Simulated Endpoints for Network Policy Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network policies applied to virtual local area networks (VLANs) and virtual extensible local area networks (VXLANs) face challenges in verifying the correct application of policies across endpoint groups, leading to potential mismanagement of traffic forwarding and security within modern network environments.

Innovation Solution

A method is introduced where a network connected device provisions simulated endpoints on switches to test policy application by sending packets with varying five-tuple headers, using traceroute and ACL logging to verify if policies are correctly applied, allowing for the identification of any discrepancies in policy implementation across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If simulated endpoints are provisioned on switches to verify policy application, then policy verification accuracy is improved, but device complexity increases

Engineering Contradiction:
Improvepolicy verification accuracyVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates simulated endpoints that are virtual copies of actual network endpoints. These simulated endpoints replicate the behavior and characteristics of real endpoints without requiring physical hardware, thereby improving verification accuracy while avoiding the complexity of additional physical devices. The simulated endpoints are provisioned on existing switch infrastructure through software-based virtualization.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The simulated endpoints act as intermediaries between the policy verification system and the actual network traffic. They receive and respond to test packets in a controlled manner, allowing verification of policy application without directly involving real endpoints. This intermediary layer simplifies the verification process by providing a controlled testing environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple packets are sent to simulated endpoint for each policy outcome, then policy verification completeness is improved, but loss of time increases

Engineering Contradiction:
Improvepolicy verification completenessVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-provisions simulated endpoints on suitable switches before verification begins. This preliminary setup includes configuring the simulated endpoints with appropriate characteristics and establishing their readiness to receive test packets. By preparing the verification environment in advance, the actual verification process can proceed more efficiently without setup delays during execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The verification process sends packets periodically or in structured batches to simulated endpoints rather than continuously. This approach allows the system to verify multiple policy outcomes systematically while managing the time required for verification. The periodic sending of test packets enables comprehensive coverage of policy scenarios without overwhelming the network infrastructure.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10009229B2Policy verification in a network
Publication Date: 2018.06.26 CISCO TECHNOLOGY INC
  • US10009229B2 patent drawing
  • US10009229B2 patent drawing
  • US10009229B2 patent drawing

AI summary

A determination is made at a network connected device that a network policy is to be verified. The network policy is applied to network packets sent to an endpoint within a network, and the application of the policy to network traffic can result in at least two outcomes. Another determination is made at the network connected device that a switch is provisionable to host the endpoint. The network connected device provisions a simulated endpoint version of the endpoint at the switch to host the policy. At least one packet is sent to the simulated endpoint via the network connected device for each of the at least two outcomes of the policy. At least one response is received by the network connected device from the simulated endpoint indicating how the policy was applied to each of the packets.