IP Library › Granted Patent US 11,102,076
Granted Patent B1
US 11,102,076 · App. 17/167,591 · Granted Aug 24, 2021

Techniques for network policies analysis in container frameworks

Inventors: Olgierd Stanislaw Pieczul (Dublin, IE); Robert Graham Clark (Clyde Hill, WA)
Assignee: Oracle International Corporation
H04L41/0893H04L41/12H04L47/20H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,102,076
App. No.
17/167,591
Filed
Feb 4, 2021
Granted
Aug 24, 2021
Kind
B1
Art Unit
2454
USPC
709/223
Abstract

Techniques are disclosed for query processing system that can, when queried, generate a result related to one or more connectivity paths and/or one or more network security rules. Network security rules and connectivity paths may be stored in corresponding data structures (e.g., sets of attributes) that may be utilized with a number of set operations. The user may issue a query requesting the system to apply a rule to a path, a set of rules to a set of paths, to identify if one set of rule(s) are equivalent to another set of rule(s), and the like. Utilizing this query processing system can enable a user to identify effects of one or more network rules with respect to traffic being allowed or restricted along particular connectivity paths between components of the system.

Claims (37)

1. A computer-implemented method, comprising:

obtaining, by a computing device, a path data structure defining a network connectivity path between at least one pair of computing components of a network;

obtaining, by the computing device, a communication policy data structure defining a network security rule;

receiving, by the computing device from a user device, a query identifying a type of request and at least one of a connectivity path or a particular network security rule;

identifying, by the computing device, a result for the query based at least in part on executing one or more operations corresponding to the type of request using the path data structure and the communication policy data structure; and

providing, by the computing device to the user device, the result in response to the query.

2. The computer-implemented method of claim 1 , wherein the network is implemented within a cloud-computing environment.

3. The computer-implemented method of claim 1 , wherein the network connectivity path is unidirectional.

4. The computer-implemented method of claim 1 , wherein the one or more operations comprises matching a first attribute of the path data structure to a second attribute of the communication policy data structure, wherein the first attribute and the second attribute are sets of data.

5. The computer-implemented method of claim 1 , wherein the communication policy data structure is one of a set of communication policy data structures that comprise one or more ingress rules and one or more egress rules of the network.

6. The computer-implemented method of claim 1 , wherein the communication policy data structure defines an egress rule that identifies a first set of one or more labels that identify one or more source components, a second set of one or more labels that identify a set of components to which traffic is allowed to be sent from the one or more source components, and one or more ports on which the traffic is allowed.

7. The computer-implemented method of claim 1 , wherein the communication policy data structure defines an ingress rule that identifies a first set of one or more labels that identify one or more source components, a second set of one or more labels that identify a set of components from which traffic is allowed to be received, and one or more ports on which the traffic is allowed.

8. A computing device, comprising:

a processor; and

a memory storing instructions that, when executed by the processor, configure the computing device to:

obtain a path data structure defining a network connectivity path between at least one pair of computing components of a network;

obtain a communication policy data structure defining a network security rule;

receive, from a user device, a query identifying a type of request and at least one of a connectivity path or a particular network security rule;

identify a result for the query based at least in part on executing one or more operations corresponding to the type of request using the path data structure and the communication policy data structure; and

provide, to the user device, the result in response to the query.

9. The computing device of claim 8 , wherein the network is implemented within a cloud-computing environment.

10. The computing device of claim 8 , wherein the network connectivity path is unidirectional.

11. The computing device of claim 8 , wherein the one or more operations comprises matching a first attribute of the path data structure to a second attribute of the communication policy data structure, wherein the first attribute and the second attribute are sets of data.

12. The computing device of claim 8 , wherein the communication policy data structure is one of a set of communication policy data structures that comprise one or more ingress rules and one or more egress rules of the network.

13. The computing device of claim 8 , wherein the communication policy data structure defines an egress rule that identifies a first set of one or more labels that identify one or more source components, a second set of one or more labels that identify a set of components to which traffic is allowed to be sent from the one or more source components, and one or more ports on which the traffic is allowed.

14. The computing device of claim 8 , wherein the communication policy data structure defines an ingress rule that identifies a first set of one or more labels that identify one or more source components, a second set of one or more labels that identify a set of components from which traffic is allowed to be received, and one or more ports on which the traffic is allowed.

15. A non-transitory computer-readable medium storing computer-executable instructions that, when executed by one or more processors of a computing device, cause the computing device to:

obtain a path data structure defining a network connectivity path between at least one pair of computing components of a network;

obtain a communication policy data structure defining a network security rule;

receive, from a user device, a query identifying a type of request and at least one of a connectivity path or a particular network security rule;

identify a result for the query based at least in part on executing one or more operations corresponding to the type of request using the path data structure and the communication policy data structure; and

provide, to the user device, the result in response to the query.

16. The non-transitory computer-readable medium of claim 15 , wherein the network is implemented within a cloud-computing environment.

17. The non-transitory computer-readable medium of claim 15 , wherein the network connectivity path is unidirectional.

18. The non-transitory computer-readable medium of claim 15 , wherein the one or more operations comprises matching a first attribute of the path data structure to a second attribute of the communication policy data structure, wherein the first attribute and the second attribute are sets of data.

19. The non-transitory computer-readable medium of claim 15 , wherein the communication policy data structure defines an egress rule that identifies a first set of one or more labels that identify one or more source components, a second set of one or more labels that identify a set of components to which traffic is allowed to be sent from the one or more source components, and one or more ports on which the traffic is allowed.

20. The non-transitory computer-readable medium of claim 15 , wherein the communication policy data structure defines an ingress rule that identifies a first set of one or more labels that identify one or more source components, a second set of one or more labels that identify a set of components from which traffic is allowed to be received, and one or more ports on which the traffic is allowed.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2021
From: PIECZUL, OLGIERD STANISLAW; CLARK, ROBERT GRAHAM
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 055150/0583 →
Cited By (10)
US 12,242,599 US 12,348,519 US 12,355,770 US 12,423,418 US 12,432,242 US 12,585,760 US 12,603,921 US 12,670,246 US 12,684,017 US 12,695,793