Flow Aggregation Appliance for SDDC Security Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.
Innovation Solution
A method for collecting and reporting data flow attributes from host computers, utilizing a logical network managed by a virtualization manager, which includes flow exporters, guest introspection agents, anomaly detection engines, and analysis appliances to process and store data for visualization and analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If data is collected from multiple host computers in SDDC, then the quantity of data for analysis increases, but the data becomes fragmented and difficult to analyze
Solution Approach 1:
The patent combines flow data from multiple host computers into a centralized analysis appliance. The flow exporter on each host collects data locally, then publishes it to the analysis appliance where data from multiple hosts is merged into unified data structures, enabling comprehensive analysis while simplifying the complexity of handling fragmented data across distributed systems.
2Reliability
If flow data is collected and published from each host computer, then the completeness of security analysis improves, but the complexity of data collection and processing increases
Solution Approach 1:
The patent segments the data collection and processing functions across different components: flow exporters on individual hosts handle local data collection, while the analysis appliance handles centralized processing. This segmentation allows each component to focus on specific tasks, improving reliability through distributed collection while managing complexity through functional separation.
Solution Approach 2:
The analysis appliance acts as an intermediary between multiple host computers. It receives flow data from various hosts, standardizes the data formats, and performs unified analysis. This intermediary approach ensures complete security analysis across all hosts while simplifying the complexity of direct peer-to-peer data processing.
3Measurement precision
If aggregated flow data is published to analysis appliance, then the security posture visualization improves, but the data processing time and resources increase
Solution Approach 1:
The flow exporter performs preliminary aggregation and formatting of flow data before publishing to the analysis appliance. Data is pre-processed into standardized structures with relevant security attributes already organized, which reduces the processing time and resources required when the analysis appliance receives and visualizes the data for security posture assessment.
Data Source
AI summary
Some embodiments provide a novel method for receiving a plurality of attribute sets from a set of host computers, each attribute set associated with a group of one or more flows that is created by using a key to associate individual flows into the group of flows. The appliance, in some embodiments, identifies at least two received attribute sets from two different host computers that relate to a same set of flows between a same set of source machines and a same set of destination machines. The appliance merges the two identified attribute sets into one merged attribute set and analyzes the merged attribute set to identify a set of properties of the flows in the groups of flows associated with the two identified attribute sets, in some embodiments.


