Correlation Key for Aggregating Flow and Context Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.

Innovation Solution

A method is introduced to collect and report attributes of data flows from host computers associated with a logical network, using a virtualization manager like VMware NSX manager, and process this data with a policy, analytics, and correlation engine appliance for analysis and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data is collected from multiple host computers in an SDDC, then the quantity and completeness of security data is improved, but the complexity of data aggregation and correlation increases

Engineering Contradiction:
Improvequantity of security dataVSAvoidcomplexity of data aggregation system
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent introduces a centralized analytics appliance as an intermediary component that receives, aggregates, and correlates flow data from multiple host computers. This intermediary consolidates the complexity of data integration into a single system, allowing individual hosts to simply export data without implementing complex correlation logic themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges data from multiple sources (flow data, context data, correlation data) into a unified analysis platform. The analytics appliance combines these different data types and correlates them across multiple hosts, transforming fragmented data into integrated security insights.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If contextual attributes are collected for each data message flow, then the precision of security analysis is improved, but the amount of data to be processed and stored increases

Engineering Contradiction:
Improveprecision of security analysisVSAvoidvolume of data to be processed
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the most relevant contextual attributes (such as user ID, process ID, command line information) from the complete data message flow. This selective extraction focuses processing on high-value security indicators while filtering out redundant data, thereby maintaining analysis precision without proportionally increasing data volume.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different levels of detail to different aspects of flow analysis. Critical security-relevant fields (user ID, process identity) are collected with high detail, while other fields are aggregated or summarized. This local quality approach optimizes the balance between precision and data volume by tailoring detail to specific analytical needs.

Inventive Principle:
Principle #3Local quality

3Reliability

If flow data and context data are correlated using multiple attributes, then the accuracy of security posture assessment is improved, but the complexity of data correlation increases

Engineering Contradiction:
Improveaccuracy of security posture assessmentVSAvoidcomplexity of correlation engine
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal correlation key structure that can accommodate multiple attributes (user ID, process ID, command line) within a single standardized framework. This multi-functional correlation mechanism handles various types of data association through a unified approach, reducing the need for separate complex correlation logic for each attribute type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11921610B2Correlation key used to correlate flow and context data
Publication Date: 2024.03.05 VMWARE INC
  • US11921610B2 patent drawing
  • US11921610B2 patent drawing
  • US11921610B2 patent drawing

AI summary

Some embodiments provide a novel method for collecting and reporting attributes of data flows associated with machines executing on a plurality of host computers to an analysis appliance. Some embodiments collect, each time a request for a new data message flow is initiated, a set of contextual attributes (i.e., context data) associated with the requested new data message flow. The method, in some embodiments, generates a correlation data set and provides the correlation data set to be included in flow data regarding the requested data message flow to be used by the analysis appliance to correlate context data and flow data received as separate data sets from multiple host computers.