ASSESSING NETWORK AND DEVICE COMPLIANCE WITH SECURITY POLICIES
    1.
    发明申请
    ASSESSING NETWORK AND DEVICE COMPLIANCE WITH SECURITY POLICIES 有权
    评估网络和设备遵守安全政策

    公开(公告)号:US20080022357A1

    公开(公告)日:2008-01-24

    申请号:US11776721

    申请日:2007-07-12

    IPC分类号: H04L9/00

    CPC分类号: H04L63/20

    摘要: All of the transit services that each device is expected to provide are determined and contrasted with the transit configuration of each device. Because the transit configuration of each device may be state-dependent, the service items within each application service are processed in sequential order. Sequences of service items are associated with connection groups, and each of the routes associated with each connection group is determined based on the sequential order of the service items. The configuration of each device along each route is processed to determine the services that will be permitted or denied, based on its current configuration. Each desired transit service item is compared to the transit configuration provided by each device to identify any inconsistencies and/or violations

    摘要翻译: 每个设备预期提供的所有过境服务都被确定,并与每个设备的传输配置进行对比。 由于每个设备的传输配置可能与状态有关,因此每个应用服务中的服务项目按顺序进行处理。 服务项目的顺序与连接组相关联,并且基于服务项目的顺序来确定与每个连接组相关联的每个路线。 根据其当前配置,处理每个路由上每个设备的配置,以确定将被允许或拒绝的服务。 将每个期望的中转服务项目与由每个设备提供的传输配置进行比较,以识别任何不一致和/或违规

    Network path discovery and analysis
    4.
    发明授权
    Network path discovery and analysis 有权
    网络路径发现与分析

    公开(公告)号:US08811193B2

    公开(公告)日:2014-08-19

    申请号:US12900348

    申请日:2010-10-07

    IPC分类号: H04L12/26

    CPC分类号: H04L41/12 H04L41/0213

    摘要: A network analysis system invokes an application specific, or source-destination specific, path discovery process. The application specific path discovery process determines the path(s) used by the application, collects performance data from the nodes along the path, and communicates this performance data to the network analysis system for subsequent performance analysis. The system may also maintain a database of prior network configurations to facilitate the identification of nodes that are off the path that may affect the current performance of the application. The system may also be specifically controlled so as to identify the path between any pair of specified nodes, and to optionally collect performance data associated with the path.

    摘要翻译: 网络分析系统调用特定于应用程序或源特定路径的路径发现过程。 应用程序特定路径发现过程确定应用程序使用的路径,从沿着路径的节点收集性能数据,并将该性能数据传达到网络分析系统以进行后续性能分析。 系统还可以维护先前网络配置的数据库,以便于识别可能影响应用的当前性能的路径之外的节点。 还可以特别地控制系统,以便识别任何一对指定节点之间的路径,并且可选地收集与该路径相关联的性能数据。

    Minimizing single points of failure in paths with mixed protection schemes
    6.
    发明授权
    Minimizing single points of failure in paths with mixed protection schemes 有权
    最小化混合保护方案路径中的单点故障

    公开(公告)号:US07616584B2

    公开(公告)日:2009-11-10

    申请号:US10986675

    申请日:2004-11-12

    IPC分类号: H04L12/26

    摘要: Methods and apparatus for substantially minimizing single points of failure for circuit paths in networks with mixed protection schemes are disclosed. According to one aspect of the present invention, a method for routing circuit paths between a source and a destination of a network includes identifying a first available circuit path between the source and the destination. The first available circuit path includes a first plurality of links which each have an associated protection type. The method also includes determining a number protection changes associated with the first plurality of links, and assigning a first metric to the first available path that is based on the number of protection changes. Finally, the method includes identifying a selected available path to be used to pass information between the source and the destination based at least in part on the first metric.

    摘要翻译: 公开了用于基本上最小化具有混合保护方案的网络中的电路路径的单点故障的方法和装置。 根据本发明的一个方面,一种用于在网络的源和目的地之间路由电路路径的方法包括识别源与目的地之间的第一可用电路路径。 第一可用电路路径包括第一多个链路,每个链路各具有相关联的保护类型。 该方法还包括确定与第一多个链路相关联的数字保护改变,以及基于保护改变的数量为第一可用路径分配第一度量。 最后,该方法包括至少部分地基于第一度量来识别用于在源和目的地之间传递信息的所选择的可用路径。

    Network Simulation and Analysis using Operational Forwarding Data
    7.
    发明申请
    Network Simulation and Analysis using Operational Forwarding Data 有权
    使用操作转发数据进行网络仿真和分析

    公开(公告)号:US20080043627A1

    公开(公告)日:2008-02-21

    申请号:US11838417

    申请日:2007-08-14

    IPC分类号: G06F11/00

    摘要: A hybrid approach to populating forwarding tables in a virtual network obtains forwarding data both by simulating routing protocol behavior in the virtual network to build forwarding tables, and by importing operational forwarding data from corresponding physical nodes in a physical network. The use of operational forwarding data improves the fidelity of the simulation by closely conforming forwarding behavior in the simulation to that which occurs in the physical network.

    摘要翻译: 在虚拟网络中填充转发表的混合方法通过模拟虚拟网络中的路由协议行为来构建转发表,以及通过从物理网络中的相应物理节点导入操作转发数据来获得转发数据。 使用运行转发数据通过将仿真中的转发行为与物理网络中发生的转发行为紧密相符,提高了仿真的保真度。

    Mapping Off-Network Traffic to an Administered Network
    8.
    发明申请
    Mapping Off-Network Traffic to an Administered Network 有权
    将网络外流量映射到管理网络

    公开(公告)号:US20080037423A1

    公开(公告)日:2008-02-14

    申请号:US11835130

    申请日:2007-08-07

    IPC分类号: G06F11/00

    摘要: Traffic flows through an administered network from an off-network source and/or to an off-network destination are simulated and analyzed by selecting an ingress and/or egress node within the administered network, the ingress node capable of collecting traffic from an off-network source, and the egress node capable of routing traffic to an off-network destination. Traffic flow is mapped from the source or ingress node through the administered network to the egress node. The traffic flow may be simulated and analyzed. The ingress and/or egress nodes may be selected in a variety of ways.

    摘要翻译: 通过选择管理的网络内的入口和/或出口节点来模拟和分析从网络外的源和/或离网目的地流经管理的网络的流量,所述入口节点能够从离线网络中收集流量, 网络源和能够将流量路由到离网目的地的出口节点。 业务流从源或入节点通过被管理网络映射到出口节点。 可以模拟和分析交通流量。 可以以各种方式来选择入口节点和/或出口节点。

    Tracing routing differences
    9.
    发明申请
    Tracing routing differences 有权
    跟踪路由差异

    公开(公告)号:US20070025328A1

    公开(公告)日:2007-02-01

    申请号:US11494692

    申请日:2006-07-27

    IPC分类号: H04L12/28 H04L12/56

    CPC分类号: H04L45/28 H04L45/02 H04L45/54

    摘要: A routing validation method and system identifies routers that are likely to be the cause of differences in forwarding tables associated with two versions of a network. Each destination sub-network prefix is processed to identify all the routers that exhibit differences in their forwarding table for this prefix. Each router exhibiting a difference is assessed to determine whether the difference may have been propagated to this router from another router. If the difference could not have been propagated from another router, this router is identified as a potential source of the observed difference. By eliminating routers that could have received the effects of the differences from another router, the task of identifying the root cause of the observed differences is substantially reduced in complexity.

    摘要翻译: 路由验证方法和系统识别可能是与两个网络版本相关联的转发表中的差异的原因的路由器。 处理每个目标子网络前缀以标识在其前缀的转发表中表现出差异的所有路由器。 评估每个出现差异的路由器,以确定差异是否可能已经从另一个路由器传播到该路由器。 如果差异不能从另一个路由器传播,则该路由器被识别为观察到的差异的潜在来源。 通过消除可能已经接收到来自另一个路由器的差异的影响的路由器,识别所观察到的差异的根本原因的任务在复杂性上显着降低。