Flow Group Configuration Tags for SDDC Security Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.

Innovation Solution

A method is introduced that collects and reports attributes of data flows from machines executing on host computers, using a logical network managed by a virtualization manager, and processes this data through a policy, analytics, and correlation engine appliance for analysis and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If flow data is collected from multiple host computers in an SDDC, then the quantity and completeness of security data is improved, but the complexity of data aggregation and correlation increases

Engineering Contradiction:
Improvequantity of security dataVSAvoidcomplexity of data aggregation system
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent introduces a centralized analytics appliance as an intermediary component that receives flow data from multiple host computers, performs aggregation and correlation operations, and generates unified security analytics. This mediator handles the complexity of data integration, allowing individual hosts to simply export data without implementing complex aggregation logic themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent combines flow data from multiple sources and multiple types of data (network flow data, context data, configuration data) into a unified analytical framework. The analytics appliance merges these disparate data streams and processes them together to produce comprehensive security analytics, eliminating the need for separate analysis systems for each data type.

Inventive Principle:
Principle #5Merging (Combining)

2Ease of operation

If flow data is aggregated into flow group records, then the ease of analysis is improved, but the loss of detailed flow information increases

Engineering Contradiction:
Improveease of data analysisVSAvoidloss of flow detail information
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent applies different levels of aggregation to different aspects of flow data. Rather than uniformly aggregating all flow records, the system maintains detailed flow information where needed while providing aggregated summaries for broader analysis. This allows analysts to drill down from aggregated flow groups to individual flow records when detailed inspection is required.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent adds temporal and hierarchical dimensions to the data structure. Flow data is organized into flow groups that represent aggregated views at different time intervals and levels of detail. This multi-dimensional organization allows the same data to serve both detailed analysis needs and high-level summary needs without losing information.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If configuration tags are used to identify groups of data messages, then the precision of security policy application is improved, but the complexity of configuration management increases

Engineering Contradiction:
Improveprecision of security policy targetingVSAvoidcomplexity of configuration management
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal tagging system where configuration tags serve multiple functions: they identify groups of data messages for policy application, enable correlation with flow data, and provide a consistent interface for security policy definition across different contexts. This multi-functional tag system reduces the need for separate configuration mechanisms for different purposes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11140090B2Analyzing flow group attributes using configuration tags
Publication Date: 2021.10.05 VMWARE INC
  • US11140090B2 patent drawing
  • US11140090B2 patent drawing
  • US11140090B2 patent drawing

AI summary

Some embodiments provide a novel method for correlating configuration data received from the network manager computer with flow group records. In some embodiments, the correlation with the configuration data identifies a group associated with at least one of: (i) the source machine, (ii) destination machine, and (iii) service rules applied to the flows. The correlation with the configuration data, in some embodiments, also identifies whether a service rule applied to the flows is a default service rule. In some embodiments, the correlation with the configuration is based on a tag included in the flow group record that identifies a configuration version, and a configuration associated with the identified configuration version is used to identify the group association or the identity of the default service rule.