Network Visualization Aggregation for Security Group Definition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current visualizations of network flows do not scale well for large amounts of data, making it difficult for users to define security groups and firewall rules, particularly in micro-segmentation of network environments, as they lack intuitive formats for analyzing and presenting large data sets.
Innovation Solution
A network visualization application that aggregates network flows by data compute nodes and security groups, providing a scalable and filterable user interface to visualize and define security groups, allowing users to drill down into details, view multiple DCNs, and filter flows by type, with recommendations for new security groups and rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If traditional network flow visualization methods are used, then individual flows can be displayed, but the visualization does not scale for large amounts of data and creates clutter
Solution Approach 1:
The patent merges multiple individual network flows into aggregated flow representations. Instead of displaying each flow separately, flows are grouped and combined into summary visualizations that show collective traffic patterns between security groups, dramatically reducing visual clutter while preserving essential information about network traffic volume and patterns
Solution Approach 2:
The patent segments the network visualization into hierarchical levels: individual DCNs, security groups, and aggregated flow summaries. This segmentation allows users to navigate from high-level aggregated views down to individual flow details as needed, enabling the system to handle large numbers of DCNs without overwhelming the user with detail at all times
2Loss of information
If detailed individual flow information is displayed for all DCNs, then complete network visibility is achieved, but the interface becomes cluttered and difficult to analyze
Solution Approach 1:
The patent implements dynamic visualization that adapts to user interaction and data volume. The system dynamically aggregates flows at appropriate levels based on the number of DCNs and security groups present, and dynamically responds to user drilling-down actions to reveal detailed information only when and where needed, maintaining ease of analysis while preserving complete information access
Solution Approach 2:
The patent adds hierarchical dimensionality to the visualization, organizing flows not just by individual connections but by security group aggregations and traffic patterns. This dimensional organization allows information to be presented in structured layers, making large datasets analyzable while maintaining completeness through drill-down capabilities
3Adaptability or versatility
If security groups and firewall rules are manually defined without automation, then customization is possible, but user effort and time are significantly increased
Solution Approach 1:
The system performs preliminary analysis of network flows and security requirements automatically, preparing recommended security group configurations and firewall rules before user review. This preliminary automation reduces the time users spend on manual definition while preserving flexibility, as users can review and customize the pre-analyzed recommendations
Data Source
AI summary
Some embodiments provide a method for defining security groups in a network. In a user interface, the method displays (i) a set of existing security groups and (ii) a set of recommend security groups based on monitored network flows in the network. Each existing security group and recommended security group includes at least one data compute node (DCN). The method provides a user interface tool for (i) accepting recommended security groups to be part of the set of existing security groups and (ii) adding DCNs from the recommended security groups to the existing security groups. Security rules are defined and implemented in the network for DCNs belonging to existing security groups.


