-
11.
公开(公告)号:US10374884B2
公开(公告)日:2019-08-06
申请号:US15217573
申请日:2016-07-22
Applicant: Cisco Technology, Inc.
Inventor: Wojciech Dec , Sanjay Agrawal , Yi Yang , Ruchir Gupta , Syed Basheeruddin Ahmed
IPC: H04L12/24
Abstract: Disclosed are systems, methods, and computer-readable storage media for automatically, dynamically generating feature model augmentation statements for data nodes for a new network feature described in a data modeling language. A software-defined controller, or other network components, can detect the availability of a new network feature defined by a feature model in a data modeling language and process the feature model to create an authorization policy data defining access rules control rules for the new network feature. Based on the authorization policy, the controller or the authorization model generator can generate a set of augmentation statements for one or more data nodes in the feature model of the new network feature and augment the new feature model with the augmentation statements for controlling access to the new network feature.
-
公开(公告)号:US11412053B2
公开(公告)日:2022-08-09
申请号:US16505618
申请日:2019-07-08
Applicant: Cisco Technology, Inc.
Inventor: Yi Yang , Wojciech Dec , Syed Basheeruddin Ahmed , Sanjay Agrawal , Ruchir Gupta
Abstract: Systems and methods provide for scaling service discovery in a micro-service environment. A controller can inject a service discovery agent onto a host. At least one of the controller or the agent can identify a first set of micro-service containers that are dependencies of the first micro-service container and a second set of micro-service containers that are dependencies of the second micro-service container. At least one of the controller or the agent can update routing data for the first set of micro-service containers and the second set of micro-service containers. At least one of the controller or the agent can determine the second micro-service container has terminated on the host computing device. At least one of the controller or the agent can update the agent to remove the routing data for the second set of micro-service containers.
-
公开(公告)号:US20190335004A1
公开(公告)日:2019-10-31
申请号:US16505618
申请日:2019-07-08
Applicant: Cisco Technology, Inc.
Inventor: Yi Yang , Wojciech Dec , Syed Basheeruddin Ahmed , Sanjay Agrawal , Ruchir Gupta
Abstract: Systems and methods provide for scaling service discovery in a micro-service environment. A controller can inject a service discovery agent onto a host. At least one of the controller or the agent can identify a first set of micro-service containers that are dependencies of the first micro-service container and a second set of micro-service containers that are dependencies of the second micro-service container. At least one of the controller or the agent can update routing data for the first set of micro-service containers and the second set of micro-service containers. At least one of the controller or the agent can determine the second micro-service container has terminated on the host computing device. At least one of the controller or the agent can update the agent to remove the routing data for the second set of micro-service containers.
-
公开(公告)号:US20180109429A1
公开(公告)日:2018-04-19
申请号:US15298102
申请日:2016-10-19
Applicant: Cisco Technology, Inc.
Inventor: Ruchir Gupta , Sanjay Agrawal , Yi Yang , Wojciech Dec , Syed Basheeruddin Ahmed
IPC: H04L12/24 , G06T11/20 , G06T11/00 , G06F3/0481
CPC classification number: H04L41/22 , G06F3/0481 , G06T11/206 , H04L41/0893 , H04L43/08
Abstract: A controller in a network can gather operational data describing performance of an end point group in the network. The end point group can include one or more containers providing microservices. The controller can calculate an overall health score for the end point group based on the operational data. The overall health score can indicate whether an actual overall performance of the end point group is meeting a desired overall performance of the end point group defined by a first set of policies assigned to the end point group. The controller can present, in a graphical user interface, a visual representation of the overall health score. The visual representation of the overall health score can indicate that the overall health score is within a first overall health range from a set of two or more overall health ranges.
-
公开(公告)号:US20180026856A1
公开(公告)日:2018-01-25
申请号:US15216588
申请日:2016-07-21
Applicant: Cisco Technology, Inc.
Inventor: Yi Yang , Wojciech Dec , Ruchir Gupta , Syed Basheeruddin Ahmed , Sanjay Agrawal
CPC classification number: H04L41/5019 , H04L41/0893 , H04L41/5009 , H04L41/5096 , H04L43/08 , H04L67/10
Abstract: A controller in a network can gather operational data describing performance of an end point group in the network, wherein the end point group includes one or more containers providing micro services. The controller can calculate a health score for the end point group based on the operational data. The health score can indicate whether an actual performance of the end point group is meeting a desired performance of the end point group defined by a first set of policies assigned to the end point group. The controller can determine, based on the health score, that the actual performance of the end point group is not meeting the desired performance of the end point group, and modify the end point group to achieve the desired performance of the end point group.
-
公开(公告)号:US20170317901A1
公开(公告)日:2017-11-02
申请号:US15142308
申请日:2016-04-29
Applicant: Cisco Technology, Inc.
Inventor: Sanjay Agrawal , Ruchir Gupta , Syed Basheeruddin Ahmed , Yi Yang , Wojciech Dec
CPC classification number: H04L43/08 , H04L41/0893 , H04L41/5009 , H04L43/16
Abstract: Disclosed are systems, methods, and computer-readable medium for adjusting group based policies. A controller in a network can gather operational data describing performance of an end point group (EPG) in the network. The EPG can be operating according to a first set of policies to achieve a desired performance for the end point group. The controller can calculate a health score for the end point group based on the operational data. The health score can indicate whether an actual performance of the end point group is meeting the desired performance of the end point group. The controller can determine, based on the health score, that the actual performance of the end point group is not meeting the desired performance of the end point group, and apply a second set of policies to the end point group to achieve the desired performance of the end point group.
-
公开(公告)号:US20170206701A1
公开(公告)日:2017-07-20
申请号:US14997342
申请日:2016-01-15
Applicant: Cisco Technology, Inc.
Inventor: Sanjay Agrawal , Ruchir Gupta , Syed Basheeruddin Ahmed , Yi Yang , Meenakshi Kaushik
CPC classification number: H04L41/22 , G06T11/206 , G06T2200/04 , G06T2200/24 , H04L41/065 , H04L41/0893 , H04L43/045
Abstract: Systems, methods, and non-transitory computer-readable storage media for visualizing current and historical access policy of a group based policy. A first group based policy and a second group based policy are received at a computing device, where each group based policy includes policy rules defining a range of destination internet protocol addresses, a range of source internet protocol addresses and a range of access ports. The computing device renders a three dimensional representation of the first group based policy, based on the policy rules of the first group based policy. The computing device renders a three dimensional representation of the second group based policy, based on the policy rules of the second group based policy. The computing device displays the representations of the first group based policy and second group based policy on a graphical interface.
-
-
-
-
-
-