ARP-Based Context Transmission for Virtual Machine Firewall Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing firewall technologies struggle to efficiently incorporate identifiers of users and processes into firewall rules, especially in virtualized networks, due to difficulties in determining and mapping these identifiers.
Innovation Solution
The proposed solution utilizes ARP requests and responses as communication vehicles to transmit and disseminate context information about users and processes between hypervisors and a central controller, enabling enhanced firewall rules that utilize user and process identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TCP sessions are used to communicate context information between hypervisors and central controller, then reliable data transmission is achieved, but communication time and setup overhead increase
Solution Approach 1:
The patent applies preliminary action by using ARP requests and responses to pre-establish communication channels and transmit context information before TCP sessions are fully established. The ARP-based mechanism performs initial data exchange in advance, reducing the time needed for subsequent TCP connection setup and enabling faster firewall rule enforcement.
2Adaptability or versatility
If Geneve headers are used to communicate context information, then data structure is standardized, but communication efficiency decreases compared to ARP-based approach
Solution Approach 1:
The patent extracts the context information transmission function from the Geneve header mechanism and implements it through ARP requests and responses. By taking out the data transmission task from the less efficient Geneve-based system and placing it in the faster ARP protocol, the invention achieves improved communication efficiency while maintaining structured data organization through the ARP message format.
3Adaptability or versatility
If firewall rules incorporate user and process identifiers, then security granularity is improved, but difficulty in determining and mapping identifiers increases
Solution Approach 1:
The patent introduces ARP requests and responses as intermediary mechanisms between hypervisors and the central controller for exchanging context information about users and processes. This intermediary ARP-based communication system simplifies the difficulty of determining and mapping identifiers by providing a standardized, efficient protocol for retrieving the necessary identification data needed for granular security rules.
Data Source
AI summary
Solutions for ARP-based annotations for virtual machines. In some solutions, a hypervisor implemented in a first host might determine that a first process is executing on the first host. The hypervisor can determine first context information for the first process, generate an Address Resolution Protocol (ARP) request, and/or transmit a first packet comprising the ARP request and the context information to a central controller as an indication that the first process is executing on the first host.


