Context Engine for Host-Based Network Attribute Collection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional middlebox services in networks do not effectively utilize rich-contextual data from host machines due to the lack of an efficient distributed scheme for filtering contextual attributes, limiting their ability to process service rules defined by smaller sets of attributes.

Innovation Solution

A novel architecture that executes a guest-introspection agent, context engine, and attribute-based service engines on host computers to capture and consume contextual attributes from network and process events, using these attributes to identify and enforce context-based services through a push or pull model.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional hardware appliances are used for middlebox services, then service processing is performed, but the flexibility and control provided by SDN and network virtualization are not utilized

Engineering Contradiction:
Improveflexibility and controlVSAvoidhardware appliance structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional hardware appliances with software-based middlebox services running on virtualized hosts. The context engine and service engines are implemented as software components that can be deployed and managed through SDN controllers, enabling flexible service chaining and dynamic policy enforcement without physical hardware constraints

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables dynamic service rule updates and flexible service chaining through software-defined networking control. Service rules can be modified, added, or removed dynamically without hardware reconfiguration, and service chains can be reconfigured based on changing network conditions and security requirements

Inventive Principle:
Principle #15Dynamics

2Loss of information

If existing middlebox solutions on hosts are deployed, then some service processing is achieved, but the rich-contextual data from captured attributes is not efficiently utilized

Engineering Contradiction:
Improvecontextual data utilizationVSAvoidservice rule processing efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The context engine extracts and captures rich contextual attributes from network packets and host events, separating this contextual data collection from the service rule processing function. This extracted contextual information is then made available to multiple service engines for efficient utilization without redundant data collection

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges multiple service engines (firewall, intrusion detection, load balancing) into a unified architecture that shares a common context engine. This consolidation allows all service engines to access the same captured contextual attributes, eliminating redundant data collection and improving overall processing efficiency while fully utilizing the rich contextual data

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If distributed filtering scheme is implemented for contextual attributes, then service rule processing efficiency is improved, but system architecture complexity increases

Engineering Contradiction:
Improveservice rule processing efficiencyVSAvoiddistributed system architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments service processing into independent service engines that can be distributed across multiple hosts. Each service engine operates autonomously with its own service rules, allowing parallel processing of different service functions while maintaining modularity and reducing the complexity burden on any single component

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The context engine serves as an intermediary that centralizes contextual attribute capture and distribution. This mediator component receives raw network data, extracts contextual attributes, and distributes relevant attributes to multiple service engines, simplifying the distributed architecture by providing a single point of truth for contextual data

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11327784B2Collecting and processing contextual attributes on a host
Publication Date: 2022.05.10 VMWARE INC
  • US11327784B2 patent drawing
  • US11327784B2 patent drawing
  • US11327784B2 patent drawing

AI summary

Some embodiments of the invention provide a novel architecture for capturing contextual attributes on host computers that execute one or more machines, and for consuming the captured contextual attributes to perform services on the host computers. The machines are virtual machines (VMs) in some embodiments, containers in other embodiments, or a mix of VMs and containers in still other embodiments. Some embodiments execute a guest-introspection (GI) agent on each machine from which contextual attributes need to be captured. In addition to executing one or more machines on each host computer, these embodiments also execute a context engine and one or more attribute-based service engines on each host computer. Through the GI agents of the machines on a host, the context engine of that host in some embodiments collects contextual attributes associated with network events and/or process events on the machines. The context engine then provides the contextual attributes to the service engines, which, in turn, use these contextual attributes to identify service rules for processing.