首页> 外国专利> Determining violation of a network invariant

Determining violation of a network invariant

机译:确定是否违反网络不变式

摘要

Example implementations relate to determining whether network invariants are violated by flow rules to be implemented by the data plane of a network. In an example, a verification module implemented on a device receives a flow rule transmitted from an SDN controller to a switch, the flow rule relating to an event. The module determines whether the flow rule matches any of a plurality of network invariants cached in the device. If determined that the flow rule matches one of the plurality of network invariants, the verification module determines whether the flow rule violates the matched network invariant. If determined that the flow rule does not match any of the plurality of network invariants, the verification module (1) reports the event associated with the flow rule to a policy management module, (2) receives a new network invariant related to the event from the policy management module, and (3) determines whether the flow rule violates the new network invariant. The verification module generates an alarm if determined that the flow rule violates any of the network invariants.
机译:示例实现方式涉及确定是否要由网络的数据平面实施的流规则违反网络不变式。在示例中,在设备上实现的验证模块接收从SDN控制器传输到交换机的流规则,该流规则与事件有关。模块确定流规则是否与设备中缓存的多个网络不变量中的任何一个匹配。如果确定流规则匹配多个网络不变式之一,则验证模块确定流规则是否违反匹配的网络不变式。如果确定流规则与多个网络不变式中的任何一个都不匹配,则验证模块(1)将与流规则相关联的事件报告给策略管理模块,(2)从中接收与该事件相关的新网络不变式(3)确定流规则是否违反了新的网络不变式。如果确定流规则违反任何网络不变式,则验证模块将生成警报。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号