Guest Introspection Agent for Datacenter Traffic Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current firewall solutions lack the ability to provide application process-based controls within datacenters, particularly in managing east-west traffic flows, and fail to effectively process virtual networking and security entities.
Innovation Solution
The implementation of a guest introspection (GI) agent and a service engine on endpoint machines, which capture contextual data items from network and file system events to perform service operations based on predefined rules, including application process-level controls, middlebox services, and process-control actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional firewall solutions are used to enforce network access controls, then north-south traffic flows can be controlled at the perimeter, but application process-based controls and east-west traffic management within the datacenter are insufficient
Solution Approach 1:
The firewall functionality is segmented into distributed firewall service virtual machines deployed on individual host computers within the datacenter. Each firewall SVM enforces rules locally on its associated virtual machines, enabling east-west traffic control while maintaining centralized management capabilities for north-south flows.
Solution Approach 2:
A service gateway acts as an intermediary between virtual machines and the firewall service. The service gateway captures service requests from virtual machines, forwards them to the appropriate firewall SVM, and receives responses to enforce policy decisions, thereby enabling application process-based controls without requiring direct VM-firewall communication.
2Measurement precision
If distributed firewall architectures are deployed on host computers with hypervisors, then both north-south and east-west flows can be managed centrally, but the ability to process virtual networking and security entities at application process level is limited
Solution Approach 1:
The firewall service virtual machine is designed as a universal security entity that can enforce firewall rules across multiple virtual machines and handle various types of traffic flows (north-south and east-west). The service gateway provides multi-functional capabilities by managing service requests, communicating with firewall SVMs, and enforcing policies across different virtual networking environments.
Solution Approach 2:
The firewall SVM automatically enforces security policies on associated virtual machines by capturing service requests through the service gateway, evaluating them against configured rules, and returning enforcement decisions. This self-service mechanism enables application process-level control without requiring manual intervention for each traffic flow decision.
Data Source
AI summary
Some embodiments of the invention provide a method for performing services on an endpoint machine in a datacenter. On the endpoint machine, the method installs a guest introspection (GI) agent and a service engine. In some embodiments, the GI agent and the service engine are part of one monitor agent that is installed on the endpoint machine. The method then registers with a set of one or more notification services on the endpoint machine, the GI agent to receive notifications regarding new data message flow events on the endpoint machine. Through the notifications, the GI agent captures contextual data items regarding new data message flows, and stores the captured contextual data items. The service engine then performs a service for the data message flow based on the captured contextual data.


