Network Security Policy Graph Overlay for Packet Flow Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security products use complex data structures like red-black trees or compiled versions of security policies, which complicate analysis and increase lookup times, making it difficult to create efficient models of network device security policies for network traffic testing.

Innovation Solution

A method is provided to parse and normalize data from network devices, creating a graphical model that overlays security policies as an abstraction on a network topology graph, allowing for the evaluation of packet flow and integration of security policies with network topology, enabling holistic evaluation across multi-vendor ecosystems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If complex data structures like red-black trees or compiled security policies are used, then lookup times are improved, but analysis and scrutiny become difficult and device complexity increases

Engineering Contradiction:
Improvelookup timeVSAvoiddata structure complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent creates a digital twin - a virtual copy of the network device that includes a graphical representation of security policies. This copy allows for easy analysis and visualization without affecting the performance of the actual device. The graphical model serves as an analyzable replica that maintains the essential security policy information in a human-readable format.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an intermediary graphical representation layer between the complex internal data structures and the user/analyst. This graphical model acts as a mediator that translates complex red-black tree structures into intuitive visual formats, enabling analysis without requiring direct interaction with the complex underlying data structures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If complex data structures like red-black trees are used, then lookup times are improved, but ease of manufacture and modeling becomes difficult

Engineering Contradiction:
Improvelookup timeVSAvoidmodeling ease
Core Design Contradiction:
Loss of timeVSEase of manufacture

Solution Approach 1:

Instead of directly modeling complex red-black tree structures, the patent creates a simplified graphical copy that represents security policies in an intuitive format. This graphical model can be easily constructed and manipulated without dealing with the complexity of binary search tree implementations, making the modeling process much more accessible.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent segments the security policy representation into discrete graphical elements that can be independently created and combined. Rather than building a monolithic complex data structure, the system divides security policies into visual components that can be manufactured and assembled more easily.

Inventive Principle:
Principle #1Segmentation

3Loss of information

If graphical models overlaying security policies on network topology are created, then visualization and analysis of packet flow is improved, but computational overhead increases

Engineering Contradiction:
Improvesecurity policy visibilityVSAvoidcomputational overhead
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary actions by pre-processing security policies into graphical representations that can be quickly queried. Instead of computing complex data structure traversals during runtime, the system prepares visual models in advance that enable faster analysis of packet flow and security policy interactions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The graphical model serves as a lightweight copy that can be used for analysis without requiring the computational resources needed for complex data structure operations. This visual representation enables policy visibility and packet flow analysis with significantly reduced computational overhead compared to manipulating the actual security policy data structures.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12598183B2Creating graphical models of network security policies and displaying on a network topology graph
Publication Date: 2026.04.07 CISCO TECHNOLOGY INC
  • US12598183B2 patent drawing
  • US12598183B2 patent drawing
  • US12598183B2 patent drawing

AI summary

Techniques and architecture are described for abstracting a real physical twin network wherein security policies are mapped as an overlay on a graphical representation of the network topology. The techniques include receiving, at a computing device, a first security policy) for a first network device. The computing device processes the first security policy to generate a plurality of first access control entries. The computing device creates first graph nodes corresponding to the first access control entries. Based at least in part on a processing order of the first security policy on the first network device, the computing device links the first graph nodes into a graph. The computing device displays the graph on a display, wherein the graph is displayed as an overlay on a network topology graph that includes the first network device.