System and method for performing configuration audit for a network entity
The system automates configuration audits using linguistic parameters and user interface libraries to ensure network entities comply with policies, enhancing efficiency and security.
Patent Information
- Application Number
- PCT/IN2025/050392
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-21
- Filing Date
- 2025-03-19
- Publication Date
- 2025-09-25
AI Technical Summary
Existing network configuration auditing systems require manual intervention for data upload and processing, especially for network entities configured to meet multiple protocols, leading to inefficiencies and challenges in ensuring compliance with security, performance, and organizational policies.
A system and method for performing configuration audits using a user interface library that enables the creation of configuration audit rules through linguistic parameters, allowing automated parsing and generation of compliance reports based on predefined rules.
Facilitates efficient and automated configuration audits, ensuring network entities align with security and organizational policies, improving system performance and security, and enabling routine management of network configurations.
Smart Images

Figure IN2025050392_25092025_PF_FP_ABST
Abstract
Description
SYSTEM AND METHOD FOR PERFORMING CONFIGURATION AUDIT FOR A NETWORK ENTITYRESERVATION OF RIGHTS
[0001] A portion of the disclosure of this patent document contains material, which is subject to intellectual property rights such as, but are not limited to, copyright, design, trademark, Integrated Circuit (IC) layout design, and / or trade dress protection, belonging to Jio Platforms Limited (JPL) or its affiliates (hereinafter referred as owner). The owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent files or records, but otherwise reserves all rights whatsoever. All rights to such intellectual property are fully reserved by the owner.TECHNICAL FIELD
[0002] The present disclosure relates generally to a field of telecommunication. More particularly, the present disclosure relates to a system and a method for performing a configuration audit for a network entity in a communication network.DEFINITIONS
[0003] As used in the present disclosure, the following terms are generally intended to have the meaning as set forth below, except to the extent that the context in which they are used to indicate otherwise.
[0004] The expression ‘configuration file’ used hereinafter in the specification refers to a collection of configuration data obtained from a network entity. One example of a configuration file is the configuration data obtained from the network entity running an operating system in response to a “show run” command. Other network entities from other vendors may provide similar or different configuration files. The present disclosure is not limited to any configuration file type(s). Configuration files may be obtained from network devices, such as commands sent via Simple Network Management Protocol (SNMP).
[0005] The expression ‘parsing’ used hereinafter in the specification refers to a process of breaking down a sentence or a string of text into its constituent parts of speech and analyzing their relationships to one another.
[0006] The expression ‘configuration audit’ used hereinafter in the specification refers to a process of examination and verification of the settings and parameters configured on the network entity. The process ensures that the network entity configuration aligns with security policies, organizational policies, and operational requirements.
[0007] The expression ‘configuration data’ used hereinafter in the specification refers to the configuration data of a network entity such as router, modem, etc. The configuration data consist of settings and parameters of the network entity. The configuration data may include, but is not limited to, the operating system of the network entity, a hostname, a firewall statement, and a quality of service (QoS) statement of a network.
[0008] The expression ‘configuration audit rules’ used hereinafter in the specification refers to configurations or settings that enable logging and monitoring of network traffic and network activities for the purpose of security auditing and compliance.
[0009] The expression ‘compliance test’ used hereinafter in the specification refers to a test conducted for a network entity to ensure that the configuration, behavior, and security measures align with the organization's standards, guidelines, or regulations.
[0010] The expression ‘linguistic parameters’ used hereinafter in the specification refers to specific language settings implemented within a network entity. These settings are utilized to instruct and audit the configuration of the network entity.
[0011] The expression ‘Configuration command’ used hereinafter in the specification refers to a command used to set up or modify the settings and parameters of a system, device, software, or network. These commands allow users or administrators to adjust the behavior of the system (or device or software or application) to meet specific needs, preferences, or requirements.
[0012] The expression ‘Configuration audit command’ used hereinafter in the specification refers to a command that may be used to perform configuration audits or checks on various aspects of a network entity configuration.
[0013] The expression 'declarative syntax’ used hereinafter in the specification refers to a type of syntax that emphasizes describing the desired result of a configuration for a network entity rather than specifying the exact sequence of steps needed to achieve that result.
[0014] The expression 'Silo mode’ used hereinafter in the specification refers to a mode in which the command is independent / not hived anything in the command.
[0015] The expression 'Solo hived entity’ used hereinafter in the specification refers to an entity having only one command under a particular command
[0016] The expression 'Non-solo hived entity’ used hereinafter in the specification refers to an entity having multiple commands under a particular command.
[0017] The expression 'Verbose' used hereinafter in the specification refers to a linguistic parameter used to detect whether a particular audit command is as it is present in the configuration file.
[0018] The expression 'succeeds' used hereinafter in the specification refers to a linguistic parameter used to detect whether any command succeeds or follows another command.
[0019] The expression 'immediately succeeds' used hereinafter in the specification refers to a linguistic parameter used to detect that a command has succeeded the particular command immediately.
[0020] The expression 'precedes' used hereinafter in the specification refers to a linguistic parameter used to detect whether another command has preceded the command.
[0021] The expression 'does not care' used hereinafter in the specification refers to a linguistic parameter used to check whether a particular entry exists in a list or no other entry after a particular command.
[0022] These definitions are in addition to those expressed in the art.BACKGROUND OF THE DISCLOSURE
[0023] The following description of related art is intended to provide background information pertaining to the field of the disclosure. This section may include certain aspects of the art that may be related to various features of the present disclosure. However, it should be appreciated that this section be used only to enhance the understanding of the reader with respect to the present disclosure, and not as admissions of prior art.
[0024] Network configuration management involves discovering devices, monitoring the status and configuration of devices, and maintaining the inventory. The key elements of network configuration are software configuration, host configuration, and network entity configuration. For example, network entityconfiguration may be a router configuration management, like network configuration management, which is the ongoing process of overseeing and maintaining the configuration of routers. The router configuration management includes making changes to configurations as needed and ensuring that those changes are uniform across devices.
[0025] Auditing systems typically perform audits by parsing configuration files of network entities (for example, routers) and verifying the existence, format, and order of the instructions in configuration files of the network entities. The configuration files define the device configuration, the functioning of the network entities, etc. Conventional auditing systems require users to upload configuration files, perform audit checks, etc., manually. Moreover, most network entities configured to meet the requirements of multiple protocols require bulky configuration files that demand considerable effort from auditing systems for data acquisition and processing. Proper regulation of an organization's operations is essential to ensure the quality of products, manufacturing processes, financial operations, human resource management, and more. Compliance with numerous policies is crucial to ensuring product quality, system security, and other factors.
[0026] The auditing systems evaluate and ensure the security, performance, and compliance of the network entities within a network. The process of evaluation and compliance of the network entities needs manual intervention for uploading files, performing audit checks, etc. Therefore, there is a need to provide a method and a system that can address the shortcomings of existing solutions.SUMMARY OF THE DISCLOSURE
[0027] In an exemplary embodiment, the present disclosure discloses a method for performing a configuration audit for a network entity in a communication network. The method includes retrieving, by a selection module, a configuration fileassociated with the network entity from a central database based on a user input received via a user interface. The method further includes parsing, by a syntax parser module, the retrieved configuration file to determine an existence of at least one configuration audit command in a predefined mode. The method further includes based on the parsing, executing, by the syntax parser module, the at least one configuration audit command with at least one linguistic parameter to perform a compliance test on the parsed configuration file. The method further includes generating, by a report generation module, a configuration audit report for the network entity based on the compliance test.
[0028] In some embodiments, the user input comprises a trigger for initiating the configuration audit for the network entity and the at least one configuration audit command.
[0029] In some embodiments, the predefined mode comprises at least one of a silo mode, a solo hived entity and a non-solo hived entity.
[0030] In some embodiments, the at least one linguistic parameter comprises verbose, succeeds, immediately succeeds, precedes, or does not care.
[0031] In some embodiments, the at least one linguistic parameter facilitates declarative syntax for parsing the configuration file.
[0032] In some embodiments, the compliance test is performed to determine whether the at least one configuration audit command exists in the configuration file according to one or more configuration audit rules of a plurality of configuration audit rules.
[0033] In some embodiments, the plurality of configuration audit rules is stored in a rule library accessible via the user interface, and where the one or more configuration audit rules are based on the at least one linguistic parameter.
[0034] In some embodiments, the configuration audit report indicates whether the at least one configuration audit command exists in the configuration file according to the one or more configuration audit rules.
[0035] In another exemplary embodiment, the system for performing a configuration audit for a network entity in a communication network is described. The system comprises a selection module configured to retrieve a configuration file associated with the network entity from a central database based on user input received via a user interface. The system further comprises a syntax parser module configured to parse the retrieved configuration file based on the at least one linguistic parameter and execute the at least one configuration audit command with at least one linguistic parameter to perform a compliance test on the parsed configuration file, based on the parsing. The system further comprises a report generation module configured to generate of configuration audit report for the network entity based on the compliance test.
[0036] In yet another exemplary embodiment, a user equipment for performing a configuration audit for a network entity in a communication network is described. The user equipment comprises a processor and a computer readable storage medium storing a set of instruction for execution by the processor. The set of instructions comprises inputting an input by a user via a user interface. The input comprises a trigger for initiating a configuration audit for a network entity and at least one configuration audit command. The set of instructions further comprises receiving a configuration audit report for the network entity on the user interface.
[0037] In some embodiments, the configuration audit report indicates whether the at least one configuration audit command exists in a configuration file according to one or more configuration audit rules.
[0038] In another embodiment, a computer program product comprising a non- transitory computer-readable medium comprising set of instructions. The instructions may be executed by one or more processor(s) to perform a method for performing a configuration audit for a network entity in a communication network. The method includes retrieving, by a selection module, a configuration file associated with the network entity from a central database based on a user input received via a user interface. The method further includes parsing, by a syntax parser module, the retrieved configuration file to determine an existence of at least one configuration audit command in a predefined mode. The method further includes based on the parsing, executing, by the syntax parser module, the at least one configuration audit command with at least one linguistic parameter to perform a compliance test on the parsed configuration file. The method further includes generating, by a report generation module, a configuration audit report for the network entity based on the compliance test.
[0039] The foregoing general description of the illustrative embodiments and the following detailed description thereof are merely exemplary aspects of the teachings of this disclosure, and are not restrictive.OBJECTS OF THE DISCLOSURE
[0040] Some of the objects of the present disclosure, which at least one embodiment herein satisfies are listed herein below.
[0041] An object of the present disclosure is to provide a system and a method that performs configuration audits for network entities.
[0042] An object of the present disclosure is to provide a system and a method for formulating and commissioning configuration audit rules through a user interface exposed library.
[0043] An object of the present disclosure is to provide a system and a method that uses linguistic parameters to parse configuration files of network entities effectively.
[0044] An object of the present disclosure is to provide a system and a method that generates configuration audit reports corresponding to the network entities based on compliance tests.
[0045] An object of the present disclosure is to provide a system and a method that automatically performs and manages compliance policies of network entities.
[0046] Other objects and advantages of the present disclosure will be more apparent from the following description, which is not intended to limit the scope of the present disclosure.BRIEF DESCRIPTION OF DRAWING
[0047] The accompanying drawings, which are incorporated herein, and constitute a part of this disclosure, illustrate exemplary embodiments of the disclosed methods and systems in which like reference numerals refer to the same parts throughout the different drawings. Components in the drawings are not necessarily to scale; emphasis is instead being placed upon clearly illustrating the principles of the present disclosure. Some drawings may indicate the components using block diagrams and may not represent the internal circuitry of each component. It will be appreciated by those skilled in the art that disclosure of such drawings includes disclosure of electrical components, electronic components, or circuitry commonly used to implement such components.
[0048] FIG. 1 illustrates an exemplary network architecture for performing a configuration audit for a network entity based on a plurality of configuration auditrules in a communication network, in accordance with an embodiment of the present disclosure.
[0049] FIG. 2 illustrates an exemplary block diagram of the system for performing the configuration audit for the network entity, in accordance with an embodiment of the present disclosure.
[0050] FIG. 3 illustrates an exemplary working of a system architecture for performing the configuration audit for the network entity, in accordance with an embodiment of the present disclosure.
[0051] FIG. 4 illustrates an exemplary flow chart illustrating steps performed by the system for performing a configuration audit for the network entity, in accordance with an embodiment of the present disclosure.
[0052] FIG. 5 illustrates an exemplary flowchart for a method for performing a configuration audit for the network entity, in accordance with an embodiment of the present disclosure.
[0053] FIG. 6 illustrates an exemplary computer system in which or with which the embodiments of the present disclosure may be implemented.
[0054] The foregoing shall be more apparent from the following more detailed description of the disclosure.LIST OF REFERENCE NUMERALS100- Network Architecture102- 1,102-2..., I02-N- User104-1, 104-2... ,104-N- User Equipment106- Network108- System110- Network Entity112- Central Database200 - Block Diagram202- Processor(S)204- Memory206- Interface(S)208- Processing Engine(S)210- Database212- Selection Module214- Syntax Parser Module216- Rule Library218- Report Generation Module220- Other Engine(S)300 - System Architecture302 - Rule List400 - Flow Diagram500 - Method Flow Diagram600 - Computer System610- External Storage Device620- Bus630- Main Memory640- Read-Only Memory650- Mass Storage Device660- Communication Port(S)670- ProcessorDETAILED DESCRIPTION
[0055] In the following description, for the purposes of explanation, various specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. It will be apparent, however, that embodiments of the present disclosure may be practiced without these specific details. Several features described hereafter can each be used independently of one another or with any combination of other features. An individual feature may not address any of the problems discussed above or might address only some of the problems discussed above. Some of the problems discussed above might not be fully addressed by any of the features described herein. Example embodiments of the present disclosure are described below, as illustrated in various drawings in which like reference numerals refer to the same parts throughout the different drawings.
[0056] The ensuing description provides exemplary embodiments only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the exemplary embodiments will provide those skilled in the art with an enabling description for implementing an exemplary embodiment. It should be understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the disclosure as set forth.
[0057] Specific details are given in the following description to provide a thorough understanding of the embodiments. However, it will be understood by one of ordinary skill in the art that the embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not toobscure the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail in order to avoid obscuring the embodiments.
[0058] Also, it is noted that individual embodiments may be described as a process that is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination can correspond to a return of the function to the calling function or the main function.
[0059] The word “exemplary” and / or “demonstrative” is used herein to mean serving as an example, instance, or illustration. For the avoidance of doubt, the subject matter disclosed herein is not limited by such examples. In addition, any aspect or design described herein as “exemplary” and / or “demonstrative” is not necessarily to be construed as preferred or advantageous over other aspects or designs, nor is it meant to preclude equivalent exemplary structures and techniques known to those of ordinary skill in the art. Furthermore, to the extent that the terms “includes,” “has,” “contains,” and other similar words are used in either the detailed description or the claims, such terms are intended to be inclusive like the term “comprising” as an open transition word without precluding any additional or other elements.
[0060] Reference throughout this specification to “one embodiment” or “an embodiment” or “an instance” or “one instance” means that a particular feature, structure, or characteristic described in connection with the embodiment is includedin at least one embodiment of the present disclosure. Thus, the appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0061] The terminology used herein is to describe particular embodiments only and is not intended to be limiting the disclosure. As used herein, the singular forms “a”, “an”, and “the” are intended to include the plural forms as well, unless the context indicates otherwise. It will be further understood that the terms “comprises” and / or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term “and / or” includes any combinations of one or more of the associated listed items. It should be noted that the terms “mobile device”, “user equipment”, “user device”, “communication device”, “device” and similar terms are used interchangeably for the purpose of describing the invention. These terms are not intended to limit the scope of the invention or imply any specific functionality or limitations on the described embodiments. The use of these terms is solely for convenience and clarity of description. The invention is not limited to any particular type of device or equipment, and it should be understood that other equivalent terms or variations thereof may be used interchangeably without departing from the scope of the invention as defined herein.
[0062] While considerable emphasis has been placed herein on the components and component parts of the preferred embodiments, it will be appreciated that many embodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and otherchanges in the preferred embodiment, as well as other embodiments of the disclosure, will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter is to be interpreted merely as illustrative of the disclosure and not as a limitation.
[0063] Network entities (such as routers) use a text file called a configuration file that represents their configuration state. A user can obtain a copy of the configuration file through a command or other known mechanisms. The configuration file is significant for a network manager as it reflects the operational configuration of the network entity. The format of the configuration file may differ from the original configuration due to the changes made through the CLI (Command Line Interface), SNMP (Simple Network Management Protocol), or other methods. Therefore, the network manager must know how to read the configuration file.
[0064] However, the users may find it difficult to read and understand the configuration file due to its large size and complexity. The configuration file can be of a large size and may have hierarchical contexts. Each context includes specific commands corresponding to certain network technologies, such as routing protocols, access lists, and multicasting. Moreover, command lines in one context may refer to command lines located in different parts of the configuration file, making it difficult for the user to find the desired context.
[0065] The present disclosure discloses a system and a method for performing a configuration audit for a plurality of network entities. The system is configured to create configuration audit rules for performing the configuration audit on the network entities. The system performs the configuration audit on the network entities using their respective configuration files. The configuration files may be text files consisting of repetitive text with placement significance.
[0066] The present disclosure uses a user interface library that enables the creation of configuration audit rules through a set of linguistic parameters. The set of linguistic parameters forms a backbone of declarative syntax required to parse the configuration files effectively. For example, the set of linguistic parameters may include verbose, succeeds, immediately succeeds, precedes, and doesn't care. Each of these parameters plays a crucial role in the parsing process and helps to ensure that the configuration audit rules are accurate and effective.
[0067] The present disclosure is configured to audit the network entity configuration files accurately and efficiently, helping to improve overall system performance and security. Additionally, the user interface library makes it easy to retire (replace) old configuration audit rules and create new configuration audit rules, which can help to ensure that the network entities remain up-to-date and secure over time.
[0068] Moreover, the present disclosure may help an organization looking to take control of network entity configurations. The present system provides automated network entity management that includes tracking and managing network entity configurations by allowing the user to implement routine, wide-scale changes using predefined network entity configuration templates.
[0069] In an aspect, performing a configuration audit for a network entity involves auditing the network entity based on the plurality of configuration audit rules. The configuration audit rules include defining specific regulations or guidelines to ensure the network entity settings align with security policies, organizational policies, compliance policies, and operational requirements.
[0070] Hereinafter, exemplary embodiments of the present disclosure will be described with reference to the accompanying drawings.
[0071] FIG. 1 illustrates a network architecture 100 for performing a configuration audit for a network entity based on a plurality of configuration audit rules in a communication network, in accordance with an embodiment of the present disclosure.
[0072] Referring to FIG. 1, the network architecture 100 may include one or more computing devices or user equipments 104-1, 104-2... 104-N associated with one or more users 102-1, 102-2... 102-N in an environment. The network architecture 100 may also include a network entity 110, a central database 112, and a network 106.
[0073] A person of ordinary skill in the art will understand that one or more users 102-1, 102-2...102-N may be individually referred to as the user 102 and collectively referred to as the users 102. Similarly, a person of ordinary skill in the art will understand that one or more user equipments 104-1, 104-2...104-N may be individually referred to as the user equipment 104 and collectively referred to as the user equipment 104. A person of ordinary skill in the art will appreciate that the terms “computing device(s)” and “user equipment” may be used interchangeably throughout the disclosure. Although three user equipments 104 are depicted in FIG. 1, however any number of the user equipments 104 may be included without departing from the scope of the ongoing description.
[0074] In an embodiment, the user equipment 104 may include, but is not limited to, a handheld wireless communication device (e.g., a mobile phone, a smartphone, a phablet device, and so on), a wearable computer device(e.g., a head-mounted display computer device, a head-mounted camera device, a wristwatch computer device, and so on), a laptop computer, a tablet computer, or another type of portable computer, a media playing device, a portable gaming system, and / or any other type of computer device with wireless communication capabilities, and the like. In an embodiment, the user equipment 104 may include, but is not limited to, any electrical, electronic,electro-mechanical, or an equipment, or a combination of one or more of the above devices such as virtual reality (VR) devices, augmented reality (AR) devices, laptop, a general-purpose computer, desktop, personal digital assistant, tablet computer, mainframe computer, or any other computing device. The user equipment 104 may include one or more in-built or externally coupled accessories including, but not limited to, a visual aid device such as a camera, an audio aid, a microphone, a keyboard, and input devices for receiving input from the user 102 or the entity such as touch pad, touch enabled screen, electronic pen, and the like.
[0075] In an embodiment, each of the user equipment 104-1, 104-2... 104-N includes a user interface via which the user 102 may provide one or more user inputs. In an aspect, user input may include a storage path address for retrieving a configuration file of a network entity 110. In some examples, the user input may include selecting the configuration file of the network entity 110 via the user interface of the user equipment 104.
[0076] In some examples, the user input may include a trigger to initiate the automatic configuration audit for the network entity 110. It may be understood that the user input may be any input that facilitates the automatic configuration audit for the network entity 110. A person of ordinary skill in the art will appreciate that the user equipment 104 may not be restricted to the mentioned devices and various other devices may be used.
[0077] In an aspect, the central database 112 stores the configuration file of the network entity 110. In an aspect, the network entity 110 may include, but is not limited to, a router, a switch, a firewall, a modem, and a server. In an aspect, the network entity 110 may have a configuration file associated with it. The configuration file may include a collection of configuration data obtained from the network entity 110. One example of a configuration file is the configuration data obtained from the network entity 110 running an operating system in response to a“show run” command. Each network entity manufacturer may use different commands and syntax based on the network entity features and capabilities.
[0078] In an exemplary embodiment, the network 106 may include, but not be limited to, at least a portion of one or more networks having one or more nodes that transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc. one or more messages, packets, signals, waves, voltage or current levels, some combination thereof, or so forth. In an exemplary embodiment, the network 106 may include, but not be limited to, a wireless network, a wired network, an internet, an intranet, a public network, a private network, a packet- switched network, a circuit-switched network, an ad hoc network, an infrastructure network, a Public-Switched Telephone Network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, or some combination thereof.
[0079] In an aspect, the central database 112 may store a set of identification parameters of the network entity. The identification parameters may include a MAC address, an IP address, a hostname, a domain name, a device type and a device ID. The central database 112 may also store the configuration file mapped with the identification parameters.
[0080] FIG. 2 illustrates an exemplary block diagram 200 of the system 108 for performing an automatic configuration audit for the network entity 110, in accordance with an embodiment of the present disclosure.
[0081] FIG. 2 with reference to FIG. 1, illustrates the block diagram 200 of the system 108 for performing the configuration audit for the network entity 110 in a communication network 106.
[0082] The system 108 includes one or more processor(s) 202, a memory 204, a processing engine 208, a database 210, and an interface(s) 206. In an exemplary embodiment, the processing engine 208 may include one or more engines selectedfrom any of a selection module 212, a syntax parser module 214, a rule library 216, a report generation module 218, and other modules 220 having functions that may include but are not limited to testing, storage, and peripheral functions, such as wireless communication unit for remote operation, audio unit for alerts and the like.
[0083] In an aspect, the selection module 212 may be configured to retrieve a configuration file associated with the network entity 110 from the central database 112 based on user input received via a user interface of the user equipment 104. In an aspect, the user input may include a trigger for initiating a configuration audit for the network entity 110. The user input may also include a storage path address for retrieving the configuration file of the network entity 110. The user input may include a selection of the configuration file of the network entity 110 via the user interface of the user equipment 104. The user input may include a set of identification parameters of the network entity 110. Further, the user may input at least one configuration audit command.
[0084] In one embodiment, the system 108 may receive an automated configuration audit command to perform an automated configuration audit. To perform the automated configuration audit, the automated configuration audit command may be generated at a predefined time interval or a particular event. The system may receive the automated configuration audit command from any network component (e.g., security component) or any network service (e.g., security service). For example, in a security configuration audit, the “IP finger” command should not be in the router’s configuration file. So, during the security configuration audit set at a predefined time interval (e.g., once in 24 Hrs), the system (i.e., syntax parser module 214 of the FIG. 2) automatically detect the presence of “IP finger” command in the router’s configuration file.
[0085] In an aspect, the configuration file associated with the network entity 110 comprises data corresponding to, but is not limited to, internet protocol (IP)addresses, network configurations, routing, security, network address assignment, quality of service (QoS), host configurations, timing, performance, domain names, password, firewall settings, access control lists (ACLs), user access policies, etc.
[0086] In an aspect, the configuration file associated with the network entity 110 may be retrieved from the central database 112 using the set of identification parameters. The set of identification parameters may include a Media Access Control (MAC), an Internet protocol (IP) address, a hostname, a domain name, a device type, and a device ID. The central database 112 may store the configuration file mapped with the identification parameters.
[0087] In an aspect, one or more configuration audit rules are used from amongst a plurality of configuration audit rules to perform the configuration audit for the network entity 110. In an aspect, the configuration audit rules may be a guideline, or criteria used to check the network entity 110 configuration compliance.
[0088] In an aspect, the configuration audit rules may be created by the selection module 212 based on one or more user inputs received via a user interface. The configuration audit rules may be created or generated in the rule library 216 based on the user input. The rule library 216 may store a rule list for the configuration of the network entity 110. The rule list may include, but is not limited to, a password policy, access control lists (ALCs), and an encryption setting. In an aspect, the rule library 216 may store the plurality of configuration rules in the database 210. In an aspect, the rule library 216 may be a part of the database 210. In an aspect, the user (e.g., network administrator) may change / update rules in the rule library 216 through the user interface. The rule changes cause the codes corresponding to the changed / updated rules to be automatically changed / updated. Further, the changes in rules may include addition or deletion of the rules from the rule library. Based on the addition / deletion of the rules, the codes corresponding to the rules are automatically added / deleted.
[0089] In an aspect, the configuration audit rules may be created by the user. The user may use one or more linguistic parameters to create the configuration audit rules. In an aspect, the user may be a network administrator. The linguistic parameters may include verbose, succeeds, immediately succeeds, precedes, and does not care. The configuration audit rules may be created using declarative syntax. The user may create the audit rules based on the linguistic parameters via the user interface. The user may store the configuration audit rules in the rule library 216. The selection module 212 may use the configuration audit rules based on the network entity 110 to perform the configuration audit.
[0090] In an aspect, the one or more configuration audit rules may be based on one or more linguistic parameters. For example, the configuration audit rules may include specific rules or guidelines to ensure the network entity settings align with security policies, organizational policies, compliance policies, and operational requirements. In an aspect, the one or more linguistic parameters comprise verbose, succeeds, immediately succeeds, precedes, and does not care. In an aspect, the linguistic parameters refer to parameters that define one or more ways in which the router's configuration file is parsed. In an aspect, the verbose parameter is a linguistic parameter used to detect whether a particular audit command is as it is present in the configuration file. In another example, to verify whether a particular access list (e.g., IPvX) exists in the network entity (e.g., router), a command “ipvX access-list XXXX- XXXX-IPvX” is entered with the verbose parameter. If the list for IPvX exists in the configuration file of the network entity (e.g., router), then the network entity (e.g., router) complies with configuration audit rules. Furthermore, in an operative aspect, the verbose parameter is used to detect the presence of a particular access list in the configuration file.
[0091] In an aspect, the immediately succeeds parameter is a linguistic parameter used to detect that a command has succeeded the particular command immediately. Inan operative aspect, the immediately succeeds parameter is used to verify command existence in a pre-determined placement in the configuration file. In an example, to detect the existence “match traffic-class X” under the command “class-map match- any QoS-XXXX-TC”, command “match traffic-class X” is entered with the linguistic parameter with its associated declarative syntax i.e., immediately succeeds and command “class-map match-any QoS-XXXX-TC”. If this exact match (i.e., “match traffic-class X” immediately succeeds under command “class-map match-any QoS- XXXX-TC”) is found in the configuration file, then the network entity (i.e., router) complies with configuration audit rules.
[0092] In an aspect, the succeeds parameter is a linguistic parameter used to detect whether any command succeeds or follows another command.
[0093] In an aspect, the precedes parameter is a linguistic parameter used to detect whether another command has preceded the command.
[0094] In an aspect, the don’t care parameter is a linguistic parameter used to check whether a particular entry exists in a list or no other entry after a particular command.
[0095] In an operative aspect, the succeeds, precedes, and don’t care parameters are collectively used to detect a particular entry in the list. In an example, to find entry “10 permit ipvX xxxx:xxx:xxx:xx00:: / XX any” in the list “ipvX access-list XXXX-XXXX-IPvX”, entering the command “permit ipvX xxxx:xxx:xxx:xx00:: / XX any” with the linguistic parameter “succeeds” with command “ipvX access-list XXXX-XXXX-IPvX” and the linguistic parameter “precedes” the command “ipv6 access-list” with the linguistic parameter don’t care If the command “10 permit ipvX xxxx:xxx:xxx:xx00:: / XX any” finds in the list “ipvX access-list XXXX- XXXX-IPvX, then the network entity (i.e., router) complies with configuration audit rules.
[0096] In an embodiment, the codes corresponding to each linguistic parameter with declarative syntax are set in the rule library. Upon detecting mention of the linguistic parameter in the compliance test, the code corresponding to the linguistic parameter with declarative syntax is automatically executed.
[0097] In an aspect, the syntax parser module 214 may be configured to parse the configuration file to determine an existence of at least one configuration audit command in a predefined mode. The predefined mode comprises at least one of a silo mode, a solo hived entity and a non-solo hived entity. In an aspect, the silo mode refers to a mode in which the command is independent / not hived anything in the command. In an aspect, the solo hived entity refers to an entity having only one command under a particular command. In an aspect, the non-solo hived entity refers to an entity having many commands under a particular command.
[0098] In an exemplary aspect, the process of parsing the configuration file initially involves interpreting and processing the configuration file into a user- readable format. The syntax parser module 214 may transform one data format into another. The syntax parser module 214 may transform machine language into user- readable and vice-versa.
[0099] In an operative aspect, the retrieved configuration file is parsed to determine the existence of at least one configuration audit command in the predefined mode. The syntax parser module 214 determines the at least one configuration audit command is in which predefined mode (silo mode or solo hived entity or non-solo hived entity). The parsed configuration file comprises data that comprises the at least one configuration audit command in the predefined mode.
[0100] In an aspect, the one or more linguistic parameters facilitate a declarative syntax for parsing the configuration file. For example, using declarative syntax for parsing may be a grammar-based approach. The grammar-based approach mayinvolve explicitly defining a parsing rule. The parsing rule may include, but is not limited to, an algorithm for parsing and a data type for extraction. For example, the parsing rule may be used by parsers to recognize and interpret the structure of sentences or expressions. In an aspect, the predefined mode in the parsed configuration file helps in applying the linguistic parameter to the configuration audit command.
[0101] In an example, the configuration audit command may be an ipvX accesslist XXXX-XXXX-IPvX command or a class-map match-any QoS-XXX-TC command. The ipvX access list XXXX-XXXX-IPvX command is used to determine access list of devices connected to the network entity in the multicast service. The class-map match-any QoS-XXXX-TC command is used to detect XXXX's service In an aspect, the configuration audit command may be executed with the associated linguistic parameter.
[0102] In an aspect, based on the parsing, the syntax parser module is configured to execute the at least one configuration audit command with at least one linguistic parameter to perform a compliance test on the parsed configuration file. The compliance test is performed to determine whether the at least one configuration audit command exists in the configuration file according to one or more configuration audit rules of a plurality of configuration audit rules. The plurality of configuration audit rules is stored in the rule library 216 accessible via the user interface. The one or more configuration audit rules are based on the at least one linguistic parameter.
[0103] In one operative aspect, based on the parsing, if the at least one configuration audit command exists in the predefined mode (i.e., silo mode), the syntax parser module 214 executes the at least one configuration audit command with the at least one linguistic parameter (i.e., verbose parameter). Further, if the at least one configuration audit command exists in the predefined mode (i.e., solo entity), the syntax parser module 214 executes the at least one configuration audit command withthe at least one linguistic parameter (i.e., immediately succeeds parameter). Furthermore, if the at least one configuration audit command exists in the predefined mode (i.e., non-solo entity), the syntax parser module 214 executes the at least one configuration audit command with the linguistic parameters (i.e., succeeds parameter, precedes parameter and don’t care parameter).
[0104] Upon detecting the at least one executed configuration audit command is present in the retrieved configuration file according to the at least one linguistic parameter, then the at least one configuration audit command exists in the configuration file according to the configuration audit rules. Further, upon detecting the at least one executed configuration audit command is not present in the retrieved configuration file according to the at least one linguistic parameter, then the at least one configuration audit command does not exist in the configuration file according to the configuration audit rules.
[0105] In an aspect, the report generation module 216 may be configured to generate a configuration audit report for the network entity based on the compliance report. For example, when the configuration file adheres to the one or more configuration audit rules, the compliance report may indicate that the configuration file complies with the one or more configuration audit rules. When the configuration file does not adhere to the one or more configuration audit rules, the compliance report may indicate that the configuration file does not comply with the one or more configuration audit rules.
[0106] In another exemplary aspect, the compliance test may involve checking for any deviation in the one or more configuration audit rules. The compliance test may be performed by executing the configuration audit command on the configuration file. The compliance test may ensure the presence and absence of configuration audit commands according to the one or more configuration audit rules in the configuration file.
[0107] In an aspect, the compliance test is performed to determine whether the at least one configuration audit command exists in the configuration file according to the one or more configuration audit rules. If at least one configuration audit command exists in the configuration file according to one or more configuration audit rules, then the router complies with / adheres to one or more configuration audit rules. If at least one configuration audit command does not exist in the configuration file according to one or more configuration audit rules, then the router does not comply with / adhere to the one or more configuration audit rules. Non-compliance of the router indicates that the router is not working appropriately. On detecting the router does not comply with one or more configuration audit rules, the network administrators have to check and rectify the errors in the configuration file of the router. The report generation module 216 may be configured to generate a compliance report for the network entity 110. The compliance report may be generated based on the compliance test performed on the configuration file. For example, when the configuration file adheres to the one or more configuration audit rules, the compliance report may indicate that the configuration file complies with the one or more configuration audit rules. When the configuration file does not adhere to / comply with the one or more configuration audit rules, the compliance report may indicate that the configuration file does not comply with the one or more configuration audit rules. In an embodiment, the interface(s) 206 (also known as interfacing unit) may comprise a variety of interfaces, for example, interfaces for data input and output devices (I / O), storage devices, and the like. The interface(s) 206 may facilitate communication through the processor(s) 202. The interface(s) 206 may also provide a communication pathway for one or more components of the system 108.
[0108] FIG. 3 illustrates an exemplary working of a system architecture 300 for performing a configuration audit for the network entity 110, in accordance with an embodiment of the present disclosure.
[0109] As shown in FIG. 3 with reference to FIG. 2, the network entity 110 (for example, a router) is communicatively coupled to the system 108. The system 108 may include the selection module 212, the report generation module 218, the rule library 216, and the database 210.
[0110] The network entity 110 connects two or more packet-switched networks or subnetworks. The network entity 110 serves two primary functions: managing network traffic by forwarding data packets to desired IP addresses and allowing the plurality of user equipment 104 to use the same internet connection. The network entity 110 may be configured to establish connectivity among the user equipment 104 and services of the system 108.
[0111] As is known in the art, a network administrator has the capability to obtain configuration files from various network entities in a network. In an example, the network administrator may be configured to obtain the configuration files by sending appropriate Command Line Interface (CLI) commands either directly or via a server. The network administrator may be prompted to obtain configuration files, for example, via user input from the user device via a graphical user interface. Additionally, or alternatively, the network administrator may obtain configuration files as part of various automated processes. The network administrator may store the configuration files in the central database and / or may provide the configuration files for display on the user equipment 104.
[0112] The selection module 212 may be configured to receive one or more user inputs from a user. In an aspect, the selection module 212 may be configured to generate the rule list based on the received one or more user inputs. The user either selects or creates a design filter (a set of rules) to filter certain contexts of command lines from a configuration file of a specific network entity. The rule list may be used for disabling and deleting a particular rule of filtering. In an aspect, the rule list may include the configuration audit rules for the network entity 110. The rule list may bestored in the rule library 216. The rule list may include, but is not limited to, a password policy, access control lists (ALCs), an encryption setting, firewall rules, and compliance checks. In an exemplary aspect, the rule list may differ based on the user input. The user may provide the requirements via the user interface. The selection module 212 may select the desired rule from the rule list. For example, if the user wants to check firewall rules, then the user enters the command corresponding to the firewall rules. In firewall rule, “IP Finger” command should not be present in the configuration file of the router. The IP Finger command provides the subscriber's information (e.g., subscriber name, mail address, terminal they are using, logging time, etc.). Running “IP finger” command on the router shows data corresponding to the customers / subscribers connected to the router. This may cause a security breach in case of hacking. To avoid this, the user (i.e., network administrator) inputs “IP Finger” command over the user interface. If the configuration file comprises the IP finger command, then the router is not compliant with the security rules. The network administrator takes necessary actions to make changes in the configurations of that router. Furthermore, in another example, to check a list of the IPs corresponding to any network entity, the access control list (ACL) rules are applied from the audit rules.
[0113] In an exemplary aspect, the selection module 212 may be a graphical user interface. In an aspect, the user inputs may include selection of a plurality of configuration files having a path associated with a network entity. In another aspect, the user inputs may include selection of the plurality of configuration files from a set of network entities presented via the graphical user interface. In an aspect, the user input may include a trigger for initiating an automatic configuration audit of the network entity 110. In an aspect, the user input may include a network entity ID.
[0114] In an aspect, the selection module 212 may be configured to, via the processor, fetch and execute computer-readable instructions stored in the memory ofthe computing device. The processor 202 may be configured to execute a sequence of instructions of the method to perform an automatic configuration audit, which may be embodied in a program or software. The instructions can be directed to the processor 202, which may subsequently program or otherwise be configured to implement the methods of the present disclosure. In some examples, the processor is configured to control and / or communicate with large databases, perform high-volume transaction processing, and generate reports from large databases.
[0115] In an aspect, the network administrator may be configured to define one or more configuration audit commands corresponding to one or more audit policies for the one or more network entities via the graphical user interface. In an aspect, the defined one or more configuration audit commands may be stored in the rule library 216.
[0116] On receiving the user input, the selection module 212 may be configured to acquire a configuration file corresponding to the network entity 110 based on the network entity ID. The selection module 212 may be configured to automatically fetch the configuration file for the network entity 110 from the database 210 after a predefined time interval. The selection module 212 may be configured to filter the configuration file based on the rule list selected by the user. The syntax parser module 214 may be configured to parse the configuration file by employing a set of predefined parameters. In an example, the set of predefined parameters (linguistic parameters) may include verbose, succeeds, immediately succeeds, precedes, and does not care. In an aspect, the selection module 212 may be configured to generate audit rules using the set of predefined parameters. The syntax parser module 214 may be configured to determine a type of the acquired configurations file. The syntax parser module 214 may be configured to execute a configuration audit command with an associated declarative syntax fetched from the one or more configuration audit rules based on the determined type. In an example, the configuration audit commandmay be an ipvX access-list XXXX-XXXX-IPvX command or a class-map match-any QoS-XXXX-TC.
[0117] The report generation module 218 may be configured to generate a report comprising information about the compliance of network entity 110 based on the execution of the configuration audit command. In an aspect, the report generation module 218 may be configured to display the generated report on a displaying unit or the graphical user interface. In an aspect, the generated report may include information about compliance with policies, status information of the network entity 110, configuration information, or other information about the network entity 110. In an aspect, the generated report may be displayed via a webpage that can include a display of the information in a dashboard fashion, which can include hierarchal representations of information, including statistical information about the network entity.
[0118] The rule library 216 may be configured to store default scenario rules and learning rules, for example, rules indicating whether the network entity 110 requires a reboot or an updation. The network administrator may define one or more configuration audit commands corresponding to one or more audit policies using the user interface.
[0119] In an exemplary aspect, the following use cases may be employed by the system 108 for configuration audit of the network entity 110.
[0120] In an exemplary use case, an audit rule formulation is made using the “verbose” linguistic parameter. The use case involves verifying whether a particular access list exists in the network entity 110. In an aspect, the access list comprises list of parameters (e.g., internet protocols (IPs)) that only query the router. The use case may verify a given statement: ipvX access-list XXXX-XXXX-IPvX exist in the access list. The user via the user interface using a front-end user interface (selectionmodule) may access the rule library 216 and paste the command ipvX access-list XXXX-XXXX-IPvX with the associated declarative syntax being stated as verbose. If the entry as shown above exists in the network entity precisely, the audit will be compliant, else the audit shall show up as non-compliant.
[0121] In another exemplary use case, an audit rule formulation for a hived parameter- Case -Solo Hived entity is made using “immediately succeeds” linguistic parameter. In an aspect, the solo Hived entity refers to an entity having only one command under a particular command. The use case involves verification of nature of placement is hived and pre-determined. The use case may verify a given statement: class-map match-any QoS-XXXX-TC match traffic-class X end-class-map
[0122] The user, via the user interface using a front-end user interface (selection module), may access the rule library 216 and paste the command match traffic-class X any with the associated declarative syntax being stated as immediately succeeds class-map match-any QoS-XXXX-TC. If the network entity comprises the entry shown above and satisfies the declarative syntax conditions of the rule, the audit will be compliant. Otherwise, the audit will be non-compliant.
[0123] Another exemplary use case, an audit rule formulation for a hived parameter-Case-Non-Solo Hived entity is made using “succeeds”, “precedes” and “don’t care” linguistic parameters. In an aspect, the Non-Solo Hived entity refers to an entity having many commands under a particular command. The use case involves verification of a particular entry that exists within an access list (rule list). ipvX access-list XXXX-XXXX-IPvX10 permit ipvX xxxx:xxx:xxx:xx00:: / XX any
[0124] The user via the user interface using a front-end user interface (selection module) may access the rule library 216 and paste the command *.* permit 10 permit ipvX xxxx:xxx:xxx:xxOO:: / XX any any with the associated declarative syntax being stated as succeeds ipvX access-list XXXX-XXXX-IPvX and precedes ipvX accesslist *.* If the network entity comprises the entry shown above and satisfies the declarative syntax conditions of the rule, the audit will be compliant. Otherwise, the audit will be non-compliant.
[0125] FIG. 4 illustrates an exemplary flow chart illustrating steps performed by the system 108 for performing a configuration audit for the network entity 110, in accordance with an embodiment of the present disclosure.
[0126] At step 402, the system 108 may be configured to verify a nature of placement existence for a configuration audit command. In an example, the nature of placement refers to the way an object or entity is situated in a particular environment or context. In an operative aspect, the nature of placement of configuration commands refers to how the commands are positioned, arranged or organized within the configuration file to perform a function.
[0127] Using the selection module 212, the user may be configured to select or create a design filter (a set of rules) to filter certain contexts of command lines from a configuration file of the network entity 110. On receiving the user input, the selection module 212 may be configured to acquire the configuration file corresponding to the network entity 110 based on the network entity ID. The syntax parser module 214 may be configured to parse the configuration file by employing a set of predefined parameters. The syntax parser module 214 may be configured to filter the configuration file based on the rule list selected by the user. The syntax parser module 214 may be configured to extract the command lines from the configuration file. In another aspect, the set of rules is automatically selected from the rule listbased on type of configuration audit. For example, for a security audit, security audit rules are automatically selected from the rule list / the rule library.
[0128] At step 404, the syntax parser module 214 may be configured to determine whether the configuration audit command exists in silo mode or not. In an aspect, the silo mode refers to a mode in which the command is independent / not hived anything in the command. In another aspect, the silo mode may refer to a strategy used in content creation or website design in which information, or pages are organized in a strict hierarchical structure. This means that all relevant content related to a particular topic or group of topics is placed on the same page or group of pages, and there is limited cross-linking between pages in different hierarchical structures.
[0129] If the configuration audit command exists in the silo mode, then the syntax parser module 214 may be configured to apply "verbose" as a primary declarative syntax for the particular configuration and command's audit (step 406). In an aspect, in silo mode, the verbose parameter is used to detect whether a particular command is present exactly in the configuration file. If the particular command is not present exactly in the configuration file, then the router does not comply with one or more audit rules. Hence, the verbose is applied as the primary declarative syntax for the particular configuration. Using the front-end user interface (selection module), the user may be configured to access the rule library 216 and paste the command ipvX access-list XXXX-XXXX-IPvX with the associated declarative syntax being stated as verbose. The report generation module 218 may be configured to generate the report about the compliance of the router based on the execution of the configuration audit command and store the generated report in the rule library 216 (step 414).
[0130] If the configuration audit command does not exist in the silo mode, then the syntax parser module 214 may be configured to check whether the configuration audit command is a solo-hived entity. In an aspect, the solo hived entity refers to an entity having only one command under a particular command. For example, the solohived entity refers to a self-contained, independent metadata entity linked to and stored as a separate object in the database (step 408). If the configuration audit command is the solo hived entity (subsidiary entity), the syntax parser module 214 may be configured to apply "immediately succeeds" associated with a parent configuration audit command as the primary declarative syntax (step 410). Using the front-end user interface, the user may be configured to gain access to the rule library 216 and paste the command match traffic-class 4 any with the associated declarative syntax being stated as immediately succeeds class-map match-any QoS-XXXX-TC. The report generation module 218 may be configured to generate the report comprising information about the compliance of the network entity 110 based on the execution of the configuration audit command and store the generated report in the rule library 216 (step 414).
[0131] If the configuration audit command is not a solo hived entity (subsidiary entity), the syntax parser module 214 may be configured to Apply "Succeeds" associated with the parent configuration audit command followed by "precedes" associated with the command as specified by a golden text as the primary declarative syntax (step 412). In an aspect, the non-solo hived entity refers to an entity having multiple commands under a particular command. In an aspect, the golden text is a syntax used at the end while user enters the command to check compliance of the network entity. Using the front-end user interface, the user may be configured to gain access to the audit rule library 216 and paste the command *.* 10 permit ipvX xxxx:xxx:xxx:xx00:: / XX any with the associated declarative syntax being stated as succeeds ipvX access-list XXXX-XXXX-IPvX and precedes ipvX access-list *.* The report generation module 218 may be configured to generate the report about the compliance of the network entity 110 based on the execution of the configuration audit command and store the generated report in the rule library 216 (step 414).
[0132] Overall, the present disclosure provides for performing automatic configuration audits for network entities using configuration audit rules. The method may use five linguistic parameters of the declarative syntax to effectively parse the configuration files of the network entities. The five linguistic parameters are verbose, succeeds, immediately succeeds, precedes, and don’t care. Using the front-end user interface, the user may be configured to run the configuration audit command with the associated declarative syntax (i.e., verbose or succeeds or immediately succeeds or precedes or don’t care) and show an output as compliant or non-compliant. (after checking if the configuration files of the network entities are as per audit rules).
[0133] FIG. 5 illustrates an exemplary flowchart for method 500 for performing the configuration audit for the network entity 110, in accordance with an embodiment of the present disclosure.
[0134] As illustrated in FIG. 5 with reference to FIGs. 2 and 3, the method 500 performs the configuration audit for the network entity 110 using the selection module 212, the syntax parser module 214, the report generation module 218, and the rule library 216.
[0135] At step 502, the method 500 includes retrieving, by the selection module 212, a configuration file associated with the network entity 110 from a central database 112 based on a user input received via a user interface. The selection module 212 may retrieve a configuration file associated with the network entity 110 from a central database 112 based on user input received via a user interface. In an aspect, the user input may include a trigger for initiating a configuration audit for the network entity 110. The user input may include a storage path address for retrieving the configuration file of the network entity 110. The user input may include selection of the configuration file of the network entity 110 via a user interface of the user equipment 104. In an aspect, the user input comprises at least one configuration auditcommand. In another exemplary aspect, the user input may include a set of identification parameters of the network entity 110.
[0136] In an aspect, the configuration file may be retrieved from the central database 112 using the set of identification parameters. The set of identification parameters may include a MAC address, an IP address, a hostname, a domain name, a device type, and a device ID. The central database 112 may store the configuration file mapped with the identification parameters.
[0137] In an aspect, the configuration audit for the network entity 110 is performed based on one or more configuration audit rules from amongst a plurality of configuration audit rules. The one or more configuration audit rules are based on at least one linguistic parameter. The configuration audit rules include defining specific regulations or guidelines to ensure the network entity settings align with security policies, organizational policies, compliance policies, and operational requirements. In an aspect, the at least one linguistic parameter comprises verbose, succeeds, immediately succeeds, precedes, and does not care.
[0138] At step 504, the method 500 includes parsing, by the syntax parser module 214, the retrieved configuration file to determine an existence of at least one configuration audit command in a predefined mode. The syntax parser module 214 may parse the configuration file to determine the existence of the at least one configuration audit command in one of predefined modes. The predefined mode comprises at least one of a silo mode, a solo hived entity and a non-solo hived entity.
[0139] In one exemplary aspect, the process of parsing the configuration file involves interpreting and processing the configuration data into user-readable form.
[0140] At step 506, the method 500 includes based on the parsing, executing 506, by the syntax parser module 214, the at least one configuration audit command with at least one linguistic parameter to perform a compliance test on the parsedconfiguration file. Based on the parsing, if the at least one configuration audit command exists in the predefined mode (i.e., silo mode), the syntax parser module 214 executes the at least one configuration audit command with the at least one linguistic parameter (i.e., verbose parameter). Further, if the at least one configuration audit command exists in the predefined mode (i.e., solo entity), the syntax parser module 214 executes the at least one configuration audit command with the at least one linguistic parameter (i.e., immediately succeeds parameter). Furthermore, if the at least one configuration audit command exists in the predefined mode (i.e., non-solo entity), the syntax parser module 214 executes the at least one configuration audit command with the linguistic parameters (i.e., succeeds parameter, precedes parameter and don’t care parameter). In the compliance test, after executing the configuration audit command with the at least one linguistic parameter, the syntax parser module 214 detects whether the at least one executed configuration audit command is present in the retrieved configuration file according to the at least one linguistic parameter. If the at least one executed configuration audit command is present in the retrieved configuration file according to the at least one linguistic parameter, then the at least one configuration audit command exists in the configuration file according to the configuration audit rules. Further, upon detecting the at least one executed configuration audit command is not present in the retrieved configuration file according to the at least one linguistic parameter, then the at least one configuration audit command does not exist in the configuration file according to the configuration audit rules.
[0141] In one exemplary embodiment, the syntax parser module 214 may perform a compliance test on the configuration file to verify adherence to the one or more configuration audit rules. The performing of the compliance test comprises executing a configuration audit command on the configuration file via the user interface. In an exemplary aspect, the compliance test may involve checking for anydeviation in the one or more configuration audit rules. The compliance test may be performed by executing the configuration audit command on the configuration file.
[0142] At step 508, the method 500 includes generating, by the report generation module 216, a configuration audit report for the network entity 110 based on the compliance test. The report generation module 216 may generate the configuration audit report for the network entity 110 based on the compliance test performed on the configuration file. The configuration audit report indicates whether the at least one configuration audit command exists in the configuration file according to the one or more configuration audit rules.
[0143] For example, when the configuration file adheres to the one or more configuration audit rules, the compliance report may indicate that the configuration file complies with the one or more configuration audit rules. When the configuration file does not adhere to the one or more configuration audit rules, the compliance report may indicate that the configuration file does not comply with the one or more configuration audit rules.
[0144] FIG. 6 illustrates an exemplary computer system 600 in which or with which the embodiments of the present disclosure may be implemented.
[0145] As shown in FIG. 6, the computer system 600 may include an external storage device 610, a bus 620, a main memory 630, a read-only memory 640, a mass storage device 650, a communication port(s) 660, and a processor 670. A person skilled in the art will appreciate that the computer system 600 may include more than one processor and communication ports. The processor 670 may include various modules associated with embodiments of the present disclosure. The communication port(s) 660 may be any of an RS-232 port for use with a modem-based dialup connection, a 10 / 100 Ethernet port, a Gigabit or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or other existing or future ports. The communicationports(s) 660 may be chosen depending on a network, such as a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system 600 connects.
[0146] In an embodiment, the main memory 630 may be Random Access Memory (RAM), or any other dynamic storage device commonly known in the art. The read-only memory 640 may be any static storage device(s) e.g., but not limited to, a Programmable Read Only Memory (PROM) chip for storing static information e.g., start-up or basic input / output system (BIOS) instructions for the processor 670. The mass storage device 650 may be any current or future mass storage solution, which can be used to store information and / or instructions. Exemplary mass storage solutions include, but are not limited to, Parallel Advanced Technology Attachment (PATA) or Serial Advanced Technology Attachment (SATA) hard disk drives or solid-state drives (internal or external, e.g., having Universal Serial Bus (USB) and / or Firewire interfaces).
[0147] In an embodiment, the bus 620 may communicatively couple the processor(s) 670 with the other memory, storage, and communication blocks. The bus 620 may be, e.g. a Peripheral Component Interconnect PCI) / PCI Extended (PCLX) bus, Small Computer System Interface (SCSI), Universal Serial Bus (USB), or the like, for connecting expansion cards, drives, and other subsystems as well as other buses, such a front side bus (FSB), which connects the processor 670 to the computer system 600.
[0148] In another embodiment, operator and administrative interfaces, e.g., a display, keyboard, and cursor control device, may also be coupled to the bus 620 to support direct operator interaction with the computer system 600. Other operator and administrative interfaces can be provided through network connections connected through the communication port(s) 660. The components described above are meantonly to exemplify various possibilities. In no way should the aforementioned exemplary computer system 600 limit the scope of the present disclosure.
[0149] The exemplary computer system (600) is configured to execute a computer program product comprising a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform a method for performing a configuration audit for a network entity in a communication network. The method includes retrieving, by a selection module, a configuration file associated with the network entity from a central database based on a user input received via a user interface. The method further includes parsing, by a syntax parser module, the retrieved configuration file to determine an existence of at least one configuration audit command in a predefined mode. The method further includes based on the parsing, executing, by the syntax parser module, the at least one configuration audit command with at least one linguistic parameter to perform a compliance test on the parsed configuration file. The method further includes generating, by a report generation module, a configuration audit report for the network entity based on the compliance test.
[0150] The present disclosure provides technical advancement related to a system and a method for performing automatic configuration audit for network entities in a communication network. This advancement addresses the limitations of existing solutions by automating configuration audit for the network entities by saving the time of a network manager. The disclosure involves configuration automation for the network entities by self-formulating and retiring configuration audit rules via a user interface, significantly improving network performance. By implementing an automatic configuration audit for the network entity, the disclosed invention enhances the network security, network compliance, and network performance of the network entity, resulting in automatic network management without the need for manual intervention.
[0151] While the foregoing describes various embodiments of the invention, other and further embodiments of the invention may be devised without departing from the basic scope thereof. The scope of the invention is determined by the claims that follow. The invention is not limited to the described embodiments, versions or examples, which are included to enable a person having ordinary skill in the art to make and use the invention when combined with information and knowledge available to the person having ordinary skill in the art.ADVANTAGES OF THE PRESENT DISCLOSURE
[0152] The present disclosure provides a system and a method for performing an automatic configuration audit for a network entity in a communication network
[0153] The present disclosure provides a system and a method for self-forming and retiring configuration audit rules through a user-interface-exposed library.
[0154] The present disclosure provides a system and a method that uses linguistic parameters to parse a textual configuration file of a network entity effectively.
[0155] The present disclosure provides a system and a method that generates configuration audit reports.
[0156] The present disclosure provides a system and a method that automatically performs and manages the compliance policies of a network entity.
Claims
CLAIMS1. A method (500) for performing a configuration audit for a network entity(110) in a communication network (106), the method (500) comprising: retrieving (502), by a selection module (212), a configuration file associated with the network entity (110) from a central database (112) based on a user input received via a user interface; parsing (504), by a syntax parser module (214), the retrieved configuration file to determine an existence of at least one configuration audit command in a predefined mode; executing (506), based on the parsing, by the syntax parser module (214), the at least one configuration audit command with at least one linguistic parameter to perform a compliance test on the parsed configuration file; and generating (508), by a report generation module (216), a configuration audit report for the network entity (110) based on the compliance test.
2. The method (500) as claimed in claim 1, wherein the user input comprises a trigger for initiating the configuration audit for the network entity (110) and the at least one configuration audit command.
3. The method (500) as claimed in claim 1, wherein the predefined mode comprises at least one of a silo mode, a solo hived entity and a non-solo hived entity.
4. The method (500) as claimed in claim 1, wherein the at least one linguistic parameter comprises verbose, succeeds, immediately succeeds, precedes, or does not care.
5. The method (500) as claimed in claim 1, wherein the at least one linguistic parameter facilitates declarative syntax for parsing the configuration file.
6. The method (500) as claimed in claim 1, wherein the compliance test is performed to determine whether the at least one configuration audit command exists in the configuration file according to one or more configuration audit rules of a plurality of configuration audit rules.
7. The method (500) as claimed in claim 6, wherein the plurality of configuration audit rules is stored in a rule library (216) accessible via the user interface, and wherein the one or more configuration audit rules are based on the at least one linguistic parameter.
8. The method (500) as claimed in claim 1, wherein the configuration audit report indicates whether the at least one configuration audit command exists in the configuration file according to the one or more configuration audit rules.
9. A system (108) for performing a configuration audit for a network entity(110) in a communication network (106), the system (108) comprises: a selection module (212) configured to: retrieve a configuration file associated with the network entity (110) from a central database (112) based on a user input received via a user interface; a syntax parser module (214) configured to: parse the retrieved configuration file to determine an existence of at least one configuration audit command in a predefined mode; andbased on the parsing, execute the at least one configuration audit command with at least one linguistic parameter to perform a compliance test on the parsed configuration file; and a report generation module (216) configured to: generate a configuration audit report for the network entity (110) based on the compliance test.
10. The system (108) as claimed in claim 9, wherein the user input comprises a trigger for initiating the configuration audit for the network entity (110) and the at least one configuration audit command.
11. The system (108) as claimed in claim 9, wherein the predefined mode comprises at least one of a silo mode, a solo hived entity and a non-solo hived entity.
12. The system (108) as claimed in claim 9, wherein the at least one linguistic parameter comprises verbose, succeeds, immediately succeeds, precedes, or does not care.
13. The system (108) as claimed in claim 9, wherein the at least one linguistic parameter facilitates declarative syntax for parsing the configuration file.
14. The system (108) as claimed in claim 9, wherein the compliance test is performed to determine whether the at least one configuration audit command exists in the configuration file according to one or more configuration audit rules of a plurality of configuration audit rules.
15. The system (108) as claimed in claim 14, wherein the plurality of configuration audit rules is stored in a rule library (216) accessible via theuser interface, and wherein the one or more configuration audit rules are based on the at least one linguistic parameter.
16. The system (108) as claimed in claim 9, wherein the configuration audit report indicates whether the at least one configuration audit command exists in the configuration file according to the one or more configuration audit rules.
17. A user equipment (104) for performing a configuration audit for a network entity in a communication network, the user equipment (104) comprising: a processor (202); and a computer readable storage medium storing a set of instruction for execution by the processor (202), the set of instructions comprises: inputting an input by a user via a user interface, wherein the input comprises a trigger for initiating a configuration audit for a network entity (110) and at least one configuration audit command; and receiving a configuration audit report for the network entity (110) on the user interface.
18. The user equipment (104) as claimed in claim 17, wherein the configuration audit report indicates whether the at least one configuration audit command exists in a configuration file according to one or more configuration audit rules.
19. A computer program product comprising a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform a method (500) forperforming a configuration audit for a network entity (110) in a communication network (106), the method (500) comprising: retrieving (502), by a selection module (212), a configuration file associated with the network entity (110) from a central database (112) based on a user input received via a user interface; parsing (504), by a syntax parser module (214), the retrieved configuration file to determine an existence of at least one configuration audit command in a predefined mode; based on the parsing, executing (506), by the syntax parser module (214), the at least one configuration audit command with at least one linguistic parameter to perform a compliance test on the parsed configuration file; and generating (508), by a report generation module (216), a configuration audit report for the network entity (110) based on the compliance test.
Citation Information
Patent Citations
System and implementing method for managing security of information based on inspection of database log file
TW201939306A
Audit Management System
US20120102543A1
System and method for automated policy audit and remediation management
US20130347107A1
Managing command compliance in internetworking devices
US20150007260A1