Remote Network Device Configuration Validation via Packet Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for testing and verifying the configuration of network devices in large, complex enterprise networks are cumbersome and expensive, and they do not effectively confirm the proper configuration of individual devices, leaving networks vulnerable to security threats.

Innovation Solution

The use of extended device management protocols like SNMP or NETCONF allows for the remote injection of traffic patterns into network devices, enabling them to process and validate configuration policies without deploying specialized testing components, allowing for centralized management and verification of network devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional distributed network analysis components are deployed to test network device configuration, then network traffic patterns can be generated and captured, but the system complexity and deployment cost increase significantly

Engineering Contradiction:
Improveconfiguration validation accuracyVSAvoidtesting system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the configuration management functionality and the packet injection/testing functionality into a single device management protocol interface. The element manager both configures the network device and injects test packets through the same protocol channel, eliminating the need for separate distributed analysis components and reducing system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The device management protocol is extended to serve multiple functions: it maintains its original configuration management capabilities while simultaneously providing packet injection and traffic pattern generation capabilities. This multi-functional approach replaces the need for specialized testing components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If distributed packet sniffers are deployed throughout the network to capture traffic, then traffic analysis capability is improved, but the deployment and provisioning becomes cumbersome and expensive

Engineering Contradiction:
Improvetraffic analysis capabilityVSAvoiddeployment ease
Core Design Contradiction:
Loss of informationVSEase of manufacture

Solution Approach 1:

The patent extracts the packet injection capability from the network traffic flow and implements it directly within the device management protocol channel. Test packets are injected through the management interface rather than being captured from actual network traffic, eliminating the need for distributed packet sniffers while maintaining full traffic analysis capability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If actual network traffic is introduced to test device configuration, then real-world testing accuracy is improved, but network security vulnerabilities are exposed

Engineering Contradiction:
Improveconfiguration testing accuracyVSAvoidnetwork security exposure
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The device management protocol serves as an intermediary channel that allows test packets to be injected into the network device without traversing the actual network. The packets are delivered through the management interface, enabling realistic configuration testing while isolating the network from potential security threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If specialized testing components are deployed at strategic network locations, then traffic pattern injection capability is improved, but the provisioning and deployment cost increases

Engineering Contradiction:
Improvetraffic injection flexibilityVSAvoidtesting components quantity
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The element manager is designed to be universally applicable across all network devices, providing traffic pattern injection capability through the standard device management protocol. This eliminates the need for specialized testing components at multiple network locations, as a single element manager can inject traffic patterns into any managed device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8248958B1Remote validation of network device configuration using a device management protocol for remote packet injection
Publication Date: 2012.08.21 JUNIPER NETWORKS INC
  • US8248958B1 patent drawing
  • US8248958B1 patent drawing
  • US8248958B1 patent drawing

AI summary

In general, this disclosure describes techniques for testing and verifying the functionality of networks and network devices without requiring the deployment of specialized testing components. For example, as described herein, a device management protocol (e.g., SNMP or NETCONF) typically used for remote configuration of devices has been extended to allow traffic patterns to be seamlessly injected into the existing network devices that form the enterprise network. For instance, a network management device sends configuration data to a managed network device in accordance with a device management protocol and calls, using a test packet parameter, a device configuration function exposed by a managed device. When the device configuration function is called, the managed device processes the test packet to produce a result in accordance with the configuration data as if the test packet had been received from the network, and the managed device returns a test packet processing result.