Network Policy Testing Device for Configuration Error Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network policies often require updating due to changes in network configurations, leading to potential errors when implemented, such as firewalls incorrectly blocking or allowing access to resources, which can result in security breaches or service disruptions.

Innovation Solution

A method and device for testing network policies by receiving and applying policies to simulated network traffic, generating a test log that indicates how the traffic would be handled, allowing administrators to evaluate and modify policies before implementation, ensuring correct policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network policies are updated to adapt to changing network configurations, then network security and access control improve, but errors in policy configuration may occur leading to incorrect blocking or allowing of traffic

Engineering Contradiction:
Improvenetwork policy adaptabilityVSAvoidpolicy enforcement reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary testing of network policies in a test mode before deploying them to operational mode. The testing device simulates policy enforcement on test traffic to identify configuration errors beforehand, preventing incorrect blocking or allowing of traffic while maintaining adaptability to network changes

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If network policies are strictly enforced to ensure security, then unauthorized access is blocked, but legitimate traffic may be incorrectly blocked causing service disruptions

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidnetwork service continuity
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system performs preliminary testing of network policies in a test mode before deploying them to operational mode. The testing device simulates policy enforcement on test traffic to identify configuration errors beforehand, preventing incorrect blocking of legitimate traffic while maintaining security enforcement

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system generates test logs that provide feedback on how test traffic would be handled by the network policy. This feedback allows administrators to review and verify policy behavior before deployment, ensuring both security enforcement and service continuity

Inventive Principle:
Principle #23Feedback

3Reliability

If network policies are tested extensively before deployment, then configuration errors are detected, but testing time and resources increase

Engineering Contradiction:
Improvepolicy configuration accuracyVSAvoidpolicy testing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system creates a copy of the network policy for testing purposes in a test mode environment. This allows extensive testing of policy configuration accuracy without affecting production systems, reducing the risk to acceptable levels while minimizing impact on operational time

Inventive Principle:
Principle #26Copying

Data Source

PatentUS7987264B1Testing policies in a network
Publication Date: 2011.07.26 JUNIPER NETWORKS INC
  • US7987264B1 patent drawing
  • US7987264B1 patent drawing
  • US7987264B1 patent drawing

AI summary

A device may include first logic configured to receive a data unit and to receive a network policy. The device may include second logic configured to identify how the data unit will be handled by the network policy and to generate a result that includes information about how the data unit will be handled by the network policy.