Flow Data Grouping and Visualization for SDDC Security Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.

Innovation Solution

A method for collecting and reporting attributes of data flows across host computers, utilizing a logical network with managed forwarding elements, and processing data through a policy, analytics, and correlation engine appliance for analysis and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data is collected from multiple host computers in an SDDC, then the quantity of data available for analysis increases, but the data becomes fragmented and difficult to analyze

Engineering Contradiction:
Improvequantity of dataVSAvoiddata analysis complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments data collection and processing across multiple host computers, with each host independently collecting flow data and context data from its virtual machines. This segmentation allows parallel data collection while maintaining manageability through modular architecture where each host processes its own data locally before centralized aggregation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges data from multiple sources by collecting flow data and context data from various hosts, aggregating them at a centralized location. The system combines network flow information with contextual information about virtual machines, creating a unified dataset that enables comprehensive security analysis across the entire SDDC environment.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If comprehensive flow data and context data are collected from all hosts, then the completeness of security analysis improves, but the complexity of data processing and reporting increases

Engineering Contradiction:
Improvesecurity analysis completenessVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary data processing at each host computer before centralized aggregation. Flow data and context data are collected and prepared at the source, with initial filtering and organization performed locally. This preliminary action reduces the burden on centralized processing systems and ensures data is ready for immediate analysis upon receipt.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces intermediary components including flow exporters on each host that act as mediators between data sources and the centralized analysis system. These exporters collect data from multiple sources, perform initial processing, and export standardized formats to the centralized system, simplifying the overall data processing architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If detailed flow attributes and context attributes are reported to the analysis appliance, then the precision of security posture assessment improves, but the amount of data to be stored and processed increases

Engineering Contradiction:
Improvesecurity posture assessment precisionVSAvoiddata volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the most relevant and valuable data attributes for security analysis. From the vast amount of available flow and context data, the system selectively extracts key attributes such as flow identifiers, statistics, and critical context information about virtual machines. This extraction focuses storage and processing resources on the most security-relevant information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by collecting different types and amounts of data from different hosts based on their specific roles and characteristics. Each host exports data with attributes tailored to its local context and security requirements, rather than uniformly collecting all possible data from every host. This approach optimizes data quality for local security concerns while managing overall data volume.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240031246A1Presenting data regarding grouped flows
Publication Date: 2024.01.25 VMWARE INC
  • US20240031246A1 patent drawing
  • US20240031246A1 patent drawing
  • US20240031246A1 patent drawing

AI summary

Some embodiments provide a novel method for receiving a plurality of attribute sets from a set of host computers, each attribute set associated with a group of one or more flows that is created by using a key to associate individual flows into the group of flows. The appliance, in some embodiments, merges two identified attribute sets into one merged attribute set and analyzes the merged attribute set to identify a set of properties of the flows in the groups of flows associated with the two attribute sets. In some embodiments, a visualization process includes identifying machines as members of groups and identifying machines that are connected. The visualization process, in some embodiments, also generates a graphical user interface that can be used to select groups of machines, domains, or individual machines and displays contextual attributes relevant to the selected group, domain, or machine.