Guest DCN Clustering for Interhost Traffic Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In datacenters and hosting systems, high-end switches with large bandwidth capacities are costly and limit computing throughput, while Software-Defined Networking (SDN) faces challenges in minimizing interhost network communications due to the co-residence of attacker and victim virtual machines on the same host, increasing the risk of threats.
Innovation Solution
A method for clustering frequently communicating guest data compute nodes (GDCNs) on a single host machine, using a service data compute node (SDCN) to intercept and duplicate network data messages, and store metadata to identify frequent communication patterns, allowing for load balancing and optimized network traffic management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If high-end switches with large bandwidth capacities are used to reduce interhost traffic, then network bandwidth capacity is improved, but cost increases and computing throughput is limited
Solution Approach 1:
The patent segments the network traffic into intrahost and interhost categories, and further segments interhost traffic into different patterns (frequent vs. infrequent communicators). By identifying and grouping frequently communicating guest DCNs into clusters on the same host, the system reduces the need for high-bandwidth switches for all traffic, only applying switch upgrades where necessary for infrequent communicators.
Solution Approach 2:
The patent uses service DCNs that collect and duplicate network data messages to monitor and analyze traffic patterns. These service DCNs create copies of metadata from network messages to track communication frequencies between guest DCNs, enabling the system to identify clustering opportunities without interfering with actual data transmission.
2Productivity
If VMs are widely placed within a hosting system to distribute workloads, then system utilization is improved, but the probability of co-residence threats increases
Solution Approach 1:
The patent implements a feedback mechanism where service DCNs continuously monitor network traffic metadata, analyze communication patterns between guest DCNs, and provide this information to the management system. The management system uses this feedback to identify clusters of frequently communicating VMs and migrate them to the same host, thereby reducing co-residence threats while maintaining workload distribution.
Solution Approach 2:
The patent makes VM placement dynamic by continuously monitoring traffic patterns and adjusting VM locations based on real-time communication data. The system can dynamically migrate VMs between hosts based on changing traffic patterns, allowing the system to adapt to evolving security risks and communication needs.
3Loss of energy
If intrahost traffic is used instead of interhost traffic, then network efficiency is improved, but VM placement flexibility is reduced
Solution Approach 1:
The patent changes the parameter of VM placement by analyzing traffic patterns and adjusting VM locations based on communication frequency. The system identifies clusters of VMs that communicate frequently and migrates them to the same host, transforming interhost traffic into intrahost traffic for these clusters while maintaining placement flexibility for other VMs based on their communication patterns.
Data Source
AI summary
Some embodiments provide a method for clustering a set of data compute nodes (DCNs), which communicate with each other more frequently, on one or more host machines. The method groups together guest DCNs (GDCNs) that (1) execute on different host machines and (2) exchange network data among themselves more frequently, in order to reduce interhost network traffic. The more frequently-communicating GDCNs can be a set of GDCNs that implement a distributed application, GDCNs of a particular tier in a multi-tier network architecture (e.g., a web tier in a three-tier architecture), GDCNs that are dedicated to a particular tenant in a hosting system, or any other set of GDCNs that exchange data among each other regularly for a particular purpose.


