Invention Grant
- Patent Title: Determining violation of a network invariant
-
Application No.: US15775378Application Date: 2015-11-20
-
Publication No.: US10541873B2Publication Date: 2020-01-21
- Inventor: Ying Zhang , Jeongkeun Lee , Puneet Sharma , Joon-Myung Kang
- Applicant: Hewlett Packard Enterprise Development LP
- Applicant Address: US TX Houston
- Assignee: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
- Current Assignee: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
- Current Assignee Address: US TX Houston
- Agency: Hewlett Packard Enterprise Patent Department
- International Application: PCT/US2015/061890 WO 20151120
- International Announcement: WO2017/086990 WO 20170526
- Main IPC: H04L12/24
- IPC: H04L12/24 ; H04L12/813 ; H04L12/851 ; H04L12/715 ; H04L12/721

Abstract:
Example implementations relate to determining whether network invariants are violated by flow rules to be implemented by the data plane of a network. In an example, a verification module implemented on a device receives a flow rule transmitted from an SDN controller to a switch, the flow rule relating to an event. The module determines whether the flow rule matches any of a plurality of network invariants cached in the device. If determined that the flow rule matches one of the plurality of network invariants, the verification module determines whether the flow rule violates the matched network invariant. If determined that the flow rule does not match any of the plurality of network invariants, the verification module (1) reports the event associated with the flow rule to a policy management module, (2) receives a new network invariant related to the event from the policy management module, and (3) determines whether the flow rule violates the new network invariant. The verification module generates an alarm if determined that the flow rule violates any of the network invariants.
Public/Granted literature
- US20180331909A1 DETERMINING VIOLATION OF A NETWORK INVARIANT Public/Granted day:2018-11-15
Information query