Policy Impact Logic for SDN Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing large numbers of network security policies in modern data networks is challenging, leading to potential network latency or failures due to changes such as adding or removing policies, which can impact traffic flow and resource utilization.

Innovation Solution

Implementing policy impact logic within a software-defined network controller to analyze the impact of new policies on network devices and traffic flow by receiving configuration information and traffic records, determining the impact, and modifying or rejecting policies to avoid detrimental effects on network resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security policies are manually managed, then policy implementation flexibility is maintained, but network latency and failures occur due to the large number of policies and changes

Engineering Contradiction:
Improvenetwork stabilityVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces policy impact logic as an intermediary component between policy administrators and network devices. This logic automatically analyzes the impact of policy changes on traffic flows and resource utilization before implementation, preventing network failures and latency issues while managing complex policy sets. The intermediary performs pre-approval analysis and provides recommendations, reducing manual management burden while maintaining network stability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If new policies are applied to network devices, then network security is improved, but network latency or failures may occur due to resource constraints

Engineering Contradiction:
Improvenetwork stabilityVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary analysis of policy impact before actual policy deployment. The policy impact logic evaluates resource utilization, traffic flow effects, and potential latency issues in advance. This preliminary action identifies problematic policies before they are applied to network devices, preventing network failures and latency while still allowing security improvements through carefully vetted policy changes.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If manual policy management is performed, then policy changes can be implemented, but the large number of policies leads to network failures

Engineering Contradiction:
Improvepolicy change capabilityVSAvoidnetwork stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where policy impact logic continuously monitors network performance and provides recommendations on policy changes. The system analyzes the impact of proposed policies on existing traffic flows and resource utilization, then feeds this information back to policy administrators. This feedback loop enables adaptable policy management while maintaining network stability through informed decision-making.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10389594B2Assuring policy impact before application of policy on current flowing traffic
Publication Date: 2019.08.20 CISCO TECHNOLOGY INC
  • US10389594B2 patent drawing
  • US10389594B2 patent drawing
  • US10389594B2 patent drawing

AI summary

Presented herein are techniques for determining the impact a policy change might have on a network. The techniques include receiving configuration information from a plurality of network devices in a network, receiving traffic flow records from the plurality of network devices, receiving an indication of an intent to apply a new policy on the network devices, and based on the configuration information, traffic flow records and the new policy, determining an impact of the new policy on the network devices and traffic flowing through the network.