Hypervisor Event Processing Microservices for Security Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity and variability of hypervisor-generated event data across different types of hypervisors pose challenges for consistent analysis and response in computer network security systems, as each hypervisor may generate and make event data accessible in unique ways, leading to operational inefficiencies and reliability issues.
Innovation Solution
The implementation of hypervisor event processing microservices that abstract and normalize event data from various hypervisors, allowing for uniform processing and response to hypervisor-generated events, regardless of the type or method of data generation, through a security service that includes a hypervisor event proxy, normalization, and processing microservices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If event data is processed directly from multiple different types of hypervisors, then the system can handle diverse hypervisor events, but the processing complexity and variability increase significantly
Solution Approach 1:
The patent introduces an intermediary component that sits between the diverse hypervisors and the security system. This intermediary translates and normalizes events from different hypervisor types into a unified format, allowing the system to handle diverse hypervisor events without directly processing their varying formats, thus reducing processing complexity while maintaining adaptability
Solution Approach 2:
The patent segments the event processing functionality into separate modules, each handling specific hypervisor types or event categories. This segmentation allows the system to process different hypervisor events through specialized handlers, reducing overall processing complexity by breaking down the complex task into manageable, standardized segments
2Measurement precision
If custom processing logic is implemented for each hypervisor type, then accurate analysis of specific hypervisor events is achieved, but operational efficiency decreases
Solution Approach 1:
The patent implements a universal event processing framework that can handle multiple hypervisor types through a common interface. This universal approach maintains accuracy by incorporating hypervisor-specific translation rules while achieving operational efficiency through standardized processing pipelines, eliminating the need for separate custom processing logic for each hypervisor type
3Adaptability or versatility
If event data from different hypervisors is processed in heterogeneous formats, then specific hypervisor characteristics are preserved, but consistency in analysis and response is compromised
Solution Approach 1:
The patent transforms event data by changing its format parameters from heterogeneous hypervisor-specific formats into a standardized internal format. This parameter transformation preserves the essential characteristics and meaning of original events while ensuring consistency in analysis and response across all hypervisor types, resolving the contradiction between adaptability and reliability
Data Source
AI summary
Systems, methods, and apparatuses enable a network security system to more efficiently process and respond to events generated by hypervisors and other associated components of a networked computer system. In this context, a hypervisor event refers broadly to any action that occurs related to one or more components of a hypervisor (including the hypervisor itself, virtual servers hosted by the hypervisor, etc.) and/or to data identifying the occurrence of the action(s) (e.g., a log entry, a notification message, etc.). A security service obtains and analyzes event data from any number of different types of hypervisors, where each different type of hypervisor may represent events differently and/or make event data accessible in different ways, among other differences.


