Network Switch ACL Verification via Machine-Readable Maps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network access control constructs, such as ACLs, in data centers are prone to errors and costly to manage, especially in dynamic environments, and are vulnerable to malicious alterations, compromising security and efficiency.

Innovation Solution

An automated method and system for verifying network access control constructs on network switches by comparing actual configurations with pre-defined maps, ensuring accurate and secure access control through machine-readable maps and validation protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual configuration of network access control constructs is used, then flexibility in adapting to dynamic environments is improved, but error rate and operational cost increase

Engineering Contradiction:
Improveadaptability to dynamic environmentsVSAvoiderror rate
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system automatically verifies and maintains network access control constructs by comparing actual configurations against expected configurations stored in machine-readable maps. The verification process self-corrects discrepancies without requiring manual intervention, thereby maintaining adaptability while reducing human error.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors actual network configurations and provides feedback by comparing them against expected configurations. When discrepancies are detected, the system can automatically generate corrections or alert administrators, creating a closed-loop system that maintains reliability while adapting to dynamic changes.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If manual verification of access control lists is performed, then flexibility in configuration changes is improved, but time consumption and operational cost increase

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidverification time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The verification system operates autonomously by automatically accessing network switches, retrieving actual access control list configurations, comparing them against expected configurations from machine-readable maps, and generating verification reports without requiring manual intervention, thereby eliminating time-consuming manual verification processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual verification processes with automated computational processes. Machine-readable maps store expected configurations, and the system automatically compares actual configurations against these stored expectations using computational algorithms, substituting the mechanical/manual verification process with an automated information processing system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If automated verification system is implemented, then error reduction and security are improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces machine-readable maps as intermediary data structures that store expected configurations. These maps act as a mediator between the verification system and the network switches, allowing the system to verify configurations without directly managing complex network states. The maps simplify the verification logic by providing pre-computed expected values.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates copies of expected configurations in machine-readable maps, which are then used for verification purposes. Instead of maintaining complex real-time synchronization with all network devices, the system uses static or periodically updated copies of expected configurations, simplifying the verification process while maintaining security.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If frequent ACL changes are made to accommodate dynamic network needs, then adaptability is improved, but vulnerability to malicious alterations increases

Engineering Contradiction:
Improvenetwork adaptabilityVSAvoidmalicious attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system provides continuous feedback by comparing actual ACL configurations against expected configurations stored in machine-readable maps. When changes are made to ACLs, the system detects these changes and can alert administrators or automatically correct them if they deviate from expected configurations, thereby preventing malicious alterations while allowing legitimate adaptive changes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system prepares counter-measures in advance by maintaining expected configurations in machine-readable maps. When unauthorized or malicious changes are detected, the system can immediately reverse them or alert administrators, preventing the harmful effects of malicious alterations before they can compromise security.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS8799466B2Method and apparatus for automatic verification of a network access control construct for a network switch
Publication Date: 2014.08.05 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8799466B2 patent drawing
  • US8799466B2 patent drawing
  • US8799466B2 patent drawing

AI summary

Embodiments of the invention provide a method and an apparatus for automatic verification of a network access control construct for a network switch. In one method embodiment, the present invention accesses an actual network access control construct on a network switching device, the actual network access control construct for defining the device actually coupled with the network switching device. Additionally, a machine-readable map of the network is accessed, the map providing a pre-determined network access control construct defining the device which should be coupled with the network switching device. A validation is performed, wherein the validation verifies that the actual network access control construct on the network switching device correlates with the pre-determined network access control construct defined by the machine-readable map.