Application-Based Network Segmentation in Virtualized Hosts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualized computing environments, conventional network segmentation at the virtual machine level is inefficient as it requires deploying multiple virtual machines to satisfy different network security requirements for applications, leading to resource wastage and inability to allow users to access different networks with different applications.
Innovation Solution
Implementing application-based network segmentation, where different target networks are defined for different applications supported by the same virtual machine, using fine-grained network controls to direct packets through specific virtual network interfaces based on configured network policies, allowing each application to access its designated network without necessitating additional virtual machines.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional network segmentation at the virtual machine level is used, then network security can be maintained, but resource efficiency deteriorates due to requiring multiple virtual machines
Solution Approach 1:
The patent applies segmentation by dividing network access at the application level rather than the virtual machine level. Each application on a virtual machine is assigned to specific target networks through network policies, enabling fine-grained network segmentation that improves security without requiring multiple virtual machines, thus resolving the contradiction between security and resource efficiency
Solution Approach 2:
The patent implements local quality by assigning different network access rights to different applications on the same virtual machine. Each application receives customized network policies tailored to its specific security requirements, allowing granular control over network access without duplicating the entire virtual machine, thereby improving both security and resource utilization
2Reliability
If multiple virtual machines are deployed to satisfy different network security requirements, then network security is improved, but device complexity increases
Solution Approach 1:
The patent applies universality by enabling a single virtual machine to serve multiple network security roles through application-level segmentation. Different applications on the same virtual machine can access different target networks according to their security requirements, eliminating the need to deploy separate virtual machines for each network segment and reducing overall system complexity
Solution Approach 2:
The patent transitions from vertical segmentation (multiple virtual machines) to horizontal segmentation (multiple applications on the same virtual machine accessing different networks). This dimensional shift allows network security to be achieved through application-level policies rather than through deploying additional virtual machine layers, thereby reducing complexity
3Productivity
If application-based network segmentation is implemented, then resource efficiency is improved, but network policy management complexity increases
Solution Approach 1:
The patent implements feedback mechanisms where the system automatically detects application identifiers and socket operations, and dynamically applies appropriate network policies. This automated feedback loop reduces manual policy configuration complexity while maintaining fine-grained control over network access for each application, thereby improving resource efficiency without proportionally increasing management complexity
Data Source
AI summary
Example methods are provided for host to implement application-based network segmentation in a virtualized computing environment. The method may comprise detecting an egress packet from a virtualized computing instance supported by the host for transmission to a destination and identifying a source application associated with the egress packet. The source application may be one of multiple applications supported by the virtualized computing instance, the multiple applications being associated with respective target networks. The method may further comprise, based on a network policy configured for the source application, determining a particular target network associated with the source application; and sending, to the destination, the egress packet via a physical network interface controller (NIC) associated with the particular target network.


