Host-Based Flow Aggregation for SDDC Security Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.
Innovation Solution
A method for collecting and reporting attributes of data flows across host computers, utilizing a logical network managed by a virtualization manager, where data is processed by a policy, analytics, and correlation engine appliance for analysis and visualization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If data is collected from multiple host computers in an SDDC, then the quantity and comprehensiveness of data increases, but the data becomes fragmented and difficult to analyze
Solution Approach 1:
The patent segments data collection and processing across multiple host computers, with each host having independent flow exporters and context exporters that collect data locally. This segmentation allows comprehensive data gathering while maintaining manageable units that can be independently processed and then aggregated by the analysis appliance.
Solution Approach 2:
The patent merges data from multiple sources by having the analysis appliance aggregate flow data and context data from all host computers into a unified dataset. This combining process transforms fragmented data into comprehensive, analyzable information while preserving the benefits of distributed collection.
2Reliability
If flow data and context data are collected separately from multiple sources, then data completeness improves, but data processing complexity increases
Solution Approach 1:
The patent applies preliminary action by having flow exporters and context exporters collect and pre-process data at the host level before transmission to the analysis appliance. This preliminary collection and filtering reduces the burden on the analysis appliance while ensuring comprehensive data capture.
Solution Approach 2:
The analysis appliance acts as an intermediary that receives, correlates, and integrates flow data and context data from multiple hosts. This mediator component simplifies the processing complexity by providing a centralized point for data aggregation and correlation, while the exporters on each host handle the complexity of data collection independently.
Data Source
AI summary
Some embodiments provide a novel method for collecting and reporting attributes of data flows associated with machines executing on a plurality of host computers to an analysis appliance. Each host computer, in some embodiments, is responsible for collecting and reporting attributes of data flows associated with machines executing on a host computer. In some embodiments, the host computer includes a flow exporter that processes and publishes flow data to the analysis appliance, a set of agents for collecting context data relating to the flows from machines executing on the host, a set of additional modules that provide additional context data, an anomaly detection engine that analyzes flow data and context data and provides additional context data, and a context exporter for processing and publishing context data to the analysis appliance.


