Policy Impact Logic for SDN Traffic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing large numbers of network security policies in modern data networks is challenging, leading to potential network latency or failures due to changes such as adding or removing policies, which can impact traffic flow and resource utilization.
Innovation Solution
Implementing policy impact logic within a software-defined network controller to analyze the impact of new policies on network devices and traffic flow by receiving configuration information and traffic records, determining the impact, and modifying or rejecting policies to avoid detrimental effects on network resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network security policies are manually managed, then policy implementation flexibility is maintained, but network latency and failures occur due to the large number of policies and changes
Solution Approach 1:
The patent introduces policy impact logic as an intermediary component between policy administrators and network devices. This logic automatically analyzes the impact of policy changes on traffic flows and resource utilization before implementation, preventing network failures and latency issues while managing complex policy sets. The intermediary performs pre-approval analysis and provides recommendations, reducing manual management burden while maintaining network stability.
2Reliability
If new policies are applied to network devices, then network security is improved, but network latency or failures may occur due to resource constraints
Solution Approach 1:
The patent implements preliminary analysis of policy impact before actual policy deployment. The policy impact logic evaluates resource utilization, traffic flow effects, and potential latency issues in advance. This preliminary action identifies problematic policies before they are applied to network devices, preventing network failures and latency while still allowing security improvements through carefully vetted policy changes.
3Adaptability or versatility
If manual policy management is performed, then policy changes can be implemented, but the large number of policies leads to network failures
Solution Approach 1:
The patent implements a feedback mechanism where policy impact logic continuously monitors network performance and provides recommendations on policy changes. The system analyzes the impact of proposed policies on existing traffic flows and resource utilization, then feeds this information back to policy administrators. This feedback loop enables adaptable policy management while maintaining network stability through informed decision-making.
Data Source
AI summary
Presented herein are techniques for determining the impact a policy change might have on a network. The techniques include receiving configuration information from a plurality of network devices in a network, receiving traffic flow records from the plurality of network devices, receiving an indication of an intent to apply a new policy on the network devices, and based on the configuration information, traffic flow records and the new policy, determining an impact of the new policy on the network devices and traffic flowing through the network.


