Container Policy Validation Using Replicated Real-Time Network Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The current process of validating containers before moving them to a production environment is inefficient and resource-intensive, as it involves simulating synthetic traffic in a non-production environment to test policies, which does not accurately reflect real-time network traffic and can impact production services.

Innovation Solution

The use of Contiv HostAgents to replicate real-time network traffic for validating the performance of containers, virtual machines, or bare-metal systems in a non-production mode without affecting real-time network traffic, allowing for accurate policy configuration and performance validation before moving them to production.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If synthetic traffic is used to validate containers in non-production environment, then validation process can be performed, but the validation does not accurately reflect real-time network traffic and is resource-intensive

Engineering Contradiction:
Improveaccuracy of validationVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent creates a copy of the production network environment including real network traffic, container images, and network policies. This copy is used in a non-production sandbox environment for validation, allowing accurate testing without consuming production resources. The sandbox environment replicates the production topology and traffic patterns to enable realistic validation.

Inventive Principle:
Principle #26Copying

2Reliability

If containers are validated in non-production environment with synthetic traffic, then validation can be performed, but it impacts production services and does not reflect real traffic patterns

Engineering Contradiction:
Improvevalidation accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a sandbox environment as an intermediary between production and validation needs. This sandbox acts as an isolated copy that receives real network traffic copies, allowing validation without directly impacting production systems. The sandbox mediates the validation process by providing a safe environment that mirrors production reality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the network environment into production and sandbox copies. The production environment continues to handle real services while the sandbox environment handles validation. This segmentation allows both environments to operate independently with the same network policies and traffic patterns, eliminating interference between validation and production operations.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If real-time network traffic is replicated for validation, then accurate performance validation is achieved, but additional system resources are required

Engineering Contradiction:
Improveperformance validation accuracyVSAvoidsystem resources
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The sandbox environment serves multiple functions: it validates new containers, tests network policies, verifies performance requirements, and confirms compliance with service level agreements. By making the sandbox multi-functional, the system reduces the need for separate testing environments and minimizes overall resource requirements while maintaining validation accuracy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3695565B1System and method for replication container performance and policy validation using real time network traffic
Publication Date: 2021.09.22 CISCO TECHNOLOGY INC
  • EP3695565B1 patent drawingFigure 1A
  • EP3695565B1 patent drawingFigure 1B
  • EP3695565B1 patent drawingFigure 1C

AI summary

Systems, methods, and computer-readable media are disclosed for using real time network traffic for validating policy configuration(s) of containers, virtual machines, bare- metals, etc. In one aspect of the present disclosure a method includes receiving, at a controller, an incoming data packet destined for one or more containers; replicating, at the controller, the incoming data packet for validating at least one non-production container to yield a replicated data packet; sending the replicated data packet to the at least one non- production container; and dropping any data packet received from the at least one non- production container at a corresponding incoming port of the controller.