Security Policy Recommendation Generation via Flow Data Aggregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.

Innovation Solution

A method for collecting and reporting attributes of data flows across host computers, utilizing a logical network managed by a virtualization manager, which aggregates and processes data through a policy, analytics, and correlation engine appliance for analysis and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If data is collected from multiple host computers and aggregated through a policy analytics and correlation engine appliance, then comprehensive data analysis and visualization capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity posture assessment capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent introduces a policy analytics and correlation engine appliance as an intermediary component that collects data from multiple host computers, aggregates flow data and context data, and provides comprehensive analysis capabilities. This intermediary handles the complexity of data collection and analysis, making the security posture assessment capability available without requiring each individual system to implement complex analysis functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent combines multiple data sources (flow data from network traffic and context data from host computers) into a unified analysis platform. The policy analytics and correlation engine appliance merges these diverse data types and processes them together to provide comprehensive security posture assessment, visualization, and anomaly detection capabilities.

Inventive Principle:
Principle #5Merging (Combining)

2Loss of information

If flow data and context data are aggregated from multiple sources, then data completeness is improved, but data processing complexity increases

Engineering Contradiction:
Improvedata completenessVSAvoiddata processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments data collection into two distinct types: flow data collected from network traffic and context data collected from host computers. This segmentation allows each data type to be collected and processed through specialized mechanisms, reducing the overall processing complexity while maintaining data completeness. The policy analytics and correlation engine appliance handles both segmented data types in a structured manner.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11349876B2Security policy recommendation generation
Publication Date: 2022.05.31 VMWARE INC
  • US11349876B2 patent drawing
  • US11349876B2 patent drawing
  • US11349876B2 patent drawing

AI summary

Some embodiments provide a novel method for collecting and reporting attributes of data flows associated with machines executing on a plurality of host computers to an analysis appliance and providing visual representations of the data to a user. Some embodiments provide a visual representation of the collected data that allows a user to select a set of machines and flows and initiate recommendation generation based on the selected machines and flows. The recommendation generation, in some embodiments, includes identifying flows for which rules have not been defined and filtering the identified rules to remove flows for which rules should not be defined. Some embodiments use the identified rues to identify services and groups associated with the rules and generate recommendations for rules, groups and services based on the identified flows, groups and services. The recommendations, in some embodiments, are implemented as a single PATCH API.