Host-Based Flow Aggregation for SDDC Security Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.

Innovation Solution

A method for collecting and reporting attributes of data flows across host computers, utilizing a logical network managed by a virtualization manager, where data is processed by a policy, analytics, and correlation engine appliance for analysis and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data is collected from multiple host computers in an SDDC, then the quantity and comprehensiveness of data increases, but the data becomes fragmented and difficult to analyze

Engineering Contradiction:
Improvedata quantityVSAvoiddata analysis complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments data collection and processing across multiple host computers, with each host having independent flow exporters and context exporters that collect data locally. This segmentation allows comprehensive data gathering while maintaining manageable units that can be independently processed and then aggregated by the analysis appliance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges data from multiple sources by having the analysis appliance aggregate flow data and context data from all host computers into a unified dataset. This combining process transforms fragmented data into comprehensive, analyzable information while preserving the benefits of distributed collection.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If flow data and context data are collected separately from multiple sources, then data completeness improves, but data processing complexity increases

Engineering Contradiction:
Improvedata completenessVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by having flow exporters and context exporters collect and pre-process data at the host level before transmission to the analysis appliance. This preliminary collection and filtering reduces the burden on the analysis appliance while ensuring comprehensive data capture.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The analysis appliance acts as an intermediary that receives, correlates, and integrates flow data and context data from multiple hosts. This mediator component simplifies the processing complexity by providing a centralized point for data aggregation and correlation, while the exporters on each host handle the complexity of data collection independently.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11398987B2Host-based flow aggregation
Publication Date: 2022.07.26 VMWARE INC
  • US11398987B2 patent drawing
  • US11398987B2 patent drawing
  • US11398987B2 patent drawing

AI summary

Some embodiments provide a novel method for collecting and reporting attributes of data flows associated with machines executing on a plurality of host computers to an analysis appliance. Each host computer, in some embodiments, is responsible for collecting and reporting attributes of data flows associated with machines executing on a host computer. In some embodiments, the host computer includes a flow exporter that processes and publishes flow data to the analysis appliance, a set of agents for collecting context data relating to the flows from machines executing on the host, a set of additional modules that provide additional context data, an anomaly detection engine that analyzes flow data and context data and provides additional context data, and a context exporter for processing and publishing context data to the analysis appliance.