Intent-based enterprise security using dynamic learning of network segment prefixes

    公开(公告)号:US12095817B2

    公开(公告)日:2024-09-17

    申请号:US17301278

    申请日:2021-03-30

    CPC classification number: H04L63/20 G06F16/245 H04L63/0227

    Abstract: In an example, systems and methods enable automatic implementation of intent-based security policies in a network system, such as a software-defined wide area network system, in which network segment prefixes for network segments at one or more sites are dynamically learned. A service orchestrator controller translates an intent-based security policy input by a user to a security policy for a first site. The security policy for the first site specifies a segment-specific queryable resource associated with a second site. To implement the security policy, a device associated with the first site queries the segment-specific queryable resource associated with the second site, and updates one or more forwarding tables of the device with the network segment prefixes associated with one or more network segments at the second site received in response to the query. The first site forwards network traffic to the second site based on the updated forwarding tables.

    Intent-based enterprise security using dynamic learning of network segment prefixes

    公开(公告)号:US11916963B2

    公开(公告)日:2024-02-27

    申请号:US17301278

    申请日:2021-03-30

    CPC classification number: H04L63/20 G06F16/245 H04L63/0227

    Abstract: In an example, systems and methods enable automatic implementation of intent-based security policies in a network system, such as a software-defined wide area network system, in which network segment prefixes for network segments at one or more sites are dynamically learned. A service orchestrator controller translates an intent-based security policy input by a user to a security policy for a first site. The security policy for the first site specifies a segment-specific queryable resource associated with a second site. To implement the security policy, a device associated with the first site queries the segment-specific queryable resource associated with the second site, and updates one or more forwarding tables of the device with the network segment prefixes associated with one or more network segments at the second site received in response to the query. The first site forwards network traffic to the second site based on the updated forwarding tables.

    Determining reorder commands for remote reordering of policy rules

    公开(公告)号:US11881997B1

    公开(公告)日:2024-01-23

    申请号:US17305625

    申请日:2021-07-12

    Inventor: Fnu Nadeem

    CPC classification number: H04L41/0893 H04L41/0816 H04L41/0886

    Abstract: In general, techniques are described for determining reorder commands for remote reordering of policy rules. A device management system comprising a memory, a processor, and an interface may be configured to perform the techniques. A memory may store a currently configured policy for a managed network device and an updated policy for the managed device. The processor may determine a longest increasing subsequence (LIS) between a source list comprising the plurality of policy rules in a first ordering and a destination list of the plurality of policy rules in a second ordering. The processor may generate, based on the LIS, one or more policy configuration commands for the managed network device that direct the managed network device to conform the currently configured policy to the updated policy. The interface may output the one or more policy configuration commands to the managed network device.

    IDENTIFYING OUT-OF-BAND CONFIGURATION CHANGES TO VALIDATE INTENT FILES

    公开(公告)号:US20230006881A1

    公开(公告)日:2023-01-05

    申请号:US17449601

    申请日:2021-09-30

    Abstract: A controller device manages a plurality of network devices. The controller device includes a memory comprising a configuration database including a set of stored network device configurations, wherein each stored network device configuration of the set of stored network device configurations corresponds to a network device of the set of network devices. Additionally, the controller device includes processing circuitry configured to receive an intent file corresponding to an intended configuration for the set of network devices; receive a message from a network device of the set of network devices indicating an out-of-band configuration change at the network device; and determine, based on a stored network device configuration corresponding to the network device and an actual configuration of the network device, whether the intent file is compatible with the out-of-band configuration change.

    Identifying out-of-band configuration changes to validate intent files

    公开(公告)号:US11777800B2

    公开(公告)日:2023-10-03

    申请号:US17449601

    申请日:2021-09-30

    CPC classification number: H04L41/0816 H04L41/22

    Abstract: A controller device manages a plurality of network devices. The controller device includes a memory comprising a configuration database including a set of stored network device configurations, wherein each stored network device configuration of the set of stored network device configurations corresponds to a network device of the set of network devices. Additionally, the controller device includes processing circuitry configured to receive an intent file corresponding to an intended configuration for the set of network devices; receive a message from a network device of the set of network devices indicating an out-of-band configuration change at the network device; and determine, based on a stored network device configuration corresponding to the network device and an actual configuration of the network device, whether the intent file is compatible with the out-of-band configuration change.

Patent Agency Ranking