Host-Container Segmentation for Network Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional segmentation systems fail to provide adequate control and security for workloads in virtualized environments due to varying levels of visibility and control over networking layers, leading to potential security breaches.

Innovation Solution

A system and method that enforce a segmentation policy on a workload executing in a container by using a configuration generation module in the host namespace to configure a traffic control and monitoring module within the container namespace, which operates under management instructions generated by a segmentation server based on label sets, isolating processes and controlling communications to and from the container.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional segmentation systems are used in virtualized environments, then device complexity is reduced, but security control and visibility are insufficient

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent embeds a traffic control and monitoring module within the container namespace, which is nested inside the host operating system namespace. This nested architecture allows the container-level module to enforce segmentation policies with full visibility and control, while the host-level configuration generation module provides coordination. The nested structure resolves the contradiction by enabling comprehensive security control at the container level without requiring complete redesign of the host segmentation system.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The configuration generation module acts as an intermediary between the segmentation policy definition and the traffic control enforcement. It receives segmentation rules, translates them into management instructions, and configures the traffic control and monitoring module accordingly. This intermediary layer enables sophisticated security control while abstracting the complexity from both the policy definition and enforcement layers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If container-level traffic control is implemented, then security and control precision are improved, but device complexity increases

Engineering Contradiction:
Improvecontrol precisionVSAvoidsystem complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent divides the segmentation system into distinct functional components: a configuration generation module at the host level that translates policies into instructions, and a traffic control and monitoring module at the container level that enforces those instructions. This segmentation allows each component to focus on specific tasks, improving control precision while distributing complexity across multiple manageable modules rather than concentrating it in a single complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The traffic control and monitoring module is specifically tailored to operate within the container namespace, providing localized security control precisely where needed. The module has visibility and control over container networking layers, applying segmentation rules with high precision at the container level without requiring complex modifications to the entire host system. This local quality approach enables precise control with minimal overall system complexity.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If host-level configuration is used to control container traffic, then ease of operation is improved, but visibility into container networking layers is insufficient

Engineering Contradiction:
Improvepolicy managementVSAvoidnetworking visibility
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent merges the configuration generation capability at the host level with the traffic control and monitoring capability at the container level. The configuration generation module executes in the host namespace to create management instructions, while the traffic control and monitoring module executes within the container namespace to enforce those instructions with full networking visibility. This merging of host-level ease of operation with container-level visibility resolves the contradiction by combining the advantages of both approaches.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10805166B2Infrastructure-agnostic network-level visibility and policy enforcement for containers
Publication Date: 2020.10.13 ILLUMIO INC
  • US10805166B2 patent drawing
  • US10805166B2 patent drawing
  • US10805166B2 patent drawing

AI summary

An enforcement mechanism on an operating system instance enforces a segmentation policy on a container. A configuration generation module executing in a host namespace of the operating system instance receives management instructions from a segmentation server for enforcing the segmentation policy on a container. The configuration generation module executes in the host namespace to configure a traffic control and monitoring module in a container namespace associated with the container. The traffic control and monitoring module in the container namespace controls and monitors communications to and from the container in accordance with its configuration. By executing a configuration generation module in the host namespace to configure traffic control and monitoring module in the container namespace, the enforcement mechanism beneficially enables robust and lightweight enforcement in a manner that is agnostic to different containerization protocols.