PATH VALIDATION AND PERFORMANCE ASSURANCE FOR DISTRIBUTED NETWORK ENDPOINTS

    公开(公告)号:US20210067592A1

    公开(公告)日:2021-03-04

    申请号:US16559526

    申请日:2019-09-03

    IPC分类号: H04L29/08 H04L12/26

    摘要: Techniques for network validation are provided. A first request is received at a first manager component, from a first client. The first client and the first manager component are on a first node of a plurality of nodes, and the first request specifies a desired network service. A first network service endpoint that is capable of providing the desired network service is identified, where the first network service endpoint is on a second node of the plurality of nodes. A connection is established between a first validation agent on the first node and a second validation agent on the second node. Finally, upon determining that the connection between the first and second validation agents satisfies predefined criteria, a connection is established between the first client and the first network service endpoint.

    NETWORK API PATH TRACING
    27.
    发明公开

    公开(公告)号:US20230379365A1

    公开(公告)日:2023-11-23

    申请号:US17749609

    申请日:2022-05-20

    IPC分类号: H04L9/40 G06F9/54

    CPC分类号: H04L63/20 G06F9/547

    摘要: In one embodiment, a device receives traffic flow information regarding an application programming interface call made to a particular endpoint via a path in a network. The device requests, based on the traffic flow information, that a plurality of distributed agents in the network perform a trace of the path taken by the application programming interface call. The device receives results from the trace of the path performed by the plurality of distributed agents. The device causes a security policy to be enforced with respect to application programming interface calls made to the particular endpoint, based on the results from the trace.

    SECURE ACCESS SERVICE EDGE FUNCTION WITH CONFIGURED METRIC COLLECTION INTELLIGENCE

    公开(公告)号:US20230379319A1

    公开(公告)日:2023-11-23

    申请号:US17749274

    申请日:2022-05-20

    IPC分类号: H04L9/40

    CPC分类号: H04L63/083 H04L63/20

    摘要: In one embodiment, a method herein comprises: receiving, at a device, a registration request from a telemetry exporter that transmits telemetry data; generating, by the device, a telemetry configuration file for the telemetry exporter, the telemetry configuration file defining a policy for transmission of telemetry data from the telemetry exporter and an authentication token for the telemetry exporter; sharing, by the device, the policy with a security enforcer; and sending, by the device, the telemetry configuration file to the telemetry exporter, wherein the telemetry exporter is caused to connect with the security enforcer using the authentication token, send the telemetry configuration file to the security enforcer, and transmit collected telemetry data to the security enforcer, and wherein the security enforcer is caused to create a dynamic publish-subscribe stream for publishing the collected telemetry data received from the telemetry exporter based on the telemetry configuration file and the policy.

    PROTECTING CONFIDENTIAL INFORMATION IN ONLINE APPLICATIONS

    公开(公告)号:US20230376632A1

    公开(公告)日:2023-11-23

    申请号:US17746517

    申请日:2022-05-17

    IPC分类号: G06F21/62

    CPC分类号: G06F21/6254

    摘要: In one embodiment, a device obtains transaction data regarding a transaction attempted by a client of an online application to access confidential information within the online application. The transaction data is captured by instrumentation code inserted into the online application at runtime. The device permits, based on a policy, the transaction to complete within the online application. The device determines, based on the policy, a set of one or more client-side functions to disable during the transaction. The device instructs an agent executed by the client to disable the set of one or more client-side functions during the transaction.

    DIFFERENTIATED SERVICE IN A FEDERATION-BASED ACCESS NETWORK

    公开(公告)号:US20230007050A1

    公开(公告)日:2023-01-05

    申请号:US17305235

    申请日:2021-07-01

    IPC分类号: H04L29/06 H04W12/06

    摘要: Differentiated service in a federation-based access network is provided by receiving, with a request for access to a wireless network offering at least a two different service levels based on user identities, a set of user credentials from a User Equipment (UE); forwarding, for authentication, the set of user credentials to an identity provider in an identity federation with the wireless network, wherein the identity provider is independent from the wireless network; in response to determining that the set of user credentials indicate a realm known to be associated with a given service level, providing network access to the UE according to the given service level; and in response to determining that the given service level is not a highest service level in the wireless network, transmitting a list of preferred realms to the UE that are associated with higher service levels than the given service level.