Hypervisor Event Processing Microservices for Security Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity and variability of hypervisor-generated event data across different types of hypervisors pose challenges for consistent analysis and response in computer network security systems, as each hypervisor may generate and make event data accessible in unique ways, leading to operational inefficiencies and reliability issues.

Innovation Solution

The implementation of hypervisor event processing microservices that abstract and normalize event data from various hypervisors, allowing for uniform processing and response to hypervisor-generated events, regardless of the type or method of data generation, through a security service that includes a hypervisor event proxy, normalization, and processing microservices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If event data is processed directly from multiple different types of hypervisors, then the system can handle diverse hypervisor events, but the processing complexity and variability increase significantly

Engineering Contradiction:
Improveability to handle diverse hypervisor eventsVSAvoidprocessing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component that sits between the diverse hypervisors and the security system. This intermediary translates and normalizes events from different hypervisor types into a unified format, allowing the system to handle diverse hypervisor events without directly processing their varying formats, thus reducing processing complexity while maintaining adaptability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the event processing functionality into separate modules, each handling specific hypervisor types or event categories. This segmentation allows the system to process different hypervisor events through specialized handlers, reducing overall processing complexity by breaking down the complex task into manageable, standardized segments

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If custom processing logic is implemented for each hypervisor type, then accurate analysis of specific hypervisor events is achieved, but operational efficiency decreases

Engineering Contradiction:
Improveaccuracy of event analysisVSAvoidoperational efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements a universal event processing framework that can handle multiple hypervisor types through a common interface. This universal approach maintains accuracy by incorporating hypervisor-specific translation rules while achieving operational efficiency through standardized processing pipelines, eliminating the need for separate custom processing logic for each hypervisor type

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If event data from different hypervisors is processed in heterogeneous formats, then specific hypervisor characteristics are preserved, but consistency in analysis and response is compromised

Engineering Contradiction:
Improvepreservation of hypervisor characteristicsVSAvoidconsistency of analysis
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent transforms event data by changing its format parameters from heterogeneous hypervisor-specific formats into a standardized internal format. This parameter transformation preserves the essential characteristics and meaning of original events while ensuring consistency in analysis and response across all hypervisor types, resolving the contradiction between adaptability and reliability

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10447716B2Systems and methods for processing hypervisor-generated event data
Publication Date: 2019.10.15 FORTINET INC
  • US10447716B2 patent drawing
  • US10447716B2 patent drawing
  • US10447716B2 patent drawing

AI summary

Systems, methods, and apparatuses enable a network security system to more efficiently process and respond to events generated by hypervisors and other associated components of a networked computer system. In this context, a hypervisor event refers broadly to any action that occurs related to one or more components of a hypervisor (including the hypervisor itself, virtual servers hosted by the hypervisor, etc.) and/or to data identifying the occurrence of the action(s) (e.g., a log entry, a notification message, etc.). A security service obtains and analyzes event data from any number of different types of hypervisors, where each different type of hypervisor may represent events differently and/or make event data accessible in different ways, among other differences.