Change Impact Simulation Analysis

The network change simulator in VPC environments allows for simulating and evaluating network changes, addressing the complexity of VPC management by assessing impact on network reachability, firewall rules, and resource utilization.

JP7857445B2Active Publication Date: 2026-05-12GOOGLE LLC
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
GOOGLE LLC
Filing Date
2025-01-15
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Managing complex virtual private cloud (VPC) networks requires significant configuration efforts due to their scale and complexity, necessitating a method to simulate network changes and assess their impact before implementation.

Method used

A network change simulator that analyzes proposed parameter changes by generating a simulation model, simulating network workflows, and comparing them to production logs to generate a report on the impact of these changes, including network reachability, firewall rules, and resource utilization.

Benefits of technology

Enables users to evaluate the effects of proposed network changes before implementation, ensuring minimal disruption and optimizing network configurations in VPC environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007857445000001
    Figure 0007857445000001
  • Figure 0007857445000002
    Figure 0007857445000002
  • Figure 0007857445000003
    Figure 0007857445000003
Patent Text Reader

Abstract

To provide a method and system for network change simulation.SOLUTION: In a system 10, a cloud network 200 includes data processing hardware 204 and memory hardware 206 for communicating with the data processing hardware. The memory hardware stores a command for causing the data processing hardware to execute operations. The operations include: receiving one or more parameter changes 84 to a production network model 354 of the cloud network; generating a simulation network model 356 including one or more parameter changes; analyzing a simulated network flow 362 in the simulation network model; generating a report; and simulating a production workflow of a production network log 322 in the simulation network model to generate a simulated network log.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to change impact simulation analysis in a cloud network.

Summary of the Invention

Problems to be Solved by the Invention

[0002] Background A virtual private cloud (VPC) is an on-demand configurable pool of shared computing resources allocated within a public cloud environment. The VPC isolates users from other cloud users. The VPC can run one or more virtual machines (VMs) that can communicate with the user's on-premises network or other remote resources via a virtual private network (VPN). The VPC may include any number of VMs, network gateways, load balancers, etc. Due to its scale and complexity, a significant network configuration is often required to operate and maintain the VPC.

Means for Solving the Problems

[0003] Overview One aspect of this disclosure provides a network change simulation method. The method includes receiving, in data processing hardware, one or more parameter changes to a production network model of a network. The method further includes the data processing hardware generating a simulation network model that includes the one or more parameter changes. The method further includes the data processing hardware analyzing a simulation network flow within the simulation network model and the data processing hardware generating a report that includes the impact of the parameter changes on the network.

[0004] This aspect of the Disclosure may include one or more of the following features. In some examples, the method further includes data processing hardware receiving a production network log containing recorded workflows for a production network model, and the data processing hardware simulating the production workflow of the production network log in a simulated network model to generate a simulated network log. In some examples, analyzing the simulated network flow includes data processing hardware comparing the production network log to the simulated network log, and the data processing hardware identifying the differences between the production network log and the simulated network log. Optionally, the production network log is one of the virtual private connection flow log and the firewall rule log.

[0005] In some examples, the method may include data processing hardware determining the impact of proposed parameter changes on a production network model. Here, determining the impact of proposed parameter changes may include determining the impact on at least one of the following: network reachability, firewall shadow rules / predicted firewall hit rate, search intent rules, security compliance rules, and resource quotas / utilization.

[0006] In some configurations, generating a simulation network model involves the data processing hardware incorporating one or more proposed parameter changes into the production network model in incremental amounts. In some examples, the method involves the data processing hardware This includes receiving one or more immutable parameters of the production network model. The method may further include the data processing hardware modifying the network configuration if the impact of the parameter change on the network is acceptable.

[0007] Other aspects of this disclosure provide a system comprising data processing hardware and memory hardware that communicates with the data processing hardware. The memory hardware stores instructions that cause the data processing hardware to perform an action when executed by the data processing hardware. An action includes receiving one or more parameter changes to a production network model of the network. An action further includes generating a simulated network model that includes one or more parameter changes. Another action includes analyzing the simulated network flow in the simulated network model. An action further includes generating a report that includes the impact of the parameter changes on the network.

[0008] This aspect of the Disclosure may include one or more of the following features. For example, the operation includes receiving a production network log containing recorded workflows for a production network model. Another operation includes simulating the production workflow of the production network log in a simulated network model to generate a simulated network log. Here, analyzing the simulated network flow may include comparing the production network log to the simulated network log and identifying the differences between the production network log and the simulated network log. Optionally, the production network log is one of the virtual private connection flow log and the firewall rule log.

[0009] In some configurations, the operation further includes determining the impact of proposed parameter changes on the production network model. Here, determining the impact of proposed parameter changes includes determining the impact on at least one of the following: network reachability, firewall shadow rules / predicted firewall hit rate, search intent rules, security compliance rules, and resource quotas / utilization.

[0010] In some examples, generating a simulation network model involves data processing hardware incorporating one or more proposed parameter changes into the production network model in incremental amounts. In some implementations, the operation further includes data processing hardware receiving one or more invariant parameters from the production network model. In some configurations, the operation includes modifying the network configuration if the impact of the parameter changes on the network is acceptable.

[0011] Other aspects of this disclosure are computer program products encoded on a non-temporary computer-readable medium, which, when executed by a data processing device, contain instructions causing the data processing device to perform an action. The action includes receiving one or more parameter changes to a production network model of the network. Another action includes generating a simulated network model that includes one or more parameter changes. The action includes receiving one or more changes to a production network model of the network. The action further includes generating a simulated network model that includes one or more parameter changes. Another action includes analyzing the simulated network flow within the simulated network model. The action further includes generating a report that includes the impact of the parameter changes on the network.

[0012] This aspect of the Disclosure may include one or more of the following features: For example, the operation includes a production network model with a recorded workflow for the production network model. This includes receiving the log. Another operation involves simulating the production workflow of the production network log within the simulated network model to generate a simulated network log. Here, analyzing the simulated network flow includes comparing the production network log with the simulated network log and identifying the differences between the production network log and the simulated network log. Optionally, the production network log is one of the virtual private connection flow log and firewall rule log.

[0013] In some configurations, the operation further includes determining the impact of proposed parameter changes on the production network model. Here, determining the impact of proposed parameter changes includes determining the impact on at least one of the following: network reachability, firewall shadow rules / predicted firewall hit rate, search intent rules, security compliance rules, and resource quotas / utilization.

[0014] In some examples, generating a simulation network model involves data processing hardware incorporating one or more proposed parameter changes into the production network model in a fixed amount. In some implementations, the operation involves data processing hardware receiving one or more invariant parameters of the production network model. In some configurations, the operation involves modifying the network configuration if the impact of the parameter changes on the network is acceptable.

[0015] Details of one or more implementations of this disclosure are described in the accompanying drawings and the following description. Other aspects, features, and advantages will become apparent from the description and drawings, as well as the claims. [Brief explanation of the drawing]

[0016] [Figure 1]This is a schematic diagram illustrating an example system for performing change impact simulation analysis in a cloud network. [Figure 2] Figure 1 is a schematic diagram showing exemplary components of a virtual machine in the system. [Figure 3] This flowchart shows an exemplary workflow for using the network change simulator for the system in Figure 1. [Figure 4] This flowchart illustrates an example of how to perform a change impact simulation analysis. [Figure 5] This is a schematic diagram showing an exemplary computing device that may be used to carry out the systems and methods described herein. [Modes for carrying out the invention]

[0017] Detailed explanation A Virtual Private Cloud (VPC) is an on-demand, configurable pool of shared computing resources allocated within a public cloud environment to isolate users from other cloud users. Such isolation is achieved through the allocation of private Internet Protocol (IP) subnets and / or virtual communication structures. This can be done by choice. A VPC can run one or more virtual machines (VMs) and communicate with the user's on-premises network or other remote resources via a virtual private network (VPN) to ensure secure access to the VPC environment. Some VPC environments are very large and complex (including many VMs, network gateways, load balancers, etc.), so operating and maintaining a VPC often requires a considerable network configuration.

[0018] An example of implementation in this specification is when the user controls network parameters (e.g., firewall) A network change simulator that enables simulating at least one production workflow via a VPC by specifying one or more changes (such as rules, VPC peering, provisioning or de-provisioning of network resources). The network change simulator provides configuration information for each simulation path, including, for example, path rules and firewall rules.

[0019] Here, the network change simulator constructs a simulation network model by gradually incorporating the proposed parameter changes into the production network model of the VPC. Next, the network change simulator simulates the workflow logged from the VPC within the simulation network model, compares the results of the simulation workflow with the production workflow, and generates an output (such as a report) indicating the impact or effect of the proposed configuration, event, and / or network change on the VPC. The user or administrator of the VPC can use the output to determine whether to proceed with the incorporation of the proposed parameter changes based on the acceptability of the impact on the VPC.

[0020] Referring to FIG. 1, in some embodiments, an exemplary system 10 includes a user device 20, which is associated with respective users 12 and communicates with a cloud network 200 via a network 30 (e.g., the Internet) and an on-premises network 40 (i.e., a local network used by the user device 20 to connect to the network 30). The on-premises network 40 includes a network gateway 42 (e.g., a router) that functions as a transfer host for the on-premises network 40. The user device 20 may correspond to any computing device such as a desktop workstation, a laptop workstation, or a mobile device (e.g., a smartphone or a tablet). The user device 20 includes computing resources 22 (e.g., data processing hardware) and / or storage resources 24 (e.g., memory hardware).

[0021] The cloud network 200 may be a single computer, multiple computers, or a distributed system (e.g., a cloud environment) having scalable / elastic resources 202 that include computing resources 204 (e.g., data processing hardware) and / or storage resources 206 (e.g., memory hardware). A data store (i.e., a remote storage device) may be overlaid on the storage resources 206 to enable scalable use of the storage resources 206 by one or more of the clients or computing resources 204. The cloud network 200 is configured to implement and execute one or more virtual machines (VMs) 250, 250a - n. One or more of the VMs are securely executed in a virtual private cloud (VPC) environment or VPC 208 that is associated with or operated by the user 12. The VPC 208 may include various other network elements such as a load balancer, a gateway, a front end, and a back end.

[0022] In the example shown in Figure 2, the distributed system 200 consists of a collection of resources 110 (for example, hardware resource 110h), a virtual machine monitor (VM), and a virtual machine monitor (VM). M)220 includes a VM layer 240 running one or more VMs 250, and an application layer 260. Each hardware resource 110h may include one or more physical central processing units (pCPUs) 204 ("physical processors 204") and memory hardware 206. Although each hardware resource 110h is shown to have a single physical processor 204, any hardware resource 110h may have It may include multiple physical processors 204. The operating system 212 may run on a collection 210 of resources 110.

[0023] In some examples, VMM220 corresponds to a hypervisor 220 (e.g., a computing engine) that includes at least one of the software, firmware, or hardware configured to create and run VM250s. The computer associated with VMM220 running one or more VM250s (i.e., data processing hardware 204) may be called the host machine, and each VM250 may be called a guest machine. Here, VMM220 or the hypervisor is configured to provide each VM250 with a corresponding guest operating system (OS) 212g having a virtual operating platform and to manage the execution of the corresponding guest OS 212g on the VM250. As used herein, each VM250 may be called an “instance” or “VM instance”. In some examples, multiple instances of different operating systems may share virtualization resources. For example, a first VM250 of the Linux® operating system, a second VM250 of the Windows® operating system, and a third VM250 of the OS X® operating system can all run on a single physical x86 machine.

[0024] The VM tier 240 contains one or more virtual machines 250. The distributed system 200 allows users 12 to launch VMs 250 on demand. VMs 250 emulate real computer systems and operate based on the computer architecture and functionality of real or virtual computer systems, and may include dedicated hardware, software, or a combination thereof. In some examples, the distributed system 200 authorizes and authenticates users 12 before launching one or more VMs 250. A software instance, or simply an instance, refers to a VM 250 hosted (running) on ​​the data processing hardware 204 of the distributed system 200.

[0025] Each VM250 may contain one or more virtual central processing units (vCPUs) 252 ("virtual processors"). In the illustrated example, the first virtual machine 250a contains a first set 252a of one or more virtual processors 252, and the second virtual machine 250b contains a second set 252b of one or more virtual processors 252. The second set 252b is shown as containing only one virtual processor 252, but any number of virtual processors 252 are possible. Each virtual processor 252 emulates one or more physical processors 204. For example, the first set 252a of one or more virtual processors 252 emulates a first set 204a of one or more physical processors 204, and the second set 252b of one or more virtual processors 252 emulates a second set 204b of one or more physical processors 204. The application layer 260 includes software resources 110s, 110sa, and 110sb (software applications) that can run on virtual machines 250.

[0026] Typically, each instance of the software (e.g., a virtual machine 250) includes at least one virtual storage device 262 that provides volatile and non-volatile storage capacity for services on the physical memory hardware 206. For example, the storage capacity on the physical memory hardware 206 could be a persistent disk (PD) that stores user 12's data across multiple physical disks of the memory hardware 206 (e.g., memory area 620 (Figure 9)), or random access to provide volatile memory. This may include memory (random access memory: RAM). More specifically, each virtual storage device 262 of the corresponding VM250 has an associated physical memory on the memory hardware 206. Non-volatile memory is provided by moving data in sequences of bytes or bits (blocks) to a block storage volume V. Therefore, the virtual storage device 262 of the corresponding VM instance 250 provides storage capacity mapped to the corresponding physical block storage volume V on the memory hardware 206. In some examples, the virtual storage device 262 supports random access to data on the memory hardware 206 and generally uses buffered I / O. Examples include hard disks, CD-ROM drives, and flash drives. Similarly, a portion of the volatile memory (e.g., RAM) of the physical memory hardware 206 may be shared across the virtual storage device 262.

[0027] Within the guest operating system 212g, there resides the guest kernel 214g. The kernel is the core computer program of the OS, granting full access and control to the operating system. In other words, the kernel acts as an intermediary between applications 110s and the host machine's hardware resources 110h. Most modern computing systems separate virtual memory into a protected kernel space and user space 216g. The kernel typically resides in volatile memory within the protected kernel space and is isolated from user space 216g. For enhanced security and reliability, applications 110s and other software services typically run in the guest user space 216g and do not have the necessary privileges to interact with the protected kernel space.

[0028] Continuing to refer to Figure 1, the cloud network 200 may also run a VPC intelligence system 300 that provides different modules for monitoring and managing VPC 208. As generally shown in Figure 1, the network simulation system 300 includes a network monitor 310 configured to monitor the health, security, and operation of VPC 208, a network logger 320 configured to record traffic flow and firewall events within VPC 208, and a network change simulator 330 capable of determining the impact of proposed changes 84 on network parameters 82 of VPC 208. The network change simulator 330 analyzes whether proposed changes 80 on one or more network parameters 82 of the cloud network 200 will affect the performance of the cloud network 200. Using the analysis, user 12 can decide whether to accept, reject, or modify the proposed changes 84 before actual implementation in the cloud network 200.

[0029] The network monitor 310 can be integrated into the change analysis system 304 or as a standalone module of the network simulation system 300. The network monitor 310 can operate to assess the overall health of VPC208. For example, the network monitor 310 can perform configuration checks, identify network failures and broken connections, monitor resource utilization and quotas within VPC208, perform IP address duplication checks within VPC208, and / or identify resource capacity reductions due to suboptimal network health. The network monitor 310 can also monitor firewall rules and firewall hits in VPC208 to identify potential security issues in VPC208. The network monitor 310 can also be configured to monitor VPC208 to determine whether elements of VPC208, such as subnets, firewalls, and load balancers, are underutilized. If included, the network monitor 310 can be configured to generate an automated change request 80b, including recommendations for parameter changes 84, based on its monitoring of VPC208.

[0030] The network change simulator 330 is a network of cloud network 200. The network change simulator 330 receives or obtains change requests 80, 80a, and 80b, which include proposed changes 84 to parameter 82. Examples of network parameters 82 that may be changed include (i) adding or removing firewall rules, (ii) adding or removing VPC peering, (iii) adding or removing IP address blocks, VM250, subnets, and / or load balancers, and / or (iv) adding or removing VPN tunnels, BB masks, Zakim endpoints, etc. The network change simulator 330 may receive or obtain change requests 80, 80a, which include parameter changes 84, directly from the user 12 via the user device 20. Alternatively, the network change simulator 330 may receive or obtain change requests 80, 80b, which include parameter changes 84 recommended by the network monitor 310 of the network simulation system 300. In addition to the change requests 80, the network change simulator 330 receives or extracts one or more invariant parameters 86 from the network monitor 310. The immutable parameters 86 may include security compliance rules specified by the administrator or service provider of the cloud network 200, or by user 12. The immutable parameters 86 may include network parameters that cannot be changed by change requests 80.

[0031] In addition to obtaining the change request 80 and the immutable parameters 86, the network change simulator 330 obtains one or more network logs 322 related to the current or previous configuration of the cloud network 200, sometimes referred to as the production configuration. The network logs 322 may include VPC flow logs 322,322a and / or firewall logs 322,322b. The VPC flow log 322a contains a record of sample network flows sent and received by each VM 250, and the firewall log 322b contains connection records corresponding to each instance of a particular firewall rule that allows or denies traffic. The connection records in the firewall log 322b include the source and destination IP addresses, protocol and port, date and time, and references to the finer-grained firewall rules applied to the allowed or denied traffic.

[0032] The network change simulator 330 includes a simulation workflow engine 340 that monitors and manages the activities of the network change simulator 330. The simulation workflow engine 340 transmits and receives simulation information within the network simulation system 300 and the cloud environment 200. The simulation workflow engine 340 also assigns simulation tasks to other modules 350, 360, and 370 of the network change simulator 330, as described in the following paragraphs. For example, the simulation workflow engine 340 may receive a change request 80 from a user device 20 or a network monitor 310 and then manage the operations within the network change simulator 330 to determine and report the potential effects of the change request 80.

[0033] One of the modules 350 of the network change simulator 330 includes a network modeler 350 that can operate to generate a simulated network model 356 based on one of the change requests 80. The network modeler 350 starts with a production network model 354 that represents the current production configuration of VPC208. The network modeler 350 then generates the simulated network model 356 by stepping through the parameter changes 84 specified in the change request 80. Thus, the simulated network model 356 includes one or more graphs of VPC208 with the parameter changes 84 incorporated.

[0034] Another module of the network change simulator 330 simulates by playing back one of the network logs 322 obtained from the network logger 320. The system includes a log replayer 360 that runs a simulated network flow 362 within the simulation network model 356. For the record, the logs 322 obtained from the network logger include VPC logs 322a and firewall rule logs 322b generated by the network intelligence system 270 for the production configuration of the cloud network 200. Thus, the model log replayer 360 uses the VPC logs 322a and firewall rule logs 322b to simulate the workflow that would occur within the cloud network 200, based on the simulation network model 356.

[0035] LogReplayer 360 analyzes the simulated network model 356 when running the sample workflow provided in network log 322 to determine the impact of change 84 on the performance metrics of VPC208. LogReplayer 360 analyzes and reports numerous performance metrics related to the simulated network model 356. For example, LogReplayer 360 analyzes the impact of parameter change 84 on reachability within VPC208. Here, LogReplayer 360 identifies whether the change opens up reachability between IP ranges and / or VM250 that were previously blocked, or breaks reachability between IP ranges and / or VM250 that were previously open. LogReplayer 360 may interpret the impact on reachability based on the reachability intent specified by the user.

[0036] Furthermore, LogReplayer 360 analyzes and reports on the impact of parameter change 84 on firewall rule relationships. For example, LogReplayer 360 analyzes whether parameter change 84 results in the addition or removal of firewall shadowing. LogReplayer 360 also identifies whether there are any changes to firewall optimality and / or firewall security boundaries. Regarding firewall optimality, LogReplayer 360 analyzes and reports whether the simulated network model 356 includes additional firewall shadow relationships, resulting in VPC208's firewalls becoming more redundant and less optimal, or whether firewall shadow relationships are removed, thereby making the firewalls more optimal. Regarding firewall security boundaries, LogReplayer 360 analyzes and reports whether the security boundary has been opened or tightened as a result of parameter change 84. LogReplayer 360 may also analyze and report the predicted firewall hit rate for the simulated network model 356.

[0037] Furthermore, the log replayer 360 may analyze whether the simulated network model 356 affects the network intent specified by user 12. For example, user 12 might initially specify that the intent for VPC208 is to perform or support a specific business function (e.g., configuring a cellular network, managing product logistics). Here, the network evaluator 360 analyzes whether the changes 84 incorporated into the simulated network model 356 comply with or violate the intent rules of VPC208. Similarly, the log replayer 360 analyzes and reports whether the simulated network model 356 affects the network compliance rules of VPC208. The log replayer 360 stores the results of the simulation workflow regarding the simulated network model 356 as a simulation log 366.

[0038] The log replayer 360 records the result of replaying the production log 322 within the simulation network model 356 as the simulation log 366, and stores the simulation log 366 in the change analysis system 304. Next, the simulation workflow engine 340 compares the simulation log 366 with the corresponding production log 322, and then the production Identify the differences between network model 354 (i.e., the current VPC network 208) and simulated network model 356 (i.e., VPC network 208 with parameter changes 84).

[0039] In addition to the log replayer 360, which performs a dynamic analysis of the simulated network model 356 using a sample workflow provided in the network log 322, the change analysis system 304 of the network change simulator 330 may include a network analyzer 370 that performs a static analysis of the simulated network model 356. Here, the network analyzer 370 is configured to perform validation tests of the simulated network model 356 to identify potential problems with the proposed parameter changes 84. For example, the network analyzer 370 may perform a comparison of the parameter changes 84 against the production network parameters 82 (e.g., static analysis, configuration checks with invariance, etc.) to highlight the differences between the production network model 354 and the simulated network model 356. In some examples, the network monitor 310 and the network analyzer 370 are integrated within the same module to perform both monitoring and analysis functions.

[0040] The network analyzer 370 may be able to operate to assess the overall health of the network simulation model 356. For example, the network analyzer 370 may perform configuration checks to identify unused routes and broken connections, monitor resource utilization and quotas within the network simulation model 356, perform IP address duplication checks within the network simulation model 356, and / or identify resource capacity degradation due to suboptimal network health. The network analyzer 370 may analyze the firewall rules and firewall hits of the network simulation model 356 to identify potential security issues in the network simulation model 356. Furthermore or alternatively, the network analyzer 370 may analyze the simulated network model 356 to identify whether elements of the network simulation model 356, such as subnets, firewalls, and load balancers, are duplicated and / or underutilized.

[0041] Based on the results of dynamic analysis in the log replayer 360 and / or static analysis in the network analyzer 370, the network change simulator 330 generates a change impact report 332, which may be presented to user 12 via user device 20. The change impact report 332 identifies the impact on network reachability, firewalls, search intent rules, security compliance rules, and resource quotas / utilization of VPC 208 if the parameter change 84 is implemented. Once received by user device 20, the change impact report 332 is presented to user 12 so that user device 20 can evaluate whether to accept, reject, or modify the pending parameter change 84. As shown in Figure 3 and described later, user 12 may use the change impact report 332 to decide whether to accept, reject, or edit the parameter change 84.

[0042] Next, referring to Figure 3, an exemplary workflow 400 is provided for a user 12 that interfaces with the network change simulator 330 via a user device 20. In block 402, user 12 or network monitor 310 generates a change request 80 that includes a parameter change 84. In block 404, network analyzer 370 analyzes the parameter change 84 and generates static analysis impact reports 332, 332a that identify the effect(s) of the parameter change 84 on the VPC network 208. The static analysis impact report 332a can identify the impact on network reachability, firewall shadow rules and predicted hit rates, search intent rules, security compliance rules, and resource quotas and utilization.

[0043] The network change simulator 330 provides a static analysis impact report 332a to the user device 20, and in decision block 406, user 12 provides instructions on whether the impact of the pending parameter change 84 is acceptable to user 12. If the static analysis impact report 332a indicates that the parameter change 84 will not affect VPC208, or will have a minimal impact, user 12 decides that the pending parameter change 84 is acceptable and proceeds to block 408 to accept the pending parameter change 84. Conversely, the static analysis impact report 332a may clearly indicate that the parameter change 84 will cause a failure in VPC208. In this case, user 12 may respond that the pending parameter change 84 is unacceptable and proceed to decision block 410 to decide whether or not to edit the parameter change 84. If user 12 decides not to edit the parameter change 84, the workflow proceeds to block 412, and the parameter change 84 is rejected.

[0044] In decision block 406, if the impact of the parameter change 84 is clearly acceptable or not, user 12 may instruct the network change simulator 330 to perform log replay in block 414. As described above, log replay 414 is performed on the log replayer 360 by replaying the production log 322 within the simulated network model 356 to generate the simulation log 366. The workflow then proceeds to block 416, where the simulation log 366 is compared with the production log 322 to identify the difference between the production network model 354 (i.e., the current VPC208) and the simulated network model 356 (i.e., the proposed VPC208). The network change simulator 330 then generates a dynamic analysis impact report 332b detailing the difference between the production network model 354 and the simulated network model 356 based on the difference between the production log 322 and the simulation log 366.

[0045] In decision block 418, user 12 reviews the dynamic analysis impact report 332b to determine whether the difference between the production network model 354 and the simulation network model 356 is acceptable. If the difference is acceptable, the workflow proceeds to block 408, and the parameter change 84 is incorporated into VPC208 (408). If the difference is unacceptable, the workflow proceeds to decision block 410, where user 12 decides whether to edit the parameter change 84. If user 12 does not want to edit the parameter change 84 (i.e., the answer is "no" in block 410), the parameter change is rejected in block 412. However, if user 12 decides to edit the parameter change 84, the workflow proceeds to block 420, where user 12 can modify one or more of the parameter changes 84. Once the parameter change 84 is edited in block 420, the workflow returns to block 402, initiating another change request 80 containing the edited parameter change 84. Thus, workflow 400 is repeated until the parameter change 84 is accepted in block 408 or rejected in block 412, thereby allowing user 12 to iteratively modify, simulate, and review the parameter change 84 for VPC208 without interrupting the production VPC208.

[0046] Figure 4 is a flowchart illustrating an exemplary sequence of operations for method 500, which performs a change impact simulation analysis. In operation 502, method 500 performs one or more operations on the data processing hardware 204 against the production network model 354 of the network 208. Method 500 includes receiving parameter changes 84. In operation 504, the data processing hardware 204 generates a simulation network model 356 that includes one or more parameter changes 84. In operation 506, the data processing hardware 204 receives a production network log 322 for the production network model 354. In operation 508, the data processing hardware 204 generates a simulation network log 366 by simulating the execution of the production network log 322 in the simulation network model 356. Method 500 further includes, in operation 510, the data processing hardware 204 analyzing the simulation network log 366, and in operation 512, the data processing hardware generates a network impact report 332 that includes the impact of the parameter changes 84 on the network 208.

[0047] Figure 5 is a schematic diagram of an exemplary computing device 600 that may be used to carry out the systems and methods described herein. The computing device 600 is intended to represent various forms of digital computers, such as laptops, desktops, workstations, personal digital assistants, servers, blade servers, mainframes, and other suitable computers. The components shown herein, their connections and relationships, and their functions are intended to be illustrative only and are not intended to limit the examples of the inventions described and / or claimed herein.

[0048] The computing device 600 includes a processor 610, memory 620, a storage device 630, a high-speed interface / controller 640 connected to memory 620 and a high-speed expansion port 650, and a low-speed bus 670 and a low-speed interface / controller 660 connected to storage device 630. Each component 610, 620, 630, 640, 650, and 660 are interconnected using various buses and may be mounted on a common motherboard or in other configurations as appropriate. The processor 610 can process instructions to be executed within the computing device 600, including instructions stored in memory 620 or storage device 630, to display graphic information for a graphical user interface (GUI) on an external input / output device such as a display 680 coupled to the high-speed interface 640. In other implementations, multiple processors and / or multiple buses may be used, along with multiple memories and multiple types of memory, as appropriate. Additionally, multiple computing devices 600 may be connected, with each device providing some of the necessary functions (for example, as a server bank, a cluster of blade servers, or a multiprocessor system).

[0049] Memory 620 stores information non-temporarily within the computing device 600. Memory 620 may be a computer-readable medium, a volatile memory unit, or a non-volatile memory unit. Non-temporarily stored memory 620 may be a physical device used by the computing device 600 to temporarily or permanently store programs (e.g., sequences of instructions) or data (e.g., program state information). Examples of non-volatile memory include flash memory and read-only memory (ROM) / programmable read-only memory (PROM) / erasable programmable read-only memory. Electronically erasable programmable read-only memory (EPROM) Examples of volatile memory include EEPROM (typically used for firmware such as boot programs), but are not limited to these. Examples of volatile memory include random access memory (RAM) and dynamic random access memory (dynamic rand This includes, but is not limited to, DRAM, static random access memory (SRAM), and phase change memory (PCM), as well as disks or tapes.

[0050] The storage device 630 can provide high-capacity storage for the computing device 600. In some implementations, the storage device 630 is a computer-readable medium. In various different implementations, the storage device 630 may be an array of devices including floppy disk devices, hard disk devices, optical disk devices, or tape devices, flash memory or other similar solid-state memory devices, or devices in a storage area network or other configuration. In additional implementations, a computer program product is tangibly embodied on an information carrier. When executed, the computer program product includes instructions that perform one or more of the methods described above. The information carrier is a computer-readable medium or a machine-readable medium, such as memory 620, the storage device 630, or memory on the processor 610.

[0051] The high-speed controller 640 manages the bandwidth-intensive operation of the computing device 600, while the low-speed controller 660 manages the less bandwidth-intensive operation. Such task assignments are illustrative only. In some implementations, the high-speed controller 640 is coupled to memory 620, a display 680 (e.g., via a graphics processor or accelerator), and a high-speed expansion port 650 that can accept various expansion cards (not shown). In some implementations, the low-speed controller 660 is coupled to a storage device 630 and a low-speed expansion port 690. The low-speed expansion port 690, which may include various communication ports (e.g., USB, Bluetooth®, Ethernet®, wireless Ethernet), may be coupled to one or more input / output devices such as a keyboard, pointing device, or scanner, or to a network device such as a switch or router, for example, via a network adapter.

[0052] The computing device 600 can be implemented in numerous different forms, as shown in the figure. For example, it can be implemented as a standard server 600a, or multiple times within a group of such servers 600a, as a laptop computer 600b, or as part of a rack server system 600c.

[0053] Various implementations of the systems and techniques described herein include digital electronic circuits and / or optical circuits, integrated circuits, application-specific integrated circuits (ASICs), computer hardware, firmware, These can be implemented in software and / or a combination thereof. These various implementations may be for specific purposes or general purposes and may include implementations in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, at least one input device, and at least one output device coupled to send and receive data and instructions to and from a storage system.

[0054] A software application (i.e., a software resource) can refer to computer software that causes a computing device to perform a task. In some cases, a software application may be called an “application,” “app,” or “program.” Examples of applications include system diagnostic applications, system administration applications, system maintenance applications, word processing applications, spreadsheet applications, and messaging applications. Examples include, but are not limited to, gaming applications, media streaming applications, social networking applications, and gaming applications.

[0055] These computer programs (also known as programs, software, software applications, or code) contain machine instructions for programmable processors and can be implemented in high-level procedural and / or object-oriented programming languages ​​and / or assembly / machine languages. As used herein, the terms “machine-readable medium” and “computer-readable medium” refer to any computer program product, non-temporary computer-readable medium, apparatus and / or device (e.g., magnetic disks, optical disks, memory, programmable logic devices (PLDs)) used to provide machine instructions and / or data to a programmable processor, including machine-readable mediums that receive machine instructions as machine-readable signals. The term “machine-readable signal” refers to machine instructions and / or data. Alternatively, it refers to any signal used to provide data to a programmable processor.

[0056] The processes and logic flows described herein are executed by one or more programmable processors, also known as data processing hardware, which run one or more computer programs to perform functions by performing operations on input data and generating outputs. Furthermore, the processes and logic flows are executed by dedicated logic circuits, such as field programmable gate arrays (FPGAs) or special This can be done using application-specific integrated circuits (ASICs). Processors suitable for executing computer programs include, as an example, both general-purpose and special-purpose microprocessors, and any one or more processors in any type of digital computer. Generally, a processor receives instructions and data from read-only memory or random-access memory or both. Essential elements of a computer are a processor for executing instructions and one or more memory devices for storing instructions and data. Generally, a computer will also be operablely connected to one or more mass storage devices for storing data, including, for example, magnetic, magneto-optical disks, or optical disks, or to receive data from them, transfer data to them, or both. However, a computer is not required to have such devices. Computer-readable media suitable for storing computer program instructions and data include, as an example, semiconductor memory devices, such as EPROM, EEPROM, and flash memory devices; magnetic disks, such as internal hard disks or removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks, including all forms of non-volatile memory, media, and memory devices. The processor and memory can be complemented by or integrated into dedicated logic circuits.

[0057] To provide user interaction, one or more aspects of this disclosure can be implemented on a computer having a display device for displaying information to the user, such as a cathode ray tube (CRT), liquid crystal display (LCD) monitor, or touchscreen, and optionally a keyboard and pointing device, such as a mouse or trackball, to which the user can provide input to the computer. It is also possible to provide user interaction using other types of devices; for example, the feedback provided to the user may be any form of sensory feedback, such as visual feedback, auditory feedback, or haptic feedback, and input from the user may be received in any form, including acoustic, speech, or haptic input. Furthermore, the computer may provide information to the device used by the user. By sending and receiving documents, for example, by responding to a request received from a web browser and sending a web page to the web browser on the user's client device, it is possible to interact with the user.

[0058] While several embodiments have been described, it will be understood that various modifications can be made without departing from the spirit and scope of this disclosure. Therefore, other embodiments fall within the scope of the following claims.

Claims

1. A method executed by a computer, which, when executed by data processing hardware, causes the data processing hardware to perform an operation, wherein the operation is: Based on the workflow of the production network model, a simulation network model is generated that includes one or more parameter changes to the production network model. The workflow of the production network model described above is reproduced as a simulated network flow within the simulated network model, This includes generating a report showing the differences between the production network model and the simulation network model based on reproducing the workflow of the production network model as the simulation network flow within the simulation network model, wherein the report shows the effect or action of one or more parameter changes on the production network model, and the action further includes Based on the report showing the difference between the aforementioned production network model and the aforementioned simulation network model, Receiving acceptance of the change of one or more parameters included in the simulation network model, A method comprising implementing the one or more parameter changes in the production network model.

2. The aforementioned operation further, Receiving production network logs including the workflow of the aforementioned production network model, The method according to claim 1, further comprising generating a simulation network log based on the simulation network flow.

3. A method executed by a computer, which, when executed by data processing hardware, causes the data processing hardware to perform an operation, wherein the operation is: Based on the workflow of the production network model, a simulation network model is generated that includes one or more parameter changes to the production network model. The workflow of the production network model described above is reproduced as a simulated network flow within the simulated network model, Based on reproducing the workflow of the production network model as the simulated network flow within the simulated network model, a report showing the difference between the production network model and the simulated network model is generated. Based on the report showing the difference between the aforementioned production network model and the aforementioned simulation network model, Receiving acceptance of the change of one or more parameters included in the simulation network model, To implement the above-mentioned change of one or more parameters in the production network model, Receiving production network logs including the workflow of the aforementioned production network model, This includes generating a simulation network log based on the aforementioned simulation network flow, To generate a report showing the difference between the production network model and the simulation network model, The aforementioned production network log is compared with the aforementioned simulation network log, A method comprising identifying the difference between the production network log and the simulation network log.

4. The method according to claim 2 or 3, wherein the production network log is one of the virtual private connection flow logs or firewall rule logs.

5. A method executed by a computer, which, when executed by data processing hardware, causes the data processing hardware to perform an operation, wherein the operation is: Based on the workflow of the production network model, a simulation network model is generated that includes one or more parameter changes to the production network model. The workflow of the production network model described above is reproduced as a simulated network flow within the simulated network model, Based on reproducing the workflow of the production network model as the simulated network flow within the simulated network model, a report showing the difference between the production network model and the simulated network model is generated. Based on the report showing the difference between the aforementioned production network model and the aforementioned simulation network model, Receiving acceptance of the change of one or more parameters included in the simulation network model, To implement the above-mentioned change of one or more parameters in the production network model, A method comprising determining the effect of the changes to one or more parameters on the production network model.

6. The method according to claim 5, wherein determining the effects of changing one or more parameters includes determining the effects on at least one of the following: network reachability, firewall shadow rules / predicted firewall hit rate, search intent rules, security compliance rules, or resource quotas / utilization.

7. A method performed by a computer, which, when executed by data processing hardware, causes the data processing hardware to perform an operation, wherein the operation is: Based on the workflow of the production network model, a simulation network model is generated that includes one or more parameter changes to the production network model. The workflow of the production network model described above is reproduced as a simulated network flow within the simulated network model, Based on reproducing the workflow of the production network model as the simulated network flow within the simulated network model, a report showing the difference between the production network model and the simulated network model is generated. Based on the report showing the difference between the aforementioned production network model and the aforementioned simulation network model, Receiving acceptance of the change of one or more parameters included in the simulation network model, This includes implementing the one or more parameter changes in the aforementioned production network model, A method for generating the simulation network model, comprising incorporating the one or more parameter changes into the production network model in fixed amounts.

8. The method according to any one of claims 1 to 7, wherein the operation further includes receiving one or more invariant parameters of the production network model.

9. A method performed by a computer, which, when executed by data processing hardware, causes the data processing hardware to perform an operation, wherein the operation is: Based on the workflow of the production network model, a simulation network model is generated that includes one or more parameter changes to the production network model. The workflow of the production network model described above is reproduced as a simulated network flow within the simulated network model, Based on reproducing the workflow of the production network model as the simulated network flow within the simulated network model, a report showing the difference between the production network model and the simulated network model is generated. Based on the report showing the difference between the aforementioned production network model and the aforementioned simulation network model, Receiving acceptance of the change of one or more parameters included in the simulation network model, To implement the above-mentioned change of one or more parameters in the production network model, A method comprising modifying the configuration of the network if the effects of the changes to one or more parameters on the network are acceptable.

10. A method executed by a computer, which, when executed by data processing hardware, causes the data processing hardware to perform an operation, wherein the operation is: Based on the workflow of the production network model, a simulation network model is generated that includes one or more parameter changes to the production network model. The workflow of the production network model described above is reproduced as a simulated network flow within the simulated network model, Based on reproducing the workflow of the production network model as the simulated network flow within the simulated network model, a report showing the difference between the production network model and the simulated network model is generated. Based on the report showing the difference between the aforementioned production network model and the aforementioned simulation network model, Receiving acceptance of the change of one or more parameters included in the simulation network model, This includes implementing the one or more parameter changes in the aforementioned production network model, A method comprising analyzing the simulated network flow within the simulated network model to determine whether the simulated network model affects the network intent of the production network model.

11. Data processing hardware and A system comprising memory hardware that communicates with the data processing hardware, wherein the memory hardware, when executed by the data processing hardware, stores instructions that cause the data processing hardware to execute the method according to any one of claims 1 to 10.

12. A method executed by a computer, which, when executed by data processing hardware, causes the data processing hardware to perform an operation, wherein the operation is: Based on the workflow of the production network model, a simulation network model is generated that includes parameter changes to the production network model. The workflow of the production network model described above is reproduced as a simulated network flow within the simulated network model, This includes generating a report showing the differences between the production network model and the simulation network model based on reproducing the workflow of the production network model as the simulation network flow within the simulation network model, wherein the report shows the effect or action of the parameter change on the production network model, and the operation further includes Receiving a rejection of the parameter change included in the simulation network model, A method performed by a computer, which includes, based on receiving a rejection of the parameter change, rejecting the implementation of the parameter change in the production network model.

13. A method executed by a computer, which, when executed by data processing hardware, causes the data processing hardware to perform an operation, wherein the operation is: Based on the workflow of the production network model, a simulation network model is generated that includes parameter changes to the production network model. The workflow of the production network model described above is reproduced as a simulated network flow within the simulated network model, Based on reproducing the workflow of the production network model as the simulated network flow within the simulated network model, a report showing the difference between the production network model and the simulated network model is generated. Receiving a rejection of the parameter change included in the simulation network model, Based on receiving a rejection of the parameter change, the production network model rejects the implementation of the parameter change. Receiving a second parameter change of the aforementioned simulation network model, Adjusting the simulation network model to include the second parameter change from the production network model, The workflow of the production network model is reproduced as a second simulation network flow within the adjusted simulation network model. Based on reproducing the workflow of the production network model as the second simulation network flow in the adjusted simulation network model, a second report is generated showing the difference between the production network model and the adjusted simulation network model. Receiving acceptance of the second parameter change included in the adjusted simulation network model, A method comprising implementing the second parameter change in the production network model based on receiving acceptance of the second parameter change.

14. The aforementioned operation further, Receiving production network logs including the workflow of the aforementioned production network model, The method according to claim 12 or 13, further comprising generating a simulation network log based on the simulation network flow.

15. A method executed by a computer, which, when executed by data processing hardware, causes the data processing hardware to perform an operation, wherein the operation is: Based on the workflow of the production network model, a simulation network model is generated that includes parameter changes to the production network model. The workflow of the production network model described above is reproduced as a simulated network flow within the simulated network model, Based on reproducing the workflow of the production network model as the simulated network flow within the simulated network model, a report showing the difference between the production network model and the simulated network model is generated. Receiving a rejection of the parameter change included in the simulation network model, Based on receiving a rejection of the parameter change, the production network model rejects the implementation of the parameter change. Receiving production network logs including the workflow of the aforementioned production network model, This includes generating a simulation network log based on the aforementioned simulation network flow, To generate a report showing the difference between the production network model and the simulation network model, The aforementioned production network log is compared with the aforementioned simulation network log, A method comprising identifying the difference between the production network log and the simulation network log.

16. The method according to claim 14 or 15, wherein the production network log is one of the virtual private connection flow logs or firewall rule logs.

17. A method executed by a computer, which, when executed by data processing hardware, causes the data processing hardware to perform an operation, wherein the operation is: Based on the workflow of the production network model, a simulation network model is generated that includes parameter changes to the production network model. The workflow of the production network model described above is reproduced as a simulated network flow within the simulated network model, Based on reproducing the workflow of the production network model as the simulated network flow within the simulated network model, a report showing the difference between the production network model and the simulated network model is generated. Receiving a rejection of the parameter change included in the simulation network model, Based on receiving a rejection of the parameter change, the production network model rejects the implementation of the parameter change. A method comprising determining the impact of the parameter changes on the production network model.

18. Determining the effects of the parameter changes is: Network reachability, Firewall shadow rules, predicted firewall hit rate, Search intent rules, Security compliance rules, or The method according to claim 17, comprising determining the impact on at least one of resource quotas and utilization rates.

19. The method according to any one of claims 12 to 18, wherein the operation further includes receiving one or more invariant parameters of the production network model.

20. A method performed by a computer, which, when executed by data processing hardware, causes the data processing hardware to perform an operation, wherein the operation is: Based on the workflow of the production network model, a simulation network model is generated that includes parameter changes to the production network model. The workflow of the production network model described above is reproduced as a simulated network flow within the simulated network model, Based on reproducing the workflow of the production network model as the simulated network flow within the simulated network model, a report showing the difference between the production network model and the simulated network model is generated. Receiving a rejection of the parameter change included in the simulation network model, Based on receiving a rejection of the parameter change, the production network model rejects the implementation of the parameter change. A method comprising receiving a modification of the parameter change in response to a rejection of the parameter change.

21. A method executed by a computer, which, when executed by data processing hardware, causes the data processing hardware to perform an operation, wherein the operation is: Based on the workflow of the production network model, a simulation network model is generated that includes parameter changes to the production network model. The workflow of the production network model described above is reproduced as a simulated network flow within the simulated network model, Based on reproducing the workflow of the production network model as the simulated network flow within the simulated network model, a report showing the difference between the production network model and the simulated network model is generated. Receiving a rejection of the parameter change included in the simulation network model, This includes, based on receiving a rejection of the parameter change, rejecting the implementation of the parameter change in the production network model, A method comprising analyzing the simulated network flow within the simulated network model, which includes determining whether the simulated network model affects the network intent of the production network model.

22. Data processing hardware and A system comprising memory hardware that communicates with the data processing hardware, wherein the memory hardware, when executed by the data processing hardware, stores an instruction that causes the data processing hardware to execute the method according to any one of claims 12 to 21.