Network Visualization Aggregation for Security Group Definition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current visualizations of network flows do not scale well for large amounts of data, making it difficult for users to define security groups and firewall rules, particularly in micro-segmentation of network environments, as they lack intuitive formats for analyzing and presenting large data sets.

Innovation Solution

A network visualization application that aggregates network flows by data compute nodes and security groups, providing a scalable and filterable user interface to visualize and define security groups, allowing users to drill down into details, view multiple DCNs, and filter flows by type, with recommendations for new security groups and rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If traditional network flow visualization methods are used, then individual flows can be displayed, but the visualization does not scale for large amounts of data and creates clutter

Engineering Contradiction:
Improvenumber of DCNs displayedVSAvoidvisualization complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent merges multiple individual network flows into aggregated flow representations. Instead of displaying each flow separately, flows are grouped and combined into summary visualizations that show collective traffic patterns between security groups, dramatically reducing visual clutter while preserving essential information about network traffic volume and patterns

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the network visualization into hierarchical levels: individual DCNs, security groups, and aggregated flow summaries. This segmentation allows users to navigate from high-level aggregated views down to individual flow details as needed, enabling the system to handle large numbers of DCNs without overwhelming the user with detail at all times

Inventive Principle:
Principle #1Segmentation

2Loss of information

If detailed individual flow information is displayed for all DCNs, then complete network visibility is achieved, but the interface becomes cluttered and difficult to analyze

Engineering Contradiction:
Improvenetwork flow information completenessVSAvoidease of analysis
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent implements dynamic visualization that adapts to user interaction and data volume. The system dynamically aggregates flows at appropriate levels based on the number of DCNs and security groups present, and dynamically responds to user drilling-down actions to reveal detailed information only when and where needed, maintaining ease of analysis while preserving complete information access

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent adds hierarchical dimensionality to the visualization, organizing flows not just by individual connections but by security group aggregations and traffic patterns. This dimensional organization allows information to be presented in structured layers, making large datasets analyzable while maintaining completeness through drill-down capabilities

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If security groups and firewall rules are manually defined without automation, then customization is possible, but user effort and time are significantly increased

Engineering Contradiction:
Improvesecurity configuration flexibilityVSAvoidtime to define security groups
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of network flows and security requirements automatically, preparing recommended security group configurations and firewall rules before user review. This preliminary automation reduces the time users spend on manual definition while preserving flexibility, as users can review and customize the pre-analyzed recommendations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11588854B2User interface for defining security groups
Publication Date: 2023.02.21 VMWARE INC
  • US11588854B2 patent drawing
  • US11588854B2 patent drawing
  • US11588854B2 patent drawing

AI summary

Some embodiments provide a method for defining security groups in a network. In a user interface, the method displays (i) a set of existing security groups and (ii) a set of recommend security groups based on monitored network flows in the network. Each existing security group and recommended security group includes at least one data compute node (DCN). The method provides a user interface tool for (i) accepting recommended security groups to be part of the set of existing security groups and (ii) adding DCNs from the recommended security groups to the existing security groups. Security rules are defined and implemented in the network for DCNs belonging to existing security groups.