to generate an automated change request 80b including recommendations for parameter changes 84 based on the monitoring of the VPC 208.

[0030] The network change simulator 330 is a network change simulator for the cloud network 200. Receive or obtain change requests 80, 80a, 80b including proposed changes 84 to parameters 82. Examples of network parameters 82 that may be changed include (i) adding or removing firewall rules, (ii) adding or removing VPC peering, (iii) adding or removing IP address blocks, VMs 250, subnets, and / or load balancers, and / or (iv) adding or removing VPN tunnels, BB masks, Zakim endpoints, etc. The network change simulator 330 may receive or obtain change requests 80, 80a including parameter changes 84 directly from the user 12 via the user device 20. Additionally or alternatively, the network change simulator 330 may receive or obtain change requests 80, 80b including parameter changes 84 recommended by the network monitor 310 of the network simulation system 300. In addition to the change requests 80, the network change simulator 330 receives or extracts one or more immutable parameters 86 from the network monitor 310. Immutable parameters 86 may include security compliance rules specified by an administrator or service provider of cloud network 200, or by user 12. Immutable parameters 86 include network parameters that cannot be changed by change request 80.

[0031] In addition to obtaining the change requests 80 and immutable parameters 86, the network change simulator 330 obtains one or more network logs 322 associated with a current or previous configuration of the cloud network 200, sometimes referred to as a production configuration. The network logs 322 may include VPC flow logs 322, 322a and / or firewall logs 322, 322b. The VPC flow logs 322a include records of sample network flows sent and received by each VM 250, and the firewall logs 322b include connection records corresponding to each instance of a particular firewall rule that allows or denies traffic. The connection records in the firewall logs 322b include source and destination IP addresses, protocols and ports, dates and times, and references to the precise firewall rules that apply to the allowed or denied traffic.

[0032] The network change simulator 330 includes a simulation workflow engine 340 that monitors and manages the activities of the network change simulator 330. The simulation workflow engine 340 sends and receives simulation information within the network simulation system 300 and the cloud environment 200. The simulation workflow engine 340 also assigns simulation tasks to other modules 350, 360, 370 of the network change simulator 330, as described in the following paragraphs. For example, the simulation workflow engine 340 may receive a change request 80 from a user device 20 or a network monitor 310, and then manage the operations within the network change simulator 330 to determine and report the potential effects of the change request 80.

[0033] One of the modules 350 of the network change simulator 330 includes a network modeler 350 operable to generate a simulated network model 356 based on one of the change requests 80. The network modeler 350 starts with a production network model 354 that represents a current production configuration of the VPCs 208. The network modeler 350 then generates the simulated network model 356 by incrementally incorporating the parameter changes 84 specified in the change requests 80. Thus, the simulated network model 356 includes one or more graphs of the VPCs 208 with the parameter changes 84 incorporated therein.

[0034] Another module of the network change simulator 330 simulates the changes by replaying one of the network logs 322 obtained from the network logger 320. The model log replayer 360 includes a log replayer 360 that executes a simulated network flow 362 within the simulation network model 356. As a reminder, the logs 322 obtained from the network logger include a VPC log 322a and a firewall rule log 322b generated by the network intelligence system 270 for the production configuration of the cloud network 200. Thus, the model log replayer 360 uses the VPC log 322a and the firewall rule log 322b to simulate the workflow that would occur within the cloud network 200 based on the simulation network model 356.

[0035] The log replayer 360 analyzes the simulated network model 356 in executing the sample workflows provided in the network log 322 to determine the impact of the changes 84 on performance metrics of the VPC 208. The log replayer 360 analyzes and reports a number of performance metrics related to the simulated network model 356. For example, the log replayer 360 analyzes the impact of the parameter changes 84 on reachability within the VPC 208. Here, the log replayer 360 identifies whether the change opens reachability between IP ranges and / or VMs 250 that were previously blocked or breaks reachability between IP ranges and / or VMs 250 that were previously open. The log replayer 360 may interpret the impact on reachability based on the reachability intent specified by the user.

[0036] The log replayer 360 also analyzes and reports the effect of the parameter change 84 on firewall rule relationships. For example, the log replayer 360 analyzes whether the parameter change 84 results in adding or removing firewall shadowing. The log replayer 360 also identifies whether changes occur in firewall optimality and / or firewall security boundaries. With respect to firewall optimality, the log replayer 360 analyzes and reports whether the simulated network model 356 includes additional firewall shadow relationships, resulting in the firewall of the VPC 208 becoming more redundant and less optimal, or whether a firewall shadow relationship is removed, resulting in the firewall becoming more optimal. With respect to firewall security boundaries, the log replayer 360 analyzes and reports whether the parameter change 84 results in an open or tightened security boundary. The log replayer 360 may also analyze and report a predicted firewall hit rate for the simulated network model 356.

[0037] The log replayer 360 may also analyze whether the simulated network model 356 impacts the network intent specified by the user 12. For example, the user 12 may initially specify that the intent of the VPC 208 is to perform or support a particular business function (e.g., configuring a cellular network, managing product logistics). The network evaluator 360 then analyzes whether the changes 84 incorporated into the simulated network model 356 comply with or violate the intent rules of the VPC 208. Similarly, the log replayer 360 analyzes and reports whether the simulated network model 356 impacts the network compliance rules of the VPC 208. The log replayer 360 stores the results of the simulation workflow for the simulated network model 356 as a simulation log 366.

[0038] The log replayer 360 records the results of replaying the production log 322 within the simulation network model 356 as a simulation log 366, and stores the simulation log 366 in the change analysis system 304. The simulation workflow engine 340 then compares the simulation log 366 with the corresponding production log 322 to determine whether the simulation log 366 is from the production log 322 or not. Differences between the network model 354 (ie, the current VPC network 208) and the simulated network model 356 (ie, the VPC network 208 including the parameter changes 84) are identified.

[0039] In addition to the log replayer 360 that performs dynamic analysis of the simulated network model 356 using the sample workflows provided in the network log 322, the change analysis system 304 of the network change simulator 330 may include a network analyzer 370 that performs static analysis of the simulated network model 356, where the network analyzer 370 is configured to perform validation tests of the simulated network model 356 to identify potential issues with the proposed parameter changes 84. For example, the network analyzer 370 may perform a comparison (e.g., static analysis, configuration checks with immutability, etc.) of the parameter changes 84 against the production network parameters 82 to highlight differences between the production network model 354 and the simulated network model 356. In some examples, the network monitor 310 and the network analyzer 370 are integrated within the same module to perform both monitoring and analysis functions.

[0040] The network analyzer 370 may be operable to assess the overall health of the network simulation model 356. For example, the network analyzer 370 may perform configuration checks, identify unused routes and broken connections, monitor resource utilization and quotas within the network simulation model 356, perform IP address duplication checks within the network simulation model 356, and / or identify resource degradation due to suboptimal network health. The network analyzer 370 may analyze firewall rules and firewall hits of the network simulation model 356 to identify potential issues with the security of the network simulation model 356. Additionally or alternatively, the network analyzer 370 may analyze the simulated network model 356 to identify whether elements of the network simulation model 356, such as subnets, firewalls, load balancers, etc., are duplicated and / or underutilized.

[0041] Based on the results of the dynamic analysis in the log replayer 360 and / or the static analysis in the network analyzer 370, the network change simulator 330 may generate a change impact report 332 and present the change impact report 332 to the user 12 via the user device 20. The change impact report 332 identifies the impact on network reachability, firewalls, search intent rules, security compliance rules, and resource quota utilization of the VPC 208 if the parameter change 84 is implemented. The change impact report 332, once received by the user device 20, causes the user device 20 to present the change impact report 332 to the user 12 for evaluation as to whether to accept, reject, or modify the pending parameter change 84. As shown in FIG. 3 and described below, the user 12 may use the change impact report 332 to determine whether to accept, reject, or edit the parameter change 84.

[0042] 3, an exemplary workflow 400 is provided for a user 12 interfacing with a network change simulator 330 via a user device 20. At block 402, the user 12 or network monitor 310 generates a change request 80 that includes a parameter change 84. At block 404, the network analyzer 370 analyzes the parameter change 84 and generates a static analysis impact report 332, 332a that identifies the effect(s) that the parameter change 84 has on the VPC network 208. The static analysis impact report 332a may identify impacts to network reachability, firewall shadow rules and predicted hit rates, search intent rules, security compliance rules, and resource quota utilization.

[0043] The network change simulator 330 provides the static analysis impact report 332a to the user device 20, and in decision block 406, the user 12 provides an indication as to whether the impact of the pending parameter change 84 is acceptable to the user 12. If the static analysis impact report 332a indicates that the parameter change 84 has no or minimal impact on the VPC 208, the user 12 determines that the pending parameter change 84 is acceptable and proceeds to block 408 to accept the pending parameter change 84. Conversely, the static analysis impact report 332a may clearly indicate that the parameter change 84 will result in a failure of the VPC 208. The user 12 may then respond that the pending parameter change 84 is not acceptable and proceed to decision block 410 to determine whether to edit the parameter change 84. If the user 12 determines not to edit the parameter change 84, the workflow proceeds to block 412, where the parameter change 84 is rejected.

[0044] If, at decision block 406, the impact of the parameter change 84 is not clearly acceptable or unacceptable, the user 12 may instruct the network change simulator 330 to perform a log replay at block 414. As described above, the log replay 414 is performed on the log replayer 360 by replaying the production log 322 within the simulated network model 356 to generate a simulation log 366. The workflow then proceeds to block 416, where the simulation log 366 is compared to the production log 322 to identify differences between the production network model 354 (i.e., the current VPC 208) and the simulated network model 356 (i.e., the proposed VPC 208). The network change simulator 330 then generates a dynamic analysis impact report 332b detailing the differences between the production network model 354 and the simulated network model 356 based on the differences between the production log 322 and the simulation log 366.

[0045] At decision block 418, the user 12 reviews the dynamic analysis impact report 332b to determine whether the differences between the production network model 354 and the simulated network model 356 are acceptable. If the differences are acceptable, the workflow proceeds to block 408, and the parameter changes 84 are incorporated (408) into the VPC 208. If the differences are not acceptable, the workflow proceeds to decision block 410, and the user 12 decides whether to edit the parameter changes 84. If the user 12 does not want to edit the parameter changes 84 (i.e., the answer is "no" at block 410), the parameter changes are rejected at block 412. However, if the user 12 decides to edit the parameter changes 84, the workflow proceeds to block 420, and the user 12 can modify one or more of the parameter changes 84. Once the parameter changes 84 are edited at block 420, the workflow returns to block 402 to initiate another change request 80 that includes the edited parameter changes 84. In this manner, the workflow 400 repeats until the parameter change 84 is either accepted at block 408 or rejected at block 412, thereby allowing the user 12 to iteratively modify, simulate, and review the parameter changes 84 to the VPC 208 without interrupting the production VPC 208.

[0046] 4 is a flow chart illustrating an example sequence of operations for a method 500 for performing a change impact simulation analysis. The method 500 includes, at operation 502, running one or more performance tests on the production network model 354 of the network 208 in the data processing hardware 204. The method 500 includes, at operation 504, the data processing hardware 204 generating a simulated network model 356 including the one or more parameter changes 84. The method 500 includes, at operation 506, receiving, at the data processing hardware 204, a production network log 322 for the production network model 354. The method 500 includes, at operation 508, the data processing hardware 204 simulating execution of the production network log 322 in the simulated network model 356 to generate a simulated network log 366. The method 500 further includes, at operation 510, the data processing hardware 204 analyzing the simulated network log 366 and, at operation 512, the data processing hardware generating a network impact report 332 including an impact of the parameter changes 84 on the network 208.

[0047] 5 is a schematic diagram of an exemplary computing device 600 that may be used to implement the systems and methods described herein. The computing device 600 is intended to represent various forms of digital computers, such as laptops, desktops, workstations, personal digital assistants, servers, blade servers, mainframes, and other suitable computers. The components shown, their connections and relationships, and their functions are intended to be exemplary only and are not intended to limit the implementation of the inventions described and / or claimed herein.

[0048] The computing device 600 includes a processor 610, a memory 620, a storage device 630, a high-speed interface / controller 640 that connects to the memory 620 and a high-speed expansion port 650, and a low-speed interface / controller 660 that connects to a low-speed bus 670 and the storage device 630. The components 610, 620, 630, 640, 650, and 660 are interconnected using various buses and may be mounted on a common motherboard or may be mounted in other manners as appropriate. The processor 610 can process instructions for execution within the computing device 600, including instructions stored in the memory 620 or the storage device 630, to display graphical information for a graphical user interface (GUI) on an external input / output device, such as a display 680 coupled to the high-speed interface 640. In other implementations, multiple processors and / or multiple buses may be used, along with multiple memories and multiple types of memories, as appropriate. Also, multiple computing devices 600 may be connected, each providing a portion of the required operations (eg, as a server bank, a group of blade servers, or a multi-processor system).

[0049] The memory 620 stores information non-transiently within the computing device 600. The memory 620 may be a computer readable medium, a volatile memory unit(s), or a non-volatile memory unit(s). The non-transient memory 620 may be a physical device used to temporarily or permanently store programs (e.g., sequences of instructions) or data (e.g., program state information) for use by the computing device 600. Examples of non-volatile memory include flash memory and read-only memory (ROM) / programmable read-only memory (PROM) / erasable programmable read-only memory (PROM). EPROM (electronically erasable programmable read-only memory) Examples of volatile memory include, but are not limited to, random access memory (RAM), dynamic random access memory (DRM), and EEPROM (EEPROM), which are typically used for firmware such as boot programs. Examples of suitable memory devices include, but are not limited to, dynamic random access memory (DRAM), static random access memory (SRAM), phase change memory (PCM), as well as disks or tapes.

[0050] The storage device 630 can provide mass storage for the computing device 600. In some implementations, the storage device 630 is a computer-readable medium. In various different implementations, the storage device 630 can be a floppy disk device, a hard disk device, an optical disk device, or an array of devices including a tape device, a flash memory or other similar solid-state memory device, or a device in a storage area network or other configuration. In additional implementations, the computer program product is tangibly embodied in an information carrier. The computer program product includes instructions that, when executed, perform one or more methods as described above. The information carrier is a computer-readable or machine-readable medium, such as the memory 620, the storage device 630, or a memory on the processor 610.

[0051] The high-speed controller 640 manages the bandwidth-intensive operations of the computing device 600, and the low-speed controller 660 manages the less bandwidth-intensive operations. Such assignment of duties is merely exemplary. In some implementations, the high-speed controller 640 is coupled to the memory 620, the display 680 (e.g., via a graphics processor or accelerator), and a high-speed expansion port 650 that can accept various expansion cards (not shown). In some implementations, the low-speed controller 660 is coupled to the storage device 630 and the low-speed expansion port 690. The low-speed expansion port 690, which may include various communication ports (e.g., USB, Bluetooth, Ethernet, wireless Ethernet), may be coupled to one or more input / output devices, such as a keyboard, pointing device, scanner, or a network device, such as a switch or router, for example, via a network adapter.

[0052] The computing device 600 may be implemented in many different forms, as shown in the figure, such as as a standard server 600a, or multiple times within a group of such servers 600a, as a laptop computer 600b, or as part of a rack server system 600c.

[0053] Various implementations of the systems and techniques described herein may be implemented in digital electronic and / or optical circuits, integrated circuits, specially designed application specific integrated circuits (ASICs), computer hardware, firmware, or other devices. The various implementations may be implemented in one or more computer programs, which may be special purpose or general purpose, and which are executable and / or interpretable on a programmable system that includes at least one programmable processor, at least one input device, and at least one output device coupled to send and receive data and instructions to and from the storage system.

[0054] A software application (i.e., a software resource) may refer to computer software that causes a computing device to perform a task. In some examples, a software application may be referred to as an "application," an "app," or a "program." Examples of applications include system diagnostic applications, system management applications, system maintenance applications, word processing applications, spreadsheet applications, messaging applications, and the like. These applications include, but are not limited to, mobile applications, media streaming applications, social networking applications, and gaming applications.

[0055] These computer programs (also known as programs, software, software applications or code) include machine instructions for a programmable processor and may be implemented in high level procedural and / or object oriented programming languages, and / or assembly / machine languages. As used herein, the terms "machine readable medium" and "computer readable media" refer to any computer program product, non-transitory computer readable medium, apparatus and / or device (e.g., magnetic disk, optical disk, memory, Programmable Logic Device (PLD)) used to provide machine instructions and / or data to a programmable processor, including machine readable media that receive machine instructions as machine readable signals. The term "machine readable signal" refers to a medium that receives machine instructions and / or data from a programmable processor. Or it refers to any signal used to provide data to a programmable processor.

[0056] The processes and logic flows described herein may be performed by one or more programmable processors, also referred to as data processing hardware, to execute one or more computer programs to perform functions by operating on input data and generating output. The processes and logic flows may also be implemented using special purpose logic circuitry, such as a field programmable gate array (FPGA) or other specialized hardware. The computer program may be implemented by a special purpose integrated circuit (ASIC). Processors suitable for executing computer programs include, by way of example, both general-purpose and special-purpose microprocessors, and any one or more processors of any kind of digital computer. In general, a processor receives instructions and data from a read-only memory or a random access memory or both. The essential elements of a computer are a processor for executing instructions and one or more memory devices for storing instructions and data. Generally, a computer will also include one or more mass storage devices for storing data, such as magnetic, magneto-optical, or optical disks, or be operatively coupled to receive data from or transfer data to them, or both. However, a computer need not have such devices. Computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and memory devices, including, by way of example, semiconductor memory devices, such as EPROM, EEPROM, and flash memory devices; magnetic disks, such as internal hard disks or removable disks; magneto-optical disks; and CD ROM and DVD-ROM disks. The processor and the memory can be supplemented by, or incorporated in, special purpose logic circuitry.

[0057] To provide for user interaction, one or more aspects of the present disclosure can be implemented on a computer having a display device, such as a cathode ray tube (CRT), liquid crystal display (LCD) monitor, or touch screen, for displaying information to the user, and optionally a keyboard and pointing device, such as a mouse or trackball, by which the user can provide input to the computer. Other types of devices can also be used to provide for user interaction, for example, feedback provided to the user can be any form of sensory feedback, such as visual feedback, auditory feedback, or tactile feedback, and input from the user can be received in any form, including acoustic, speech, or tactile input. Additionally, the computer can communicate with the device used by the user. It is possible to interact with a user by sending and receiving documents, for example by sending web pages to a web browser on a user's client device in response to requests received from the web browser.

[0058] Although several embodiments have been described, it will be understood that various modifications can be made without departing from the spirit and scope of the disclosure. Accordingly, other embodiments are within the scope of the following claims.

Claims

1. A method (500) for network configuration simulation, comprising: receiving, at the data processing hardware (204), one or more parameter changes (84) to a production network model (354) of the network (200); generating a simulation network model (356) that includes the one or more parameter changes (84) using the data processing hardware (204); said data processing hardware (204) analyzing a simulation network flow (362) within said simulation network model (356); and generating a report (332) including an effect of the parameter change (84) on the network (200) by the data processing hardware (204).

2. receiving, at said data processing hardware (204), a production network log (322) including a recorded workflow for said production network model (354); 2. The method of claim 1, further comprising: the data processing hardware simulating the production workflow of the production network log in the simulation network model to generate a simulation network log.

3. Analyzing the simulation network flow (362) comprises: said data processing hardware (204) comparing said production network log (322) with said simulation network log (366); The method of claim 2, further comprising: the data processing hardware determining a difference between the production network log and the simulation network log.

4. The method (500) of claim 2 or 3, wherein the production network log (322) is one of a virtual private connection flow log (322a) and a firewall rule log (322b).

5. The method (500) of any one of claims 1 to 4, further comprising the data processing hardware (204) determining an effect of the parameter change (84) on the production network model (354).

6. 6. The method of claim 5, wherein determining the impact of the parameter change includes determining an impact on at least one of network reachability, firewall shadow rules and predicted firewall hit rates, search intent rules, security compliance rules, or resource quotas and utilization rates.

7. The method (500) of any one of claims 1 to 6, wherein generating the simulation network model (356) includes the data processing hardware (204) incrementally incorporating the one or more parameter changes (84) into the production network model (354).

8. The method (500) of any one of claims 1 to 7, further comprising the data processing hardware (204) receiving one or more immutable parameters (86) of the production network model (354).

9. The method (500) of any one of claims 1 to 8, further comprising: if the effect of the parameter change (84) on the network (200) is acceptable, the data processing hardware (204) altering a configuration of the network (200).

10. Data processing hardware (204); and memory hardware (206) in communication with the data processing hardware (204), the memory hardware (206) storing instructions that, when executed by the data processing hardware, cause the data processing hardware to perform operations, the operations including: receiving one or more parameter changes (84) to a production network model (354) of the network (200); generating a simulation network model (356) that includes the one or more parameter changes (84); analyzing a simulation network flow (362) within the simulation network model (356); generating a report (332) including an effect of the parameter change (84) on the network (200).

11. The operation further comprises: receiving a production network log (322) including a recorded workflow for said production network model (354); simulating the production workflow of the production network log (322) in the simulation network model (356) to generate a simulation network log (366).

12. Analyzing the simulation network flow (362) comprises: comparing said production network log (322) with said simulation network log (366); and identifying differences between the production network log and the simulation network log.

13. 13. The system (10) of claim 11 or 12, wherein the production network log (322) is one of a virtual private connection flow log (322a) and a firewall rule log (322b).

14. The system (10) of any one of claims 10 to 13, wherein the operations further comprise determining an impact of the parameter change (84) on the production network model (354).

15. 15. The system of claim 14, wherein determining the impact of the parameter change includes determining an impact on at least one of network reachability, firewall shadow rules and predicted firewall hit rates, search intent rules, security compliance rules, or resource quotas and utilization rates.

16. The system (10) of any one of claims 10 to 15, wherein generating the simulation network model (356) includes incorporating the one or more parameter changes (84) into the production network model (354) in a constant manner.

17. The operations further include receiving one or more immutable parameters (86) of the production network model (354). 10)。

18. The system (10) of any one of claims 10 to 17, wherein the operations further include modifying a configuration of the network (200) if the effect of the parameter change (84) on the network (200) is acceptable.

19. A computer program product encoded on a non-transitory computer-readable storage medium (206) that includes instructions that, when executed by a data processing device (204), cause the data processing device (204) to perform operations, the operations including: receiving one or more parameter changes (84) to a production network model (354) of the network (200); generating a simulation network model (356) that includes the one or more parameter changes (84); analyzing a simulation network flow (362) within the simulation network model (356); generating a report (332) including an effect of the parameter changes (84) on the network (200).

20. The operation further comprises: receiving a production network log (322) including a recorded workflow for said production network model (354); and simulating the production workflow of the production network log (322) in the simulation network model (356) to generate a simulation network log (366).

21. Analyzing the simulation network flow (362) comprises: comparing said production network log (322) with said simulation network log (366); and identifying differences between the production network log (322) and the simulation network log (366).

22. 22. The computer program product of claim 20 or 21, wherein the production network log (322) is one of a virtual private connection flow log (322a) and a firewall rule log (322b).

23. The computer program product of any one of claims 19 to 22, wherein the operations further comprise determining an effect of the parameter change (84) on the production network model (354).

24. 24. The computer program product of claim 23, wherein determining the impact of the parameter change (84) comprises determining an impact on at least one of network reachability, firewall shadow rules and predicted firewall hit rates, search intent rules, security compliance rules, or resource quotas and utilization rates.

25. 25. The computer program product of claim 19, wherein generating the simulation network model (356) comprises incrementally incorporating the one or more parameter changes (84) into the production network model (354).

26. The computer program product of any one of claims 19 to 25, wherein the operations further comprise receiving one or more immutable parameters (86) of the production network model (354).

27. 27. The computer program product of claim 19, wherein the operations further comprise: modifying a configuration of the network if the effect of the parameter change on the network is acceptable.

Citation Information

Patent Citations

  • Techniques for dynamic network optimization using geolocation and network modeling

    CN105813112A

  • Device, method and program for designing network

    JP2007208633A

  • Network verification system

    JP2014154925A

  • Techniques for dynamic network optimization using geolocation and network modeling

    US20160212634A1

  • Methods and systems for configuring communication networks

    US20170134224A1