Flow Group Configuration Tags for SDDC Security Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.
Innovation Solution
A method is introduced that collects and reports attributes of data flows from machines executing on host computers, using a logical network managed by a virtualization manager, and processes this data through a policy, analytics, and correlation engine appliance for analysis and visualization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If flow data is collected from multiple host computers in an SDDC, then the quantity and completeness of security data is improved, but the complexity of data aggregation and correlation increases
Solution Approach 1:
The patent introduces a centralized analytics appliance as an intermediary component that receives flow data from multiple host computers, performs aggregation and correlation operations, and generates unified security analytics. This mediator handles the complexity of data integration, allowing individual hosts to simply export data without implementing complex aggregation logic themselves.
Solution Approach 2:
The patent combines flow data from multiple sources and multiple types of data (network flow data, context data, configuration data) into a unified analytical framework. The analytics appliance merges these disparate data streams and processes them together to produce comprehensive security analytics, eliminating the need for separate analysis systems for each data type.
2Ease of operation
If flow data is aggregated into flow group records, then the ease of analysis is improved, but the loss of detailed flow information increases
Solution Approach 1:
The patent applies different levels of aggregation to different aspects of flow data. Rather than uniformly aggregating all flow records, the system maintains detailed flow information where needed while providing aggregated summaries for broader analysis. This allows analysts to drill down from aggregated flow groups to individual flow records when detailed inspection is required.
Solution Approach 2:
The patent adds temporal and hierarchical dimensions to the data structure. Flow data is organized into flow groups that represent aggregated views at different time intervals and levels of detail. This multi-dimensional organization allows the same data to serve both detailed analysis needs and high-level summary needs without losing information.
3Measurement precision
If configuration tags are used to identify groups of data messages, then the precision of security policy application is improved, but the complexity of configuration management increases
Solution Approach 1:
The patent creates a universal tagging system where configuration tags serve multiple functions: they identify groups of data messages for policy application, enable correlation with flow data, and provide a consistent interface for security policy definition across different contexts. This multi-functional tag system reduces the need for separate configuration mechanisms for different purposes.
Data Source
AI summary
Some embodiments provide a novel method for correlating configuration data received from the network manager computer with flow group records. In some embodiments, the correlation with the configuration data identifies a group associated with at least one of: (i) the source machine, (ii) destination machine, and (iii) service rules applied to the flows. The correlation with the configuration data, in some embodiments, also identifies whether a service rule applied to the flows is a default service rule. In some embodiments, the correlation with the configuration is based on a tag included in the flow group record that identifies a configuration version, and a configuration associated with the identified configuration version is used to identify the group association or the identity of the default service rule.


