Flow Data Grouping and Visualization for SDDC Security Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.
Innovation Solution
A method for collecting and reporting attributes of data flows across host computers, utilizing a logical network with managed forwarding elements, and processing data through a policy, analytics, and correlation engine appliance for analysis and visualization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If data is collected from multiple host computers in an SDDC, then the quantity of data available for analysis increases, but the data becomes fragmented and difficult to analyze
Solution Approach 1:
The patent segments data collection and processing across multiple host computers, with each host independently collecting flow data and context data from its virtual machines. This segmentation allows parallel data collection while maintaining manageability through modular architecture where each host processes its own data locally before centralized aggregation.
Solution Approach 2:
The patent merges data from multiple sources by collecting flow data and context data from various hosts, aggregating them at a centralized location. The system combines network flow information with contextual information about virtual machines, creating a unified dataset that enables comprehensive security analysis across the entire SDDC environment.
2Reliability
If comprehensive flow data and context data are collected from all hosts, then the completeness of security analysis improves, but the complexity of data processing and reporting increases
Solution Approach 1:
The patent performs preliminary data processing at each host computer before centralized aggregation. Flow data and context data are collected and prepared at the source, with initial filtering and organization performed locally. This preliminary action reduces the burden on centralized processing systems and ensures data is ready for immediate analysis upon receipt.
Solution Approach 2:
The patent introduces intermediary components including flow exporters on each host that act as mediators between data sources and the centralized analysis system. These exporters collect data from multiple sources, perform initial processing, and export standardized formats to the centralized system, simplifying the overall data processing architecture.
3Measurement precision
If detailed flow attributes and context attributes are reported to the analysis appliance, then the precision of security posture assessment improves, but the amount of data to be stored and processed increases
Solution Approach 1:
The patent extracts only the most relevant and valuable data attributes for security analysis. From the vast amount of available flow and context data, the system selectively extracts key attributes such as flow identifiers, statistics, and critical context information about virtual machines. This extraction focuses storage and processing resources on the most security-relevant information.
Solution Approach 2:
The patent applies local quality by collecting different types and amounts of data from different hosts based on their specific roles and characteristics. Each host exports data with attributes tailored to its local context and security requirements, rather than uniformly collecting all possible data from every host. This approach optimizes data quality for local security concerns while managing overall data volume.
Data Source
AI summary
Some embodiments provide a novel method for receiving a plurality of attribute sets from a set of host computers, each attribute set associated with a group of one or more flows that is created by using a key to associate individual flows into the group of flows. The appliance, in some embodiments, merges two identified attribute sets into one merged attribute set and analyzes the merged attribute set to identify a set of properties of the flows in the groups of flows associated with the two attribute sets. In some embodiments, a visualization process includes identifying machines as members of groups and identifying machines that are connected. The visualization process, in some embodiments, also generates a graphical user interface that can be used to select groups of machines, domains, or individual machines and displays contextual attributes relevant to the selected group, domain, or machine.


