Communication Rules Management for Software Defined Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Administrators face difficulties in configuring software defined networks to manage internal and external communications within computing environments, particularly in determining which communications should be permitted based on applications and services deployed in virtual nodes.
Innovation Solution
A method for managing communication rules across multiple computing networks involves maintaining and providing subsets of communication rules based on application configurations, where communication settings service identifies and suggests rules by comparing application similarities across networks, allowing administrators to select and implement rules within the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If administrators manually configure communication rules for each application in software defined networks, then network security and control are improved, but configuration time and administrative burden increase significantly
Solution Approach 1:
The system performs preliminary actions by automatically generating communication rules based on application metadata and network policies before administrators need to configure them. The management system analyzes application descriptions, identifies communication requirements, and pre-configures rules that administrators can then review and deploy, eliminating the need for manual rule creation from scratch.
Solution Approach 2:
The system enables self-service by allowing the management system to automatically generate and configure communication rules without requiring administrator intervention for each individual rule. The system uses application metadata and policy definitions to autonomously create appropriate communication rules, which administrators can then review and deploy with a single action.
2Reliability
If comprehensive communication rules are configured to cover all possible communication scenarios, then network security is improved, but rule complexity and difficulty of management increase
Solution Approach 1:
The system segments communication rules into modular components based on application types, communication patterns, and policy categories. Instead of managing one large complex rule set, administrators can work with segmented rules organized by application, network layer, or security policy, making the overall system more manageable while maintaining comprehensive coverage.
Solution Approach 2:
The system creates universal rule templates that can be applied across multiple applications and scenarios. By defining communication rules at an abstract level that captures common patterns, the system can generate specific instance rules automatically, reducing the number of unique rules administrators need to manage while still covering diverse communication scenarios.
3Manufacturing precision
If communication rules are customized for each specific network environment, then rule accuracy and applicability are improved, but the effort to determine and configure rules increases
Solution Approach 1:
The management system performs self-service by automatically analyzing application metadata, network topology, and policy definitions to generate customized communication rules specific to each network environment. This eliminates the need for administrators to manually determine appropriate rules while ensuring high accuracy through automated analysis of network-specific characteristics.
Solution Approach 2:
The system uses parameter changes by dynamically adjusting rule parameters based on network environment characteristics, application types, and security policies. Instead of using fixed rule templates, the system modifies rule parameters automatically to match the specific network context, ensuring accuracy while requiring minimal administrator input.
Data Source
AI summary
Described herein are systems, methods, and software to enhance the implementation of communication rules in a computing network. In one example, a method of operating a communication settings system maintains communication rules for a plurality of networks, wherein the communication rules define forwarding actions for ingress and egress packets to and from applications in the plurality of computing networks. The service further identifies a configuration request from a computing network with applications executing in the computing network, identifies a subset of the communication rules based on the plurality of applications, and provides the subset of the communication rules to the computing network.


