IP Library Granted Patent US 10,491,529
Granted Patent B2
US 10,491,529 · App. 15/639,914 · Granted Nov 26, 2019

Automatic rule generation for flow management in software defined networking networks

Inventors: Mario Baldi (Brooklyn, NY); Han Hee Song (San Jose, CA); Antonio Nucci (San Jose, CA); Marco Mellia (Turin, IT); Martino Trevisan (Turin, IT); Idilio Drago (Turin, IT)
Assignee: Cisco Technology, Inc.
H04L47/2483H04L45/38H04L45/64H04L61/1511
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,491,529
App. No.
15/639,914
Granted
Nov 26, 2019
Kind
B2
Abstract

In an example embodiment, a Software Defined Networking (SDN) application identifies a domain based on a destination address of a packet that is associated with a primary service. The domain corresponds to the primary service, and the primary service is configured to trigger one or more support flows from one or more ancillary services. The SDN application identifies the one or more support flows based on the domain, and generates one or more rules for distribution to one or more network elements that handle packets of the one or more support flows from the one or more ancillary services.

Claims (61)

1. A method comprising:

obtaining, from a user, an indication of an association of a domain corresponding to a primary service and one or more support domains corresponding to one or more ancillary services, wherein the primary service is configured to trigger one or more support flows from the one or more ancillary services;

identifying the domain based on a destination address of a packet that is associated with the primary service;

identifying the one or more support flows based on the domain; and

generating one or more rules for distribution to one or more network elements that handle packets of the one or more support flows from the one or more ancillary services.

2. The method of claim 1 , further comprising:

before identifying the domain, obtaining the packet from a network controller; and

after generating the one or more rules, forwarding the packet to the network controller or declining to forward the packet to the network controller.

3. The method of claim 1 , further comprising:

obtaining, from a domain name server, information indicating an association of the destination address of the packet with the domain.

4. The method of claim 1 , further comprising:

monitoring one or more previous flows that enabled direct access to the primary service, the primary service having triggered one or more previous support flows from the one or more ancillary services; and

producing, based on the monitoring, an indication of an association of the domain and the one or more support domains corresponding to the one or more ancillary services.

5. The method of claim 1 , further comprising:

storing the indication.

6. The method of claim 1 , further comprising:

determining at least one of a number of times the primary service is directly accessed, an amount of traffic generated when the primary service is accessed, or a number of packets exchanged when the primary service is accessed.

7. The method of claim 1 , wherein the one or more rules include one or more of:

a rule to block the one or more support flows;

a rule to route the one or more support flows on a specific path or to a specific device; or

a rule to prioritize or deprioritize the one or more support flows relative to one or more other network flows.

8. An apparatus comprising:

a network interface unit configured to enable network communications; and

one or more processors coupled to the network interface unit, wherein the one or more processors are configured to:

obtain, from a user, an indication of an association of a domain corresponding to a primary service and one or more support domains corresponding to one or more ancillary services, wherein the primary service is configured to trigger one or more support flows from the one or more ancillary services;

identify the domain based on a destination address of a packet that is associated with the primary service;

identify the one or more support flows based on the domain; and

generate one or more rules for distribution to one or more network elements that handle packets of the one or more support flows from the one or more ancillary services.

9. The apparatus of claim 8 , wherein the one or more processors are further configured to:

before identifying the domain, obtain the packet from a network controller; and

after generating the one or more rules, forward the packet to the network controller or decline to forward the packet to the network controller.

10. The apparatus of claim 8 , wherein the one or more processors are further configured to:

obtain, from a domain name server, information indicating an association of the destination address of the packet with the domain.

11. The apparatus of claim 8 , wherein the one or more processors are further configured to:

monitor one or more previous flows that enabled direct access to the primary service, the primary service having triggered one or more previous support flows from the one or more ancillary services; and

produce, based on the monitoring, an indication of an association of the domain and the one or more support domains corresponding to the one or more ancillary services.

12. The apparatus of claim 8 , wherein the one or more processors are further configured to:

store the indication.

13. The apparatus of claim 8 , wherein the one or more processors are further configured to:

determine at least one of a number of times the primary service is directly accessed, an amount of traffic generated when the primary service is accessed, or a number of packets exchanged when the primary service is accessed.

14. The apparatus of claim 8 , wherein the one or more rules include one or more of:

a rule to block the one or more support flows;

a rule to route the one or more support flows on a specific path or to a specific device; or

a rule to prioritize or deprioritize the one or more support flows relative to one or more other network flows.

15. One or more non-transitory computer readable storage media encoded with instructions that, when executed by a processor, cause the processor to:

obtain, from a user, an indication of an association of a domain corresponding to a primary service and one or more support domains corresponding to one or more ancillary services, wherein the primary service is configured to trigger one or more support flows from the one or more ancillary services;

identify the domain based on a destination address of a packet that is associated with the primary service;

identify the one or more support flows based on the domain; and

generate one or more rules for distribution to one or more network elements that handle packets of the one or more support flows from the one or more ancillary services.

16. The one or more non-transitory computer readable storage media of claim 15 , wherein the instructions further cause the processor to:

before identifying the domain, obtain the packet from a network controller; and

after generating the one or more rules, forward the packet to the network controller or decline to forward the packet to the network controller.

17. The one or more non-transitory computer readable storage media of claim 15 , wherein the instructions further cause the processor to:

obtain, from a domain name server, information indicating an association of the destination address of the packet with the domain.

18. The one or more non-transitory computer readable storage media of claim 15 , wherein the instructions further cause the processor to:

monitor one or more previous flows that enabled direct access to the primary service, the primary service having triggered one or more previous support flows from the one or more ancillary services; and

produce, based on the monitoring, an indication of an association of the domain and the one or more support domains corresponding to the one or more ancillary services.

19. The one or more non-transitory computer readable storage media of claim 15 , wherein the instructions further cause the processor to:

store the indication.

20. The one or more non-transitory computer readable storage media of claim 15 , wherein the instructions further cause the processor to:

determine at least one of a number of times the primary service is directly accessed, an amount of traffic generated when the primary service is accessed, or a number of packets exchanged when the primary service is accessed.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2017
From: BALDI, MARIO; SONG, HAN HEE; NUCCI, ANTONIO; MELLIA, MARCO; TREVISAN, MARTINO; DRAGO, IDILIO
To: CISCO TECHNOLOGY, INC.
Reel/Frame 042923/0562 →
Continuity (1)
Related Publication 20190007327A1 · Jan 3, 2019
Cited By (2)
US 12,549,948 US 12,719,804