Dynamic Key Aggregation for Flow Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.

Innovation Solution

A method is introduced that collects and reports attributes of data flows from machines executing on host computers, using a logical network managed by a virtualization manager, and processes this data through a policy, analytics, and correlation engine appliance for analysis and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If flow data is collected from multiple host computers, then the quantity of data available for analysis increases, but the complexity of processing and analyzing this fragmented data increases

Engineering Contradiction:
Improvequantity of flow dataVSAvoidcomplexity of data processing
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments the data processing task by introducing key-based aggregation groups that organize flow data from multiple hosts into manageable categories. Each key defines a specific aggregation group (e.g., by source IP, destination IP, or other attributes), allowing the system to process data in organized segments rather than handling all fragmented data uniformly, thus reducing processing complexity while maintaining comprehensive coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges flow data from multiple host computers by aggregating records that share common keys into unified aggregation groups. This combining process consolidates fragmented data into structured groups that can be analyzed collectively, transforming the complexity of handling multiple separate data streams into a unified processing approach that maintains data completeness while simplifying analysis.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If dynamic key updates are implemented to adapt to changing network conditions, then the adaptability of the system improves, but the complexity of managing and synchronizing key changes across hosts increases

Engineering Contradiction:
Improveadaptability to network conditionsVSAvoidcomplexity of key management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where hosts report their current key sets to the analysis appliance, and the appliance sends updated key sets back to hosts. This feedback loop enables the system to adapt to changing network conditions dynamically while managing complexity through automated synchronization - the appliance centrally coordinates key updates based on feedback from hosts, eliminating the need for complex distributed key management algorithms.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary action by having hosts send notifications about key changes before the analysis appliance processes updates. This allows the system to anticipate and prepare for key changes, reducing the complexity of real-time synchronization by handling updates in advance through host-initiated notifications that trigger coordinated key set updates across the distributed system.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If flow data is aggregated into groups based on keys, then the ease of analyzing and visualizing data improves, but the loss of granular flow information increases

Engineering Contradiction:
Improveease of data analysisVSAvoidloss of flow granularity
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent applies dynamics by enabling flexible key configurations that can be adjusted based on analytical needs. Keys can be defined using various attributes (source IP, destination IP, protocol, ports, etc.) and can be dynamically modified to aggregate or disaggregate data at different granularities. This dynamic key configuration allows the system to maintain ease of analysis through aggregation while preserving the ability to access granular flow information when needed through flexible key redesign.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces another dimension to data organization by using key-based aggregation that operates on multiple attributes simultaneously. Instead of simple single-dimension filtering, the system aggregates across combinations of attributes (source IP, destination IP, protocol, ports, etc.), creating a multi-dimensional organization of flow data that maintains analytical ease while preserving granular information through the flexibility of multi-attribute key combinations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11288256B2Dynamically providing keys to host for flow aggregation
Publication Date: 2022.03.29 VMWARE INC
  • US11288256B2 patent drawing
  • US11288256B2 patent drawing
  • US11288256B2 patent drawing

AI summary

Some embodiments provide a novel method for collecting and reporting attributes of data flows associated with machines executing on a plurality of host computers to an analysis appliance. The analysis appliance, in some embodiments, receives definitions of keys and provides them to the host computers. In some embodiments, existing keys are modified based on the analysis. Additionally, or alternatively, new keys are provided based on the analysis. In some embodiments, the analysis appliance receives the flow group records (e.g., sets of attributes) based on the keys and the configuration data from each host computer.