Flow Aggregation Appliance for SDDC Security Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.

Innovation Solution

A method for collecting and reporting data flow attributes from host computers, utilizing a logical network managed by a virtualization manager, which includes flow exporters, guest introspection agents, anomaly detection engines, and analysis appliances to process and store data for visualization and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data is collected from multiple host computers in SDDC, then the quantity of data for analysis increases, but the data becomes fragmented and difficult to analyze

Engineering Contradiction:
Improvequantity of dataVSAvoidcomplexity of data analysis
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent combines flow data from multiple host computers into a centralized analysis appliance. The flow exporter on each host collects data locally, then publishes it to the analysis appliance where data from multiple hosts is merged into unified data structures, enabling comprehensive analysis while simplifying the complexity of handling fragmented data across distributed systems.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If flow data is collected and published from each host computer, then the completeness of security analysis improves, but the complexity of data collection and processing increases

Engineering Contradiction:
Improvecompleteness of security analysisVSAvoidcomplexity of data collection
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the data collection and processing functions across different components: flow exporters on individual hosts handle local data collection, while the analysis appliance handles centralized processing. This segmentation allows each component to focus on specific tasks, improving reliability through distributed collection while managing complexity through functional separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The analysis appliance acts as an intermediary between multiple host computers. It receives flow data from various hosts, standardizes the data formats, and performs unified analysis. This intermediary approach ensures complete security analysis across all hosts while simplifying the complexity of direct peer-to-peer data processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If aggregated flow data is published to analysis appliance, then the security posture visualization improves, but the data processing time and resources increase

Engineering Contradiction:
Improveprecision of security posture assessmentVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The flow exporter performs preliminary aggregation and formatting of flow data before publishing to the analysis appliance. Data is pre-processed into standardized structures with relevant security attributes already organized, which reduces the processing time and resources required when the analysis appliance receives and visualizes the data for security posture assessment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11176157B2Using keys to aggregate flows at appliance
Publication Date: 2021.11.16 VMWARE INC
  • US11176157B2 patent drawing
  • US11176157B2 patent drawing
  • US11176157B2 patent drawing

AI summary

Some embodiments provide a novel method for receiving a plurality of attribute sets from a set of host computers, each attribute set associated with a group of one or more flows that is created by using a key to associate individual flows into the group of flows. The appliance, in some embodiments, identifies at least two received attribute sets from two different host computers that relate to a same set of flows between a same set of source machines and a same set of destination machines. The appliance merges the two identified attribute sets into one merged attribute set and analyzes the merged attribute set to identify a set of properties of the flows in the groups of flows associated with the two identified attribute sets, in some embodiments.