Micro-segmentation for East-West Traffic Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional perimeter security solutions in Software-Defined Datacenters (SDDCs) are ineffective in inspecting and controlling east-west traffic within the data center, leaving internal devices vulnerable to lateral threats once an attacker penetrates the perimeter.
Innovation Solution
Implementing micro-segmentation through a dynamic and automated approach that uses clustering algorithms to detect virtual machine groups based on application implementation information, creating logical network segments and enforcing security policies to isolate and secure east-west traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If perimeter security solutions are used to inspect north-south traffic, then external threats are blocked, but east-west traffic within the data center remains unsecured and vulnerable to lateral threats
Solution Approach 1:
The patent divides the data center network into multiple micro-segments at the virtual machine level, creating fine-grained security zones. Each virtual machine or group of virtual machines becomes an isolated segment with its own security policies, enabling inspection and control of east-west traffic between segments while maintaining overall network security architecture.
Solution Approach 2:
The patent introduces a new dimension of security by moving from traditional perimeter-based security (north-south traffic) to internal micro-segmentation security (east-west traffic). This dimensional shift allows security policies to be applied at the virtual machine level within the data center, complementing existing perimeter security rather than replacing it.
2Reliability
If micro-segmentation is implemented to secure east-west traffic, then internal device protection is improved, but system complexity increases due to dynamic segmentation and policy management
Solution Approach 1:
The patent implements automated clustering algorithms that dynamically form micro-segments based on application implementation information and communication patterns. The system self-organizes virtual machines into security segments without manual intervention, and automatically generates and enforces security policies, reducing the operational complexity despite the increased segmentation granularity.
Solution Approach 2:
The patent dynamically adjusts security segmentation parameters based on changing application requirements and communication patterns. The clustering algorithm continuously monitors and reconfigures micro-segments according to actual traffic patterns, allowing the system to adapt to parameter changes in application behavior without requiring manual reconfiguration of security policies.
3Measurement precision
If dynamic clustering algorithms are used to detect virtual machine groups, then security segmentation accuracy is improved, but computational overhead and processing time increase
Solution Approach 1:
The patent performs clustering analysis on application implementation information collected during normal operation to pre-determine micro-segment groupings. By analyzing communication patterns and application relationships in advance, the system establishes security segments before threats occur, enabling rapid policy enforcement without real-time computational delays during security events.
Solution Approach 2:
The patent implements continuous monitoring of east-west traffic patterns and communication behavior within micro-segments. The clustering algorithm uses feedback from observed traffic patterns to refine and adjust segment groupings, improving segmentation accuracy over time while learning from actual data center operations to reduce computational overhead in subsequent clustering cycles.
Data Source
AI summary
Example methods are provided for an entity to perform micro-segmentation in a virtualized computing environment that includes multiple hosts. The method may comprise obtaining application implementation information associated with one or more applications implemented by multiple virtualized computing instances, each of the multiple virtualized computing instances being supported by one of the multiple hosts. The method may further comprise detecting micro-segments by clustering the multiple virtualized computing instances based on the application implementation information, and determining security policies for respective detected micro-segments. Each of the detected micro-segments may include one or more of the multiple virtualized computing instances that have more similarity compared to those in a different detected micro-segment.


