Network Compliance Dashboard with Drill-Down Violation Views

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large information networks, identifying and verifying numerous rules across interconnected elements becomes cumbersome, and managing multiple policies driven by external factors such as corporate directives and compliance laws is complex, making it difficult to maintain network predictability and compliance.

Innovation Solution

A network compliance management system that uses a passive probe mechanism to populate a configuration management database with real-time data, a policy manager to identify and evaluate rules, and a display engine to provide a dashboard view for users to monitor compliance, allowing drill-down queries for specific rule violations and severity analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple policies with numerous rules are implemented to maintain network predictability and compliance, then network management reliability is improved, but the complexity of identifying and verifying each rule across the network increases substantially

Engineering Contradiction:
Improvenetwork management reliabilityVSAvoidrule verification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a policy management system that acts as an intermediary between network elements and administrators. This system automatically collects configuration data from network elements, evaluates it against stored policies and rules, and presents compliance information to administrators. The intermediary handles the complex task of rule verification across numerous network elements, relieving administrators from manually checking each rule while maintaining reliable policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a comprehensive set of rules is enforced across all network elements, then policy compliance is improved, but the time and resources required to identify and verify each rule increase

Engineering Contradiction:
Improvepolicy complianceVSAvoidrule verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring policies and rules in the policy management system before they need to be evaluated. Configuration data from network elements is collected and stored in advance. When compliance evaluation is needed, the pre-prepared data and pre-configured policies can be quickly matched and evaluated, significantly reducing the time required for rule verification compared to on-demand collection and analysis.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If detailed monitoring of each rule violation is provided, then measurement precision of compliance status is improved, but the complexity of the dashboard interface and data processing increases

Engineering Contradiction:
Improvecompliance measurement precisionVSAvoiddashboard complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The dashboard interface is segmented into multiple hierarchical levels. The top level provides an overview of overall policy compliance status. Users can drill down to see specific policy violations, then further drill down to individual rule violations, and finally to specific network elements involved. This segmentation allows precise measurement and monitoring of compliance at each level while keeping the interface manageable by displaying only relevant details at each hierarchical stage.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7934248B1Network policy enforcement dashboard views
Publication Date: 2011.04.26 EMC IP HLDG CO LLC
  • US7934248B1 patent drawing
  • US7934248B1 patent drawing
  • US7934248B1 patent drawing

AI summary

A network compliance application performs a method of coalescing violation data based on rule and policy violations by retrieving network event data indicative of compliance with a set of policies, in which each of the policies has a set of rules. The application computes, for each of the policies, violations, each violation indicative of a deviation from a particular rule, and displays a summary view indicative of a plurality of policies in the set of policies, the summary view indicative of violations attributable to each of the policies. From the displayed summary view, the application receives a detail selection corresponding to a subset of the displayed violations in the summary view; displays, for the received detail selection, a violation view having a sequence of ranked violation entries corresponding to the detail selection.