Network Compliance Analysis Using Machine Learning Role Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large-scale network deployments face challenges in forensic disentanglement and automated analysis due to the lack of a consistent design framework, leading to labor-intensive manual processes and limited ability to infer modularity and business outcomes from network device configurations.

Innovation Solution

A method using machine learning models, such as Random Forest, to classify network device roles and analyze policies, enabling the creation of a Relational State of Policy Attributes (RSPA) framework that breaks down networks into design objects for holistic analysis and validation, with the aid of a graph database to establish relationships and compliance with network design solutions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual categorization or broad feature usage is used to determine network device roles, then device functionality can be identified, but the process becomes labor-intensive and design context is lost

Engineering Contradiction:
Improvenetwork device role determinationVSAvoidmanual analysis time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical analysis with automated machine learning models that classify network device roles by analyzing configuration data, relationships, and policies. The system automatically determines device functionality without human intervention, eliminating the labor-intensive manual categorization process while preserving design context through structured data analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a virtual model or copy of the network infrastructure that mirrors the actual network devices, configurations, and relationships. This digital twin allows automated analysis and role determination without affecting the real network, enabling rapid evaluation and comparison of different analysis approaches.

Inventive Principle:
Principle #26Copying

2Measurement precision

If line-by-line configuration analysis is performed across thousands of network devices, then detailed inspection is possible, but the process becomes slow and labor-intensive

Engineering Contradiction:
Improveconfiguration analysis detailVSAvoidanalysis speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts only the most relevant configuration elements, relationships, and policies from the complete device configurations using natural language processing and pattern recognition. Instead of analyzing every line of configuration data, the system identifies and extracts key features that determine device roles and compliance, dramatically reducing analysis time while maintaining precision.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the network infrastructure into discrete analyzable units including network devices, configurations, relationships, and policies. This segmentation allows parallel processing of multiple devices and configuration elements simultaneously, improving analysis throughput while maintaining detailed inspection capabilities through systematic evaluation of each segment.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If network devices from multiple vendors and design standards are integrated, then network functionality is enhanced, but it becomes challenging to determine what solutions are enabled

Engineering Contradiction:
Improvemulti-vendor solution supportVSAvoidsolution identification clarity
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent implements a universal classification framework that can handle network devices, configurations, and policies from multiple vendors and design standards through a common language and structure. The machine learning models are trained to recognize patterns across different vendor-specific configurations, enabling unified role determination and solution identification regardless of the underlying vendor diversity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary layer of standardized data models and relationship definitions that translate between different vendor-specific configurations and a unified analysis framework. This intermediary layer preserves the original vendor-specific details while enabling consistent role determination and solution identification across multi-vendor environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11456917B2Analyzing deployed networks with respect to network solutions
Publication Date: 2022.09.27 CISCO TECHNOLOGY INC
  • US11456917B2 patent drawing
  • US11456917B2 patent drawing
  • US11456917B2 patent drawing

AI summary

Techniques and architecture for determining compliance of a network with respect to a network design solution. The techniques may include determining a role for each network device of a network that comprises multiple network devices and determining one or more policies related to each network device with respect to other network devices of the network. The techniques may further include based at least in part on the roles for each network device and the one or more policies, determining a level of compliance of a configuration of the network with respect to a network design solution. Based at least in part on the level of compliance, a remedial action may be performed. In configurations, a machine learning model may be used.