Structured Policy Expressions for Network Appliances
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As network devices provide increasingly complex functions, configuring and managing their policies becomes complex, leading to performance issues, network errors, and security vulnerabilities due to improper configuration, with a need for structured policy expressions and efficient processing of policies, especially in handling undefined policy scenarios.
Innovation Solution
The development of systems and methods for configuring and evaluating object-oriented policies that allow users to specify structured expressions for network traffic, enabling efficient processing of complex data streams, controlling policy execution order, and defining actions for undefined policy elements, using a configuration interface and a policy engine to apply these policies to network devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the number and complexity of network device functions grow to provide more capabilities, then the functionality and versatility of the network device improve, but the complexity and amount of configuration required increase
Solution Approach 1:
The patent segments the policy configuration into distinct components: policy definitions, policy groups, and policy expressions. This segmentation allows administrators to manage complex network device functions by organizing policies into modular units that can be independently configured and combined, reducing overall configuration complexity while maintaining functionality.
Solution Approach 2:
The patent introduces policy expressions as an intermediary layer between the administrator and the actual policy implementation. These expressions provide a structured language for defining policies, acting as a mediator that simplifies the configuration process while enabling complex network device functions through a standardized interface.
2Adaptability or versatility
If the number of policies required for configuration increases to support more functions, then the versatility of the network device improves, but the difficulty of managing and specifying processing orders increases
Solution Approach 1:
The patent creates a universal policy expression framework that can handle multiple policy types and functions through a single standardized mechanism. This universal approach allows the same policy expression structure to manage diverse network functions, reducing the complexity of managing increasing numbers of policies while maintaining versatility.
Solution Approach 2:
The patent implements policy groups that allow administrators to pre-organize policies into logical collections with predefined processing orders. This preliminary organization reduces the management burden when dealing with large numbers of policies, as administrators can work with grouped policies rather than individual ones, simplifying the specification of processing orders.
3Reliability
If policies are made more specific to handle undefined scenarios, then the reliability of policy evaluation improves, but the complexity of writing always-defined policies increases
Solution Approach 1:
The patent provides default actions that cushion against undefined policy scenarios. When a policy expression does not explicitly match a traffic flow, the system applies a predefined default action, ensuring reliable policy evaluation without requiring administrators to write complex policies that anticipate every possible scenario. This beforehand cushioning maintains reliability while avoiding increased policy complexity.
Data Source
AI summary
Systems and methods for configuring and evaluating policies that direct processing of one or more data streams are described. A configuration interface is described for allowing users to specify object oriented policies. These object oriented policies may allow any data structures to be applied with respect to a payload of a received packet stream, including any portions of HTTP traffic. A configuration interface may also allow the user to control the order in which policies and policy groups are executed, in addition to specifying actions to be taken if one or more policies are undefined. Systems and methods for processing the policies may allow efficient processing of object-oriented policies by applying potentially complex data structures to unstructured data streams. A device may also interpret and process a number of flow control commands and policy group invocation statements to determine an order of execution among a number of policies and policy groups. These policy configurations and processing may allow configuration and processing of complex network behaviors relating to load balancing, VPNs, SSL offloading, content switching, application security, acceleration, and caching.


