IP Library Granted Patent US 11,509,535
Granted Patent B2
US 11,509,535 · App. 16/999,447 · Granted Nov 22, 2022

Network agent for reporting to a network policy system

Inventors: Hai Vu (San Jose, CA); Shih-Chun Chang (San Jose, CA); Varun Malhotra (Sunnyvale, CA); Shashi Gandham (Fremont, CA); Navindra Yadav (Cupertino, CA); Allen Chen (Mountain View, CA); Praneeth Vallem (San Jose, CA); Rohit Prasad (Sunnyvale, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L41/0893H04L41/046H04L43/06H04L67/02H04L43/065H04L43/0817
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,509,535
App. No.
16/999,447
Granted
Nov 22, 2022
Kind
B2
Abstract

The disclosed technology relates to a network agent for reporting to a network policy system. A network agent includes an agent enforcer and an agent controller. The agent enforcer is configured to implementing network policies on the system, access data associated with the implementation of the network policies on the system, and transmit, via an interprocess communication, the data to the agent controller. The agent controller is configured to generate a report including the data and transmit the report to a network policy system.

Claims (72)

1. A network entity comprising:

at least one processor; and

at least one memory storing instructions that, when executed by the at least one processor, cause the at least one processor to:

receive a network policy;

implement, by a first agent with a privileged status running on the network entity, the network policy;

access, by the first agent and based on the privileged status, policy enforcement data associated with the implementation of the network policy;

enable access, by the first agent to a second agent without a privileged status running on the network entity, the policy enforcement data;

generate, by the second agent, a report based on the policy enforcement data; and

transmit the report.

2. The network entity of claim 1 , further comprising:

one or more sensors configured to collect the policy enforcement data.

3. The network entity of claim 1 , further comprising instructions which when executed by the at least one processor, cause the at least one processor to:

access, by the first agent based on the privileged status, entity or performance data of the network entity;

enable access, to the second agent, to the entity or performance data; and

generate, by the second agent, the report to include the entity or performance data.

4. The network entity of claim 1 , further comprising instructions which when executed by the at least one processor, cause the at least one processor to:

periodically collect the policy enforcement data; and

enable access, to the second agent, to the periodically collected policy enforcement data for generating the report.

5. The network entity of claim 1 , further comprising instructions which when executed by the at least one processor, cause the at least one processor to:

determine implementation characteristics of the network entity;

generate one or more specific polices from the network policy based on the implementation characteristics; and

implement the one or more specific policies.

6. The network entity of claim 5 , further comprising instructions which when executed by the at least one processor, cause the at least one processor to:

identity that a specific policy from the one or more specific policies has been altered; and

in response to the identification that the specific policy is altered, revert to a previous policy.

7. The network entity of claim 1 , wherein the network policy is based on user intent.

8. At least one non-transitory computer readable medium storing instructions that, when executed by the at least one processor, cause the at least one processor to:

receive a network policy;

implement, by a first agent with a privileged status running on the network entity, the network policy;

access, by the first agent and based on the privileged status, policy enforcement data associated with the implementation of the network policy;

enable access, by the first agent to a second agent without a privileged status running on the network entity, the policy enforcement data;

generate, by the second agent, a report based on the policy enforcement data; and

transmit the report.

9. The at least one non-transitory computer readable medium of claim 8 , further comprising:

one or more sensors configured to collect the policy enforcement data.

10. The at least one non-transitory computer readable medium of claim 8 , further comprising instructions which when executed by the at least one processor, cause the at least one processor to:

access, by the first agent based on the privileged status, entity or performance data of the network entity;

enable access, to the second agent, to the entity or performance data; and

generate, by the second agent, the report to include the entity or performance data.

11. The at least one non-transitory computer readable medium of claim 8 , further comprising instructions which when executed by the at least one processor, cause the at least one processor to:

periodically collect the policy enforcement data; and

enable access, to the second agent, to the periodically collected policy enforcement data for generating the report.

12. The at least one non-transitory computer readable medium of claim 8 , further comprising instructions which when executed by the at least one processor, cause the at least one processor to:

determine implementation characteristics of the network entity;

generate one or more specific polices from the network policy based on the implementation characteristics; and

implement the one or more specific policies.

13. The at least one non-transitory computer readable medium of claim 12 , further comprising instructions which when executed by the at least one processor, cause the at least one processor to:

identity that a specific policy from the one or more specific policies has been altered; and

in response to the identification that the specific policy is altered, revert to a previous policy.

14. The least one non-transitory computer readable medium of claim 8 , wherein the network policy is based on user intent.

15. A method comprising:

receiving, at a network entity, a network policy;

implementing, by a first agent with a privileged status running on a network entity, the network policy;

accessing, by the first agent and based on the privileged status, policy enforcement data associated with the implementation of the network policy;

enabling access, by the first agent to a second agent without a privileged status running on the network entity, the policy enforcement data;

generating, by the second agent, a report based on the policy enforcement data; and

transmitting the report.

16. The method of claim 15 , further comprising:

accessing, by the first agent based on the privileged status, entity or performance data of the network entity;

enabling access, to the second agent, to the entity or performance data; and

generating, by the second agent, the report to include the entity or performance data.

17. The method of claim 15 , further comprising:

periodically collecting the policy enforcement data; and

enabling access, to the second agent, to the periodically collected policy enforcement data for generating the report.

18. The method of claim 15 , further comprising:

determining implementation characteristics of the network entity;

generating one or more specific polices from the network policy based on the implementation characteristics; and

implementing the one or more specific policies.

19. The method of claim 18 , further comprising:

identifying that a specific policy from the one or more specific policies has been altered; and

in response to identifying that the specific policy is altered, reverting to a previous policy.

20. The method of claim 15 , wherein the network policy is based on user intent.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2020
From: VU, HAI; CHANG, SHIH-CHUN; MALHOTRA, VARUN; GANDHAM, SHASHI; YADAV, NAVINDRA; CHEN, ALLEN; VALLEM, PRANEETH; PRASAD, ROHIT
To: CISCO TECHNOLOGY, INC.
Reel/Frame 053562/0316 →
Continuity (2)
Continuation 15469737 · Mar 27, 2017
Related Publication 20200389361A1 · Dec 10, 2020
Cited By (1)
US 12,218,919