Scalable event driven auto-diagnosis system

    公开(公告)号:US12261736B2

    公开(公告)日:2025-03-25

    申请号:US17817330

    申请日:2022-08-03

    Applicant: Google LLC

    Abstract: A method for scalable event driven auto-diagnosis systems includes obtaining a data packet configured for transmission across a network from a source address to a destination address. The method includes obtaining a list of changes to the network. The method also includes analyzing, based on a network model, the data packet using a plurality of analyzers. The method includes correlating the list of changes to the network and the analysis of the data packet. The method further includes determining, based on the correlation between the list of changes to the network and the analysis of the data packet, a configuration status of the network. The method also includes reporting the configuration status to a user.

    Change Impact Simulation Analysis
    12.
    发明公开

    公开(公告)号:US20230396508A1

    公开(公告)日:2023-12-07

    申请号:US18452512

    申请日:2023-08-18

    Applicant: Google LLC

    CPC classification number: H04L41/145 H04L41/28 H04L63/0272

    Abstract: A system for simulating network configurations includes data processing hardware and memory hardware in communication with the data processing hardware. The memory hardware stores instructions that when executed on the data processing hardware cause the data processing hardware to perform operations. The operation includes receiving one or more parameter changes for a production network model of a network. The operations also include generating a simulation network model including the one or more parameter changes. Another operation includes analyzing the simulated network flow within the simulation network model. The operations also include generating a report including an impact of the parameter changes on the network. The operations may also include receiving a production network log including a recorded workflow for the production network model and simulating the production workflow of the production network log within the simulation network model to generate a simulated network log.

    FIREWALL RULES INTELLIGENCE
    14.
    发明申请

    公开(公告)号:US20230114050A1

    公开(公告)日:2023-04-13

    申请号:US18051686

    申请日:2022-11-01

    Applicant: Google LLC

    Abstract: A firewall intelligence system, includes a data storage storing a set of firewall rules for a network; a recommendation engine that receives, from a log service, traffic logs detailing traffic for the network and firewall logs detailing the usage of firewall rules in response to the traffic for the network, accesses, from the data storage, the set of firewall rules for the network; processes the set of firewall rules to evaluate the firewall rules against a set of quantitative evaluation rules to determine one or more firewall rule recommendations, wherein each firewall rule recommendation is a recommendation to change at least one of the firewall rules in the set of firewall rules; and a front end API that provides data describing the one or more firewall rule recommendations to a user device.

    Cloud network reachability analysis for virtual private clouds

    公开(公告)号:US11477110B2

    公开(公告)日:2022-10-18

    申请号:US16840084

    申请日:2020-04-03

    Applicant: Google LLC

    Abstract: A method for providing cloud network reachability analysis includes receiving a reachability query requesting a reachability status of a target including a packet header associated with a data packet. The packet header includes a source IP address and a destination IP address. The method also includes generating one or more simulated forwarding paths for the data packet based on the packet header using a data plane model. Each simulated forwarding path includes corresponding network configuration information. The method includes determining the reachability status of the target based on the one or more simulated forwarding paths and providing the determined reachability status and the one or more simulated forwarding paths to a user device associated with the reachability query which causes the user device to present the network configuration information for each simulated forwarding path.

    Change impact simulation analysis
    16.
    发明授权

    公开(公告)号:US11424991B2

    公开(公告)日:2022-08-23

    申请号:US17110259

    申请日:2020-12-02

    Applicant: Google LLC

    Abstract: A system for simulating network configurations includes data processing hardware and memory hardware in communication with the data processing hardware. The memory hardware stores instructions that when executed on the data processing hardware cause the data processing hardware to perform operations. The operations includes receiving one or more parameter changes for a production network model of a network. The operations also include generating a simulation network model including the one or more parameter changes. Another operation includes analyzing the simulated network flow within the simulation network model. The operations also include generating a report including an impact of the parameter changes on the network. The operations may also include receiving a production network log including a recorded workflow for the production network model and simulating the production workflow of the production network log within the simulation network model to generate a simulated network log.

    Network Reachability Impact Analysis

    公开(公告)号:US20220191102A1

    公开(公告)日:2022-06-16

    申请号:US17117376

    申请日:2020-12-10

    Applicant: Google LLC

    Abstract: A method of network reachability impact analysis includes receiving a plurality of network configuration snapshots for a network. The method also include selecting a first network configuration snapshot of the network and a second network configuration snapshot of the network. The method further includes generating a first reachability graph representing packet reachability of the network for the first network configuration snapshot. The method also includes generating a second reachability graph representing packet reachability of the network for the second network configuration snapshot. The method also includes computing a reachability differentiation graph identifying a net change to reachability from the first reachability graph to the second reachability graph. The method further includes generating a reachability differentiation report including a human-interpretable output of the net change to reachability.

    Change Impact Simulation Analysis
    18.
    发明申请

    公开(公告)号:US20220150128A1

    公开(公告)日:2022-05-12

    申请号:US17110259

    申请日:2020-12-02

    Applicant: Google LLC

    Abstract: A system for simulating network configurations includes data processing hardware and memory hardware in communication with the data processing hardware. The memory hardware stores instructions that when executed on the data processing hardware cause the data processing hardware to perform operations. The operations includes receiving one or more parameter changes for a production network model of a network. The operations also include generating a simulation network model including the one or more parameter changes. Another operation includes analyzing the simulated network flow within the simulation network model. The operations also include generating a report including an impact of the parameter changes on the network. The operations may also include receiving a production network log including a recorded workflow for the production network model and simulating the production workflow of the production network log within the simulation network model to generate a simulated network log.

    Change impact simulation analysis
    19.
    发明授权

    公开(公告)号:US12170596B2

    公开(公告)日:2024-12-17

    申请号:US18452512

    申请日:2023-08-18

    Applicant: Google LLC

    Abstract: A system for simulating network configurations includes data processing hardware and memory hardware in communication with the data processing hardware. The memory hardware stores instructions that when executed on the data processing hardware cause the data processing hardware to perform operations. The operation includes receiving one or more parameter changes for a production network model of a network. The operations also include generating a simulation network model including the one or more parameter changes. Another operation includes analyzing the simulated network flow within the simulation network model. The operations also include generating a report including an impact of the parameter changes on the network. The operations may also include receiving a production network log including a recorded workflow for the production network model and simulating the production workflow of the production network log within the simulation network model to generate a simulated network log.

    Network reachability impact analysis

    公开(公告)号:US12009985B2

    公开(公告)日:2024-06-11

    申请号:US17804389

    申请日:2022-05-27

    Applicant: Google LLC

    Abstract: A method includes obtaining a stream of consecutive network configuration snapshots each including network configuration information. The method also includes determining that first network configuration information is the same as second network configuration information. After determining that the first network configuration information is the same as the second network configuration information, the method includes determining that the second network configuration information is not the same as third network configuration information. The method also includes determining a net change in reachability for a network based on a difference in packet reachability. The method also includes determining a policy violation based on the net change in reachability for the network and generating a reachability differentiation report including the policy violation. The method also includes reverting a configuration of the network to a state corresponding to the first network configuration information and implementing the network using the reverted configuration.

Patent Agency Ranking