Context Engine for Host-Based Attribute Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing middlebox services do not effectively utilize rich-contextual data from data message flows due to inefficient distributed schemes for filtering contextual attributes, which limits their ability to process service rules defined by smaller sets of attributes.
Innovation Solution
A novel architecture that executes a guest-introspection agent and a context engine on each host to capture and process contextual attributes from network and process events, using these attributes to identify and enforce context-based service rules through attribute-based service engines.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional hardware appliances are used for middlebox services, then service processing is reliable, but flexibility and control are limited
Solution Approach 1:
The patent replaces traditional hardware appliances with a software-based architecture running on general-purpose hosts. The context engine and service engines are implemented as software components that can be deployed on standard server hardware, eliminating the need for specialized hardware appliances while maintaining service functionality through virtualized and software-defined networking approaches
Solution Approach 2:
The patent creates a universal platform where a single host can run multiple service engines (firewall, load balancer, intrusion detection, etc.) simultaneously. The context engine provides a common foundation that multiple service engines can utilize, allowing one hardware platform to perform functions that traditionally required multiple specialized hardware appliances
2Measurement precision
If all captured contextual attributes are processed, then service rule accuracy is improved, but processing efficiency deteriorates due to the large volume of attributes
Solution Approach 1:
The patent extracts only the necessary contextual attributes needed for service rule matching from the complete set of captured attributes. The context engine filters and selects relevant attributes based on service requirements, extracting only the essential information needed for accurate service rule evaluation while discarding unnecessary data
Solution Approach 2:
The patent segments the attribute processing into multiple stages: capture phase (collecting all attributes), filtering phase (selecting relevant attributes), and matching phase (evaluating service rules). This segmentation allows the system to handle large volumes of attributes efficiently by processing them in discrete, manageable steps rather than all at once
3Productivity
If a distributed scheme is implemented for filtering contextual attributes, then processing scalability is improved, but system complexity increases
Solution Approach 1:
The patent merges the attribute filtering and service rule evaluation functions into a single integrated context engine. This consolidation combines multiple processing tasks into one unified component, reducing the number of separate systems that need to communicate and coordinate, thereby simplifying the overall distributed architecture while maintaining scalability
Data Source
AI summary
Some embodiments of the invention provide a novel architecture for capturing contextual attributes on host computers that execute one or more machines, and for consuming the captured contextual attributes to perform services on the host computers. The machines are virtual machines (VMs) in some embodiments, containers in other embodiments, or a mix of VMs and containers in still other embodiments. Some embodiments execute a guest-introspection (GI) agent on each machine from which contextual attributes need to be captured. In addition to executing one or more machines, each host computer in these embodiments executes a context engine and one or more attribute-based service engines. Through the GI agents of a host's machines, the context engine of that host in some embodiments collects contextual attributes associated with network and/or process events on the machines, and provides the contextual attributes to the service engines to use to identify service rules for processing.


