Network Validation via Domain Specific Language

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security configurations require extensive IT specialist intervention, making them costly and inefficient for maintaining secure network communications, as they need to be uniquely tailored and updated to prevent unauthorized access, which is increasingly complex and prohibitive.

Innovation Solution

A network validation system that uses domain-specific language to express user intent, allowing for automated generation, analysis, and validation of network configurations, correcting errors, and providing guidance to ensure compliance with user-defined policies, thereby reducing the need for manual IT intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IT specialists manually configure each network object to reject or allow network traffic, then network security can be tailored to unique requirements, but the cost and complexity of maintaining secure communications increases significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables users to configure network security policies through an intuitive interface without requiring IT specialist intervention. Users can define their own network objects, assign CIDR blocks, and set traffic rules through a self-service configuration process that automatically translates into network object configurations, eliminating the need for manual IT specialist configuration while maintaining security tailored to unique requirements

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical configuration processes with automated software-based configuration. The system automatically translates user-friendly policy statements into network object configurations, automatically provisions network objects, and maintains configurations without human intervention, thereby reducing complexity while preserving security customization

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If IT specialists manually update network configurations to prevent security breaches, then security can be maintained against sophisticated attacks, but the time and resources required for ongoing maintenance becomes prohibitive

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidmaintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables users to independently update network security configurations through the self-service interface. Users can modify existing policies, add new network objects, and update traffic rules without requiring IT specialist involvement, allowing ongoing security maintenance to be performed by users themselves and eliminating the prohibitive time and resource costs associated with continuous manual maintenance

Inventive Principle:
Principle #25Self-service

3Extent of automation

If domain specific language is used to express user intent for network configuration, then automation of configuration and validation is enabled, but the system must handle variances and errors within error thresholds

Engineering Contradiction:
Improveconfiguration automationVSAvoidconfiguration accuracy
Core Design Contradiction:
Extent of automationVSManufacturing precision

Solution Approach 1:

The system performs preliminary validation of user input against defined error thresholds before configuration is applied. The validation engine proactively identifies potential issues, variances, and errors in the domain specific language input and resolves them automatically or provides guidance, ensuring that only valid and accurate configurations are deployed while enabling full automation of the configuration process

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11823701B2Network operation based on domain specific language
Publication Date: 2023.11.21 ORACLE INT CORP
  • US11823701B2 patent drawing
  • US11823701B2 patent drawing
  • US11823701B2 patent drawing

AI summary

A network validation system is described which may perform operations such as generating, analyzing, verifying, correcting, recommending, and deploying language, symbols, etc., such as domain specific language, configured to allow users to express their intent on the configuration and operation of a network, such as a cloud-based network. The network validation system may provide domain specific language that includes rules, statements, symbols, data, etc., configured to convey the intent of users on the configuration and operation of networks for purposes such as configuring and/or validating communication paths, testing or setting associated network object configurations, and may be employed to report violations in such configurations relative to user intent of the one or more users. The network validation system may also be employed to monitor such domain specific language and generate telemetry signaling, for example, that a rule has or has not been violated, actions a user may take, etc.