Enterprise Network Policy Scope Discovery and Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing network policies in complex enterprise networks is challenging due to heterogeneity in traffic patterns, making it costly and labor-intensive to find appropriate policy scopes and implement policies effectively.

Innovation Solution

The method involves identifying communities of devices within the network, generating a hierarchical representation of policy scopes, and managing policies by selecting and compressing policies to create a minimal policy set, which simplifies policy management and reduces redundancy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual policy scope discovery is performed in complex enterprise networks, then policy implementation accuracy can be maintained, but the process becomes costly and labor intensive

Engineering Contradiction:
Improvepolicy scope identification accuracyVSAvoidpolicy discovery time and cost
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs self-service by automatically analyzing network traffic data to discover policy scopes without human intervention. The analytics engine autonomously identifies device communities, determines appropriate policy scopes, and generates policy recommendations, eliminating the need for manual policy scope discovery while maintaining high accuracy through automated traffic pattern analysis

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical analysis with automated computational analysis. Instead of human experts manually examining network traffic and identifying policy scopes, an analytics engine uses computational algorithms to analyze traffic data, detect device communities, and automatically determine policy scopes, dramatically reducing time and cost while maintaining precision

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive policies are applied to cover all network scenarios, then network control and security are improved, but policy complexity and redundancy increase

Engineering Contradiction:
Improvenetwork control and securityVSAvoidpolicy set complexity and redundancy
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the essential and non-redundant policies needed for effective network control. By analyzing device communities and their traffic patterns, the analytics engine identifies and extracts the minimum necessary policy set that covers all critical security and control requirements, eliminating redundant policies while maintaining comprehensive coverage

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the network into distinct device communities based on traffic patterns, then applies tailored policies to each community. This segmentation allows for targeted policy application rather than blanket policies across the entire network, reducing overall policy complexity while ensuring appropriate control for each segment's specific requirements

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11627166B2Scope discovery and policy generation in an enterprise network
Publication Date: 2023.04.11 CISCO TECHNOLOGY INC
  • US11627166B2 patent drawing
  • US11627166B2 patent drawing
  • US11627166B2 patent drawing

AI summary

The present disclosure relates to methods, systems, and non-transitory computer readable media for discovering policy scopes within an enterprise network and managing network policies for discovered policy scopes. In one aspect, a method includes identifying one or more communities of devices in an enterprise network; defining, from the one or more communities of devices, policy scopes in the enterprise network; generating a hierarchical representation of the policy scopes; identifying, based on the hierarchical representation of the policy scopes, one or more policies governing traffic flow between devices associated with each of the policy scopes; and managing application of the one or more policies at the devices.