Micro-segmentation for East-West Traffic Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional perimeter security solutions in Software-Defined Datacenters (SDDCs) are ineffective in inspecting and controlling east-west traffic within the data center, leaving internal devices vulnerable to lateral threats once an attacker penetrates the perimeter.

Innovation Solution

Implementing micro-segmentation through a dynamic and automated approach that uses clustering algorithms to detect virtual machine groups based on application implementation information, creating logical network segments and enforcing security policies to isolate and secure east-west traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If perimeter security solutions are used to inspect north-south traffic, then external threats are blocked, but east-west traffic within the data center remains unsecured and vulnerable to lateral threats

Engineering Contradiction:
ImprovesecurityVSAvoidtraffic inspection coverage
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides the data center network into multiple micro-segments at the virtual machine level, creating fine-grained security zones. Each virtual machine or group of virtual machines becomes an isolated segment with its own security policies, enabling inspection and control of east-west traffic between segments while maintaining overall network security architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of security by moving from traditional perimeter-based security (north-south traffic) to internal micro-segmentation security (east-west traffic). This dimensional shift allows security policies to be applied at the virtual machine level within the data center, complementing existing perimeter security rather than replacing it.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If micro-segmentation is implemented to secure east-west traffic, then internal device protection is improved, but system complexity increases due to dynamic segmentation and policy management

Engineering Contradiction:
Improveinternal device protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements automated clustering algorithms that dynamically form micro-segments based on application implementation information and communication patterns. The system self-organizes virtual machines into security segments without manual intervention, and automatically generates and enforces security policies, reducing the operational complexity despite the increased segmentation granularity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent dynamically adjusts security segmentation parameters based on changing application requirements and communication patterns. The clustering algorithm continuously monitors and reconfigures micro-segments according to actual traffic patterns, allowing the system to adapt to parameter changes in application behavior without requiring manual reconfiguration of security policies.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If dynamic clustering algorithms are used to detect virtual machine groups, then security segmentation accuracy is improved, but computational overhead and processing time increase

Engineering Contradiction:
Improvesegmentation accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs clustering analysis on application implementation information collected during normal operation to pre-determine micro-segment groupings. By analyzing communication patterns and application relationships in advance, the system establishes security segments before threats occur, enabling rapid policy enforcement without real-time computational delays during security events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous monitoring of east-west traffic patterns and communication behavior within micro-segments. The clustering algorithm uses feedback from observed traffic patterns to refine and adjust segment groupings, improving segmentation accuracy over time while learning from actual data center operations to reduce computational overhead in subsequent clustering cycles.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10375121B2Micro-segmentation in virtualized computing environments
Publication Date: 2019.08.06 VMWARE INC
  • US10375121B2 patent drawing
  • US10375121B2 patent drawing
  • US10375121B2 patent drawing

AI summary

Example methods are provided for an entity to perform micro-segmentation in a virtualized computing environment that includes multiple hosts. The method may comprise obtaining application implementation information associated with one or more applications implemented by multiple virtualized computing instances, each of the multiple virtualized computing instances being supported by one of the multiple hosts. The method may further comprise detecting micro-segments by clustering the multiple virtualized computing instances based on the application implementation information, and determining security policies for respective detected micro-segments. Each of the detected micro-segments may include one or more of the multiple virtualized computing instances that have more similarity compared to those in a different detected micro-segment.