IP Library Patent Application 15045205
Patent Application
App. No. 15/045,205

SYSTEM AND METHOD FOR NETWORK POLICY SIMULATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/045,205
Abstract

This disclosure generally relate to a method and system for network policy simulation in a distributed computing system. The present technology relates techniques that enable simulation of a new network policy with regard to its effects on the network data flow. By enabling a simulation data flow that is parallel and independent from the regular data flow, the present technology can provide optimized network security management with improved efficiency.

Claims (69)

1 . A method comprising:

receiving a network traffic from a first endpoint group of a network destined for a second endpoint group of the network;

capturing first network flow data between the first endpoint group and the second endpoint group based at least in part by enforcing a first network policy of the network with respect to the network traffic;

receiving a request to simulate enforcement of a second network policy between the first endpoint group and the second endpoint group;

determining second network flow data between the first endpoint group and the second endpoint group by simulating enforcement of the second network policy with respect to the network traffic; and

providing an indication whether to enforce the second network policy based at least in part on the second network flow data.

2 . The method of claim 1 , further comprising:

receiving aggregate network flow data from a plurality of sensors of the network, the plurality of sensors including at least a first sensor of a physical switch of the network, a second sensor of a hypervisor associated with the physical switch, a third sensor of a virtual machine associated with the hypervisor;

determining, based at least in part on the aggregate network flow data, a dependency map of an application executing in the network, the dependency map indicating a pattern of network traffic associated with the application;

determining, based at least in part on the dependency map, at least one network policy for the network; and

storing the at least one network policy in a policy table.

3 . The method of claim 2 , wherein the at least one network policy comprises a whitelist rule.

4 . The method of claim 2 , wherein the at least one network policy comprises a blacklist rule, and the method further comprises:

converting, based at least in part on the dependency map, the blacklist rule to a whitelist rule.

5 . The method of claim 2 , further comprising:

simulating removal of at least one network policy from the policy table; and

determining third network flow data without the at least one network policy in effect.

6 . The method of claim 2 , further comprising:

simulating addition of at least one endpoint to the first endpoint group or the second endpoint group; and

determining third network flow data associated with the at least one endpoint.

7 . The method of claim 1 , further comprising:

simulating removal of at least one endpoint from the first endpoint group or the second endpoint group; and

determining third network flow data associated with the at least one endpoint.

8 . The method of claim 1 , further comprising:

simulating membership of at least one endpoint in the first endpoint group to the second endpoint group; and

determining third network flow data associated with the at least one endpoint.

9 . A system comprising:

one or more processors; and

memory including instructions that, upon being executed by the one or more processors, cause the system to: p 1 receive a network traffic from a first endpoint group of a network destined for a second endpoint group of the network;

capture first network flow data between the first endpoint group and the second endpoint group based at least in part by enforcing a first network policy of the network with respect to the network traffic;

receive a request to simulate enforcement of a second network policy between the first endpoint group and the second endpoint group;

determine second network flow data between the first endpoint group and the second endpoint group by simulating enforcement of the second network policy with respect to the network traffic; and

provide an indication whether to enforce the second network policy based at least in part on the second network flow data.

10 . The system of claim 9 , wherein the instructions upon being executed further cause the system to:

receive aggregate network flow data from a plurality of sensors of the network, the plurality of sensors including at least a first sensor of a physical switch of the network, a second sensor of a hypervisor associated with the physical switch, a third sensor of a virtual machine associated with the hypervisor;

determine, based at least in part on the aggregate network flow data, a dependency map of an application executing in the network, the dependency map indicating a pattern of network traffic associated with the application;

determine, based at least in part on the dependency map, at least one network policy for the network; and

store the at least one network policy in a policy table.

11 . The system of claim 10 , wherein the at least one network policy comprises a whitelist rule.

12 . The system of claim 10 , wherein the at least one network policy comprises a blacklist rule, and the instructions upon being executed further cause the system to:

convert, based at least in part on the dependency map, the blacklist rule to a whitelist rule.

13 . The system of claim 9 , wherein the instructions upon being executed further cause the system to:

simulate removal of at least one network policy from the policy table; and

determine third network flow data without the at least one network policy in effect.

14 . The system of claim 9 , wherein the instructions upon being executed further cause the system to:

simulate addition of at least one endpoint to the first endpoint group or the second endpoint group; and

determine third network flow data associated with the at least one endpoint.

15 . The system of claim 9 , wherein the instructions upon being executed further cause the system to:

simulate modification of at least one endpoint in the first endpoint group to the second endpoint group; and

determine third network flow data associated with the at least one endpoint.

16 . A non-transitory computer-readable storage medium having stored therein instructions that, upon being executed by a processor, cause the processor to:

receive a network traffic from a first endpoint group of a network destined for a second endpoint group of the network;

capture first network flow data between the first endpoint group and the second endpoint group based at least in part by enforcing a first network policy of the network with respect to the network traffic; p 1 receive a request to simulate enforcement of a second network policy between the first endpoint group and the second endpoint group;

determine second network flow data between the first endpoint group and the second endpoint group by simulating enforcement of the second network policy with respect to the network traffic; and

provide an indication whether to enforce the second network policy based at least in part on the second network flow data.

17 . The non-transitory computer-readable storage medium of claim 16 , wherein the instructions upon being executed further cause the processor to:

receive aggregate network flow data from a plurality of sensors of the network, the plurality of sensors including at least a first sensor of a physical switch of the network, a second sensor of a hypervisor associated with the physical switch, a third sensor of a virtual machine associated with the hypervisor;

determine, based at least in part on the aggregate network flow data, a dependency map of an application executing in the network, the dependency map indicating a pattern of network traffic associated with the application;

determine, based at least in part on the dependency map, at least one network policy for the network; and

store the at least one network policy in a policy table.

18 . The non-transitory computer-readable storage medium of claim 17 , wherein the instructions upon being executed further cause the processor to:

simulate removal of at least one network policy from the policy table; and

determine second simulated network flow data without the at least one network policy in effect.

19 . The non-transitory computer-readable storage medium of claim 16 , wherein the instructions upon being executed further cause the processor to:

simulate addition of at least one endpoint to the first endpoint group or the second endpoint group; and

determine third network flow data associated with the at least one endpoint.

20 . The non-transitory computer-readable storage medium of claim 16 , wherein the instructions upon being executed further cause the processor to:

simulate modification of at least one endpoint in the first endpoint group to the second endpoint group; and

determine third network flow data associated with the at least.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2016
From: GUPTA, SUNIL KUMAR; YADAV, NAVINDRA; WATTS, MICHAEL STANDISH; PARANDEHGHEIBI, ALI; GANDHAM, SHASHIDHAR; KULSHRESHTHA, ASHUTOSH; DEEN, KHAWAR
To: CISCO TECHNOLOGY, INC.
Reel/Frame 037746/0462 →