Network Policy Violation Detection Using Data Samples

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Server virtualization in large and dynamic data centers leads to configuration and troubleshooting complexity, with trivial errors potentially causing significant network performance declines and taking weeks to diagnose.

Innovation Solution

A system and method that collect data samples from network nodes, determine policy violations using sensors and a network service sentinel, and generate alerts, reducing troubleshooting time from weeks to minutes by automatically detecting policy breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If manual configuration and troubleshooting methods are used in virtualized data centers, then operational flexibility is maintained, but troubleshooting time increases to weeks and complexity increases

Engineering Contradiction:
Improvetroubleshooting timeVSAvoidconfiguration and troubleshooting complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system implements self-service through automated policy violation detection and alerting. Sensors continuously monitor network traffic and automatically identify policy violations without human intervention. The system generates alerts and notifications autonomously, enabling the network management system to self-diagnose and self-report issues, thereby reducing troubleshooting time from weeks to minutes while managing complexity through automation.

Inventive Principle:
Principle #25Self-service

2Productivity

If automated policy violation detection is implemented, then troubleshooting time is reduced to minutes, but system complexity increases

Engineering Contradiction:
Improvetroubleshooting efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the network monitoring function into independent sensors deployed at various network nodes. Each sensor independently monitors its local segment for policy violations. This segmentation distributes the computational burden and simplifies the overall system architecture, allowing automated detection across the entire network while maintaining manageable complexity at each segment level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces sensors as intermediary components between network traffic and the central management system. These sensors act as mediators that automatically detect policy violations in network traffic and translate them into structured alerts. This intermediary layer handles the complexity of policy evaluation and violation detection, freeing the central management system from direct involvement in detailed analysis while maintaining high troubleshooting efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If continuous network monitoring is implemented to detect policy violations, then network reliability is improved, but energy consumption increases

Engineering Contradiction:
Improvenetwork policy complianceVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system implements periodic monitoring through sensors that continuously sample network traffic at intervals rather than analyzing every single packet in real-time. This periodic sampling approach maintains network policy compliance detection capability while significantly reducing energy consumption compared to continuous deep packet inspection. The sensors periodically assess traffic patterns and detect policy violations without requiring constant full-bandwidth analysis.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9246774B2Sample based determination of network policy violations
Publication Date: 2016.01.26 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9246774B2 patent drawing
  • US9246774B2 patent drawing
  • US9246774B2 patent drawing

AI summary

Disclosed herein are a system, computer-readable medium, and method for enforcing network policies. Samples of data traveling through at least some nodes of a network are collected. It is determined whether a node violated a predefined network policy based on the samples.