Correlation Key for Aggregating Flow and Context Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.
Innovation Solution
A method is introduced to collect and report attributes of data flows from host computers associated with a logical network, using a virtualization manager like VMware NSX manager, and process this data with a policy, analytics, and correlation engine appliance for analysis and visualization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If data is collected from multiple host computers in an SDDC, then the quantity and completeness of security data is improved, but the complexity of data aggregation and correlation increases
Solution Approach 1:
The patent introduces a centralized analytics appliance as an intermediary component that receives, aggregates, and correlates flow data from multiple host computers. This intermediary consolidates the complexity of data integration into a single system, allowing individual hosts to simply export data without implementing complex correlation logic themselves.
Solution Approach 2:
The patent merges data from multiple sources (flow data, context data, correlation data) into a unified analysis platform. The analytics appliance combines these different data types and correlates them across multiple hosts, transforming fragmented data into integrated security insights.
2Measurement precision
If contextual attributes are collected for each data message flow, then the precision of security analysis is improved, but the amount of data to be processed and stored increases
Solution Approach 1:
The patent extracts only the most relevant contextual attributes (such as user ID, process ID, command line information) from the complete data message flow. This selective extraction focuses processing on high-value security indicators while filtering out redundant data, thereby maintaining analysis precision without proportionally increasing data volume.
Solution Approach 2:
The patent applies different levels of detail to different aspects of flow analysis. Critical security-relevant fields (user ID, process identity) are collected with high detail, while other fields are aggregated or summarized. This local quality approach optimizes the balance between precision and data volume by tailoring detail to specific analytical needs.
3Reliability
If flow data and context data are correlated using multiple attributes, then the accuracy of security posture assessment is improved, but the complexity of data correlation increases
Solution Approach 1:
The patent implements a universal correlation key structure that can accommodate multiple attributes (user ID, process ID, command line) within a single standardized framework. This multi-functional correlation mechanism handles various types of data association through a unified approach, reducing the need for separate complex correlation logic for each attribute type.
Data Source
AI summary
Some embodiments provide a novel method for collecting and reporting attributes of data flows associated with machines executing on a plurality of host computers to an analysis appliance. Some embodiments collect, each time a request for a new data message flow is initiated, a set of contextual attributes (i.e., context data) associated with the requested new data message flow. The method, in some embodiments, generates a correlation data set and provides the correlation data set to be included in flow data regarding the requested data message flow to be used by the analysis appliance to correlate context data and flow data received as separate data sets from multiple host computers.


