Network Flow Status Synchronization for VM Migration Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security detection systems, particularly stateful detection methods, fail to maintain synchronized network data flow detection status across security device nodes when virtual machines migrate, leading to inadequate network attack detection and compromised system security.

Innovation Solution

A method and device for synchronizing network data flow detection status, where a status synchronizing server receives requests from security device nodes to maintain and update flow entries, determining detection status by querying local records and communicating with other nodes to ensure consistent detection status across nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If stateful detection method is used to detect multiple data packets and maintain detection status, then network attack detection accuracy is improved, but system complexity increases and data loss occurs during virtual machine migration

Engineering Contradiction:
Improvenetwork attack detection accuracyVSAvoiddetection status information loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

A status synchronizing server is introduced as an intermediary component between multiple security device nodes. This server maintains a centralized registration record that stores detection status information for data flows, enabling different security nodes to access and synchronize status information without direct peer-to-peer communication complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent introduces a new dimensional perspective by creating a centralized status management layer (the status synchronizing server) that operates independently from the traditional peer-to-peer detection architecture. This additional dimension enables status information to be stored, queried, and synchronized across multiple nodes without disrupting the existing detection flow.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If stateful detection method is used to detect multiple data packets in sequence, then network security detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork security detection capabilityVSAvoidsecurity device node complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security detection system is segmented into functional components: security device nodes perform detection operations locally, while the status synchronizing server handles centralized status management. This segmentation allows each component to have simpler, more focused functionality rather than requiring every node to maintain complex stateful detection status independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The status synchronizing server acts as an intermediary that centralizes the management of detection status information. This reduces the complexity burden on individual security device nodes by offloading status maintenance and synchronization tasks to the dedicated server.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If virtual machine migration occurs, then system flexibility and adaptability are improved, but detection status synchronization fails leading to security vulnerabilities

Engineering Contradiction:
Improvevirtual machine migration capabilityVSAvoiddetection status synchronization
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The status synchronizing server serves as a persistent intermediary that survives virtual machine migrations. When a virtual machine migrates between hosts, the registration record of its data flow status is preserved in the server, enabling seamless status synchronization across the migration event without losing detection context.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by proactively querying and updating detection status information in the registration record before and during virtual machine migration events. This ensures that status information is ready and synchronized in advance, preventing detection failures that would occur with reactive approaches.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2811691B1Method and device for synchronizing network data flow detection status
Publication Date: 2016.09.14 HUAWEI TECH CO LTD
  • EP2811691B1 patent drawingFigure 1~2
  • EP2811691B1 patent drawingFigure 3~4
  • EP2811691B1 patent drawingFigure 5

AI summary

Embodiments of the present invention provide a method and a device for synchronizing network data flow detection status. The method includes: receiving a first request sent by a first security device node, where the first request carries a first flow entry of a first data flow that is currently detected by the first security device node, and a flow entry is used to uniquely identify a data flow; determining first network data flow detection status corresponding to the first flow entry; sending a first response to the first security device node, where the first response carries the first network data flow detection status, so that the first security device node maintains, according to the first response, second network data flow detection status that corresponds to the first flow entry and is stored on the first security device node. According to the embodiments of the present invention, a security device node requests previous network data flow detection status of a data flow from a status synchronizing server so as to synchronize network data flow detection status, thereby allowing the security device node to detect a network attack in a more accurate way and improving network system security.