Host-Based Anomaly Detection Offloading for SDDC Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.
Innovation Solution
A method is introduced that collects and reports attributes of data flows from machines executing on host computers, using a logical network managed by a virtualization manager, and processes this data through a policy, analytics, and correlation engine appliance for analysis and visualization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If anomaly detection is performed on the server (analysis appliance), then centralized analysis capability is provided, but server processing load and complexity increase
Solution Approach 1:
The system segments the anomaly detection functionality by deploying lightweight detection agents on individual host computers rather than concentrating all detection processing on the server. Each host agent independently performs local anomaly detection on its own flow data, dividing the overall detection task across multiple distributed nodes. This segmentation reduces server processing load while maintaining centralized coordination through the analysis appliance.
Solution Approach 2:
The patent introduces host-based detection agents as intermediaries between the data source (local flows) and the centralized analysis appliance. These agents collect, pre-process, and filter flow data locally before transmitting relevant information to the server, reducing the processing burden on the analysis appliance while maintaining centralized oversight and coordination.
2Quantity of substance
If flow data is collected from multiple host computers, then comprehensive data coverage is achieved, but data aggregation and processing complexity increase
Solution Approach 1:
Each host computer's detection agent autonomously performs local data collection, filtering, and preliminary analysis of its own flow data without requiring centralized coordination for every operation. The agents independently determine which anomalies to report and what data to transmit to the analysis appliance, reducing the complexity of data aggregation at the server while maintaining comprehensive coverage across all hosts.
Solution Approach 2:
The host-based detection agents perform preliminary data processing, filtering, and anomaly identification locally before transmitting results to the centralized analysis appliance. This pre-processing eliminates the need for the server to handle raw data from all hosts, significantly reducing aggregation complexity while preserving comprehensive data coverage through coordinated collection of processed results.
Data Source
AI summary
Some embodiments provide a novel method for collecting and analyzing attributes of data flows associated with machines executing on a plurality of host computers to detect anomalous behavior. In some embodiments, an anomalous behavior is detected for at least one particular flow associated with at least one machine executing on the host computer. In some embodiments, anomaly detection is based on the context data from the guest introspection agent and deep packet inspection. An identifier of the detected anomalous behavior is stored, in some embodiments. The stored attributes are provided, in some embodiments, to a server for further analysis.


