Network controller policy enforcement in enterprise networks
The techniques described herein enable a network controller to create multi-faceted policies. The network controller may comprise a VEX processing engine that captures VEX data and generates vulnerability insights, a retrieval augmented generation (RAG) component that can be utilized to generate context data based on the VEX data, vulnerability insights, and data captured by the network controller. The network controller may implement or input the context data to a model, which outputs customized synthetic test(s). The network controller identify, generate, or modify network policies and/or network control policies based on the output from executing the synthetic tests.
1 . A method implemented by a network controller of a network, comprising:
monitoring one or more network devices within the network to determine network data;
receiving software data indicative of software deployed within the network, the software data including a software bill of materials (SBOM);
extracting vulnerability exploitability exchange (VEX) data from the SBOM;
determining, based on the software data and VEX data, a vulnerability insight indicative of a component that is potentially vulnerable within the network;
generating, based on the network data and the vulnerability insight context data indicative of insights into the network;
generating, using the context data and a machine learning model, a synthetic test to evaluate the component that is potentially vulnerable within the network;
causing the synthetic test to be executed within the network;
determining, based on executing the synthetic test, an impact of the component that is potentially vulnerable within the network;
generating, based on the impact, a network controller policy associated with mitigating the impact; and
enforcing the network controller policy.
2 . The method of claim 1 , wherein determining the vulnerability insight is based on receiving a message indicating a security threat or a problem within the network.
3 . The method of claim 1 , wherein the network data includes at least one of telemetry data associated with the one or more network devices within the network, configuration data of the one or more network devices, user data associated with users accessing the network, inventory data, export data associated with applications, or log data.
4 . The method of claim 1 , wherein generating the context data comprises using a retrieval augmented generation (RAG) component of the network controller.
5 . The method of claim 1 , wherein the machine learning model is a large language model (LLM).
6 . The method of claim 1 , wherein generating the network controller policy associated with mitigating the impact comprises:
creating, based on the impact, one or more of a network provisioning policy, telemetry handling policy, or a site wide policy as the network controller policy; and
updating the network controller to apply the network controller policy, wherein the network controller policy is configured to change one or more operational behaviors of the network controller.
7 . The method of claim 1 , further comprising:
determining, based on the impact, a network policy to apply to one or more sites, the one or more network devices, or more or more applications within the network to mitigate the impact; and
sending the network policy to the one or more sites or the one or more network devices within the network.
8 . The method of claim 1 , wherein the synthetic test is customized outputs a score indicating the impact of the component that is potentially vulnerable within the network.
9 . A system comprising:
one or more processors; and
one or more computer-readable media storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:
monitoring, by a network controller, network data associated with a plurality of network devices within a network;
receiving software data indicative of software deployed within the network;
determining, based on the software data, a vulnerability insight indicative of a component that is potentially vulnerable within the network;
generating, by the network controller and based on the network data and the vulnerability insight, context data indicative of insights into the network;
generating, by the network controller and using the context data and a machine learning model, a synthetic test to evaluate the component that is potentially vulnerable within the network;
determining, by the network controller and based on executing the synthetic test, an impact of the component that is potentially vulnerable within the network;
generating, by the network controller and based on the impact, a network controller policy associated with mitigating the impact; and
enforcing, by the network controller, the network controller policy.
10 . The system of claim 9 , the operations further comprising:
extracting, based on processing the software data, vulnerability exploitability exchange (VEX) data from the software data; and
storing data regarding the vulnerability insight and the VEX data within a datastore of the network controller, the data regarding the vulnerability insight being indexed and associated with the software.
11 . The system of claim 10 , wherein generating the context data is based at least in part on the VEX data.
12 . The system of claim 9 , wherein determining the vulnerability insight is based on receiving a message indicating a security threat or a problem within the network.
13 . The system of claim 9 , wherein the network data includes at least one of telemetry data associated with the plurality of network devices within the network, configuration data of the plurality of network devices, user data associated with users accessing the network, VEX data, inventory data, export data associated with applications, or log data.
14 . The system of claim 9 , wherein generating the context data comprises using a retrieval augmented generation (RAG) component of the network controller.
15 . The system of claim 9 , wherein generating the synthetic test comprises providing the context data as input to a large language model (LLM).
16 . The system of claim 9 , wherein the synthetic test is customized and outputs a score indicating the impact of the component that is potentially vulnerable within the network.
17 . The system of claim 9 , the operations further comprising:
determining, based on the impact, a network policy to apply to one or more sites, one or more network devices, or more or more applications within the network to mitigate the impact; and
sending the network policy to the one or more sites or the one or more network devices within the network.
18 . One or more non-transitory computer-readable media maintaining instructions that, when executed by one or more processors of a network controller of a network, program the one or more processors to perform operations comprising:
monitoring network data associated with a plurality of network devices within the network;
receiving software data indicative of software deployed within the network;
determining, based on the software data, a vulnerability insight indicative of a component that is potentially vulnerable within the network;
generating, based on the network data and the vulnerability insight context data indicative of insights into the network;
generating, using the context data and a machine learning model, a synthetic test to evaluate the component that is potentially vulnerable within the network;
determining, based on executing the synthetic test, an impact of the component that is potentially vulnerable within the network;
generating, based on the impact, a network controller policy associated with mitigating the impact; and
enforcing the network controller policy.
19 . The one or more non-transitory computer-readable media of claim 18 , wherein the operations further comprise:
extracting vulnerability exploitability exchange (VEX) data from the software data;
wherein determining the vulnerability insight is based on the VEX data.
20 . The one or more non-transitory computer-readable media of claim 18 , wherein generating the context data comprises using a retrieval augmented generation (RAG) component of the network controller.