SYSTEM AND METHOD FOR NETWORK POLICY SIMULATION
This disclosure generally relate to a method and system for network policy simulation in a distributed computing system. The present technology relates techniques that enable simulation of a new network policy with regard to its effects on the network data flow. By enabling a simulation data flow that is parallel and independent from the regular data flow, the present technology can provide optimized network security management with improved efficiency.
1 . A method comprising:
receiving a network traffic from a first endpoint group of a network destined for a second endpoint group of the network;
capturing first network flow data between the first endpoint group and the second endpoint group based at least in part by enforcing a first network policy of the network with respect to the network traffic;
receiving a request to simulate enforcement of a second network policy between the first endpoint group and the second endpoint group;
determining second network flow data between the first endpoint group and the second endpoint group by simulating enforcement of the second network policy with respect to the network traffic; and
providing an indication whether to enforce the second network policy based at least in part on the second network flow data.
2 . The method of claim 1 , further comprising:
receiving aggregate network flow data from a plurality of sensors of the network, the plurality of sensors including at least a first sensor of a physical switch of the network, a second sensor of a hypervisor associated with the physical switch, a third sensor of a virtual machine associated with the hypervisor;
determining, based at least in part on the aggregate network flow data, a dependency map of an application executing in the network, the dependency map indicating a pattern of network traffic associated with the application;
determining, based at least in part on the dependency map, at least one network policy for the network; and
storing the at least one network policy in a policy table.
3 . The method of claim 2 , wherein the at least one network policy comprises a whitelist rule.
4 . The method of claim 2 , wherein the at least one network policy comprises a blacklist rule, and the method further comprises:
converting, based at least in part on the dependency map, the blacklist rule to a whitelist rule.
5 . The method of claim 2 , further comprising:
simulating removal of at least one network policy from the policy table; and
determining third network flow data without the at least one network policy in effect.
6 . The method of claim 2 , further comprising:
simulating addition of at least one endpoint to the first endpoint group or the second endpoint group; and
determining third network flow data associated with the at least one endpoint.
7 . The method of claim 1 , further comprising:
simulating removal of at least one endpoint from the first endpoint group or the second endpoint group; and
determining third network flow data associated with the at least one endpoint.
8 . The method of claim 1 , further comprising:
simulating membership of at least one endpoint in the first endpoint group to the second endpoint group; and
determining third network flow data associated with the at least one endpoint.
9 . A system comprising:
one or more processors; and
memory including instructions that, upon being executed by the one or more processors, cause the system to: p 1 receive a network traffic from a first endpoint group of a network destined for a second endpoint group of the network;
capture first network flow data between the first endpoint group and the second endpoint group based at least in part by enforcing a first network policy of the network with respect to the network traffic;
receive a request to simulate enforcement of a second network policy between the first endpoint group and the second endpoint group;
determine second network flow data between the first endpoint group and the second endpoint group by simulating enforcement of the second network policy with respect to the network traffic; and
provide an indication whether to enforce the second network policy based at least in part on the second network flow data.
10 . The system of claim 9 , wherein the instructions upon being executed further cause the system to:
receive aggregate network flow data from a plurality of sensors of the network, the plurality of sensors including at least a first sensor of a physical switch of the network, a second sensor of a hypervisor associated with the physical switch, a third sensor of a virtual machine associated with the hypervisor;
determine, based at least in part on the aggregate network flow data, a dependency map of an application executing in the network, the dependency map indicating a pattern of network traffic associated with the application;
determine, based at least in part on the dependency map, at least one network policy for the network; and
store the at least one network policy in a policy table.
11 . The system of claim 10 , wherein the at least one network policy comprises a whitelist rule.
12 . The system of claim 10 , wherein the at least one network policy comprises a blacklist rule, and the instructions upon being executed further cause the system to:
convert, based at least in part on the dependency map, the blacklist rule to a whitelist rule.
13 . The system of claim 9 , wherein the instructions upon being executed further cause the system to:
simulate removal of at least one network policy from the policy table; and
determine third network flow data without the at least one network policy in effect.
14 . The system of claim 9 , wherein the instructions upon being executed further cause the system to:
simulate addition of at least one endpoint to the first endpoint group or the second endpoint group; and
determine third network flow data associated with the at least one endpoint.
15 . The system of claim 9 , wherein the instructions upon being executed further cause the system to:
simulate modification of at least one endpoint in the first endpoint group to the second endpoint group; and
determine third network flow data associated with the at least one endpoint.
16 . A non-transitory computer-readable storage medium having stored therein instructions that, upon being executed by a processor, cause the processor to:
receive a network traffic from a first endpoint group of a network destined for a second endpoint group of the network;
capture first network flow data between the first endpoint group and the second endpoint group based at least in part by enforcing a first network policy of the network with respect to the network traffic; p 1 receive a request to simulate enforcement of a second network policy between the first endpoint group and the second endpoint group;
determine second network flow data between the first endpoint group and the second endpoint group by simulating enforcement of the second network policy with respect to the network traffic; and
provide an indication whether to enforce the second network policy based at least in part on the second network flow data.
17 . The non-transitory computer-readable storage medium of claim 16 , wherein the instructions upon being executed further cause the processor to:
receive aggregate network flow data from a plurality of sensors of the network, the plurality of sensors including at least a first sensor of a physical switch of the network, a second sensor of a hypervisor associated with the physical switch, a third sensor of a virtual machine associated with the hypervisor;
determine, based at least in part on the aggregate network flow data, a dependency map of an application executing in the network, the dependency map indicating a pattern of network traffic associated with the application;
determine, based at least in part on the dependency map, at least one network policy for the network; and
store the at least one network policy in a policy table.
18 . The non-transitory computer-readable storage medium of claim 17 , wherein the instructions upon being executed further cause the processor to:
simulate removal of at least one network policy from the policy table; and
determine second simulated network flow data without the at least one network policy in effect.
19 . The non-transitory computer-readable storage medium of claim 16 , wherein the instructions upon being executed further cause the processor to:
simulate addition of at least one endpoint to the first endpoint group or the second endpoint group; and
determine third network flow data associated with the at least one endpoint.
20 . The non-transitory computer-readable storage medium of claim 16 , wherein the instructions upon being executed further cause the processor to:
simulate modification of at least one endpoint in the first endpoint group to the second endpoint group; and
determine third network flow data associated with the at least.