Host-Based Anomaly Detection Offloading for SDDC Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.

Innovation Solution

A method is introduced that collects and reports attributes of data flows from machines executing on host computers, using a logical network managed by a virtualization manager, and processes this data through a policy, analytics, and correlation engine appliance for analysis and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If anomaly detection is performed on the server (analysis appliance), then centralized analysis capability is provided, but server processing load and complexity increase

Engineering Contradiction:
Improvecentralized analysis capabilityVSAvoidserver processing load
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The system segments the anomaly detection functionality by deploying lightweight detection agents on individual host computers rather than concentrating all detection processing on the server. Each host agent independently performs local anomaly detection on its own flow data, dividing the overall detection task across multiple distributed nodes. This segmentation reduces server processing load while maintaining centralized coordination through the analysis appliance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces host-based detection agents as intermediaries between the data source (local flows) and the centralized analysis appliance. These agents collect, pre-process, and filter flow data locally before transmitting relevant information to the server, reducing the processing burden on the analysis appliance while maintaining centralized oversight and coordination.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If flow data is collected from multiple host computers, then comprehensive data coverage is achieved, but data aggregation and processing complexity increase

Engineering Contradiction:
Improvedata coverageVSAvoiddata aggregation complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

Each host computer's detection agent autonomously performs local data collection, filtering, and preliminary analysis of its own flow data without requiring centralized coordination for every operation. The agents independently determine which anomalies to report and what data to transmit to the analysis appliance, reducing the complexity of data aggregation at the server while maintaining comprehensive coverage across all hosts.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The host-based detection agents perform preliminary data processing, filtering, and anomaly identification locally before transmitting results to the centralized analysis appliance. This pre-processing eliminates the need for the server to handle raw data from all hosts, significantly reducing aggregation complexity while preserving comprehensive data coverage through coordinated collection of processed results.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11436075B2Offloading anomaly detection from server to host
Publication Date: 2022.09.06 VMWARE INC
  • US11436075B2 patent drawing
  • US11436075B2 patent drawing
  • US11436075B2 patent drawing

AI summary

Some embodiments provide a novel method for collecting and analyzing attributes of data flows associated with machines executing on a plurality of host computers to detect anomalous behavior. In some embodiments, an anomalous behavior is detected for at least one particular flow associated with at least one machine executing on the host computer. In some embodiments, anomaly detection is based on the context data from the guest introspection agent and deep packet inspection. An identifier of the detected anomalous behavior is stored, in some embodiments. The stored attributes are provided, in some embodiments, to a server for further analysis.