Virtual Network Segmentation via Traffic Pattern Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual configuration of virtual network segmentation in complex computer systems is cumbersome and error-prone, requiring detailed knowledge and increasing with system size and complexity, leading to issues like blocked communications and degraded user experience.

Innovation Solution

A system that monitors communications and dependencies to automatically segment virtual networks, instances, and applications, grouping them based on traffic patterns and refining segmentations dynamically, with options for varying security levels and policies based on time, data sensitivity, and intrusion risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of virtual network segmentation is performed, then security isolation and resource separation are improved, but system complexity and configuration difficulty increase significantly

Engineering Contradiction:
Improvesecurity isolationVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically analyzing communication patterns between virtual machine instances and generating segmentation configurations without requiring manual administrator intervention. The segmentation service monitors network traffic, identifies communication dependencies, and autonomously creates routing rules to segment the virtual network according to actual usage patterns.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring network communications and using this information to dynamically adjust segmentation configurations. The segmentation service receives feedback about communication patterns and modifies routing rules to optimize security isolation while maintaining necessary communications, resolving the contradiction between security and complexity.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If manual configuration of routing rules is performed for intercommunication, then communication control is improved, but error rate and blocked communications increase

Engineering Contradiction:
Improvecommunication controlVSAvoidcommunication reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system replaces the mechanical manual configuration process with an automated computational system. Instead of administrators manually analyzing and configuring routing rules, the segmentation service uses algorithms to analyze communication patterns and automatically generate routing configurations, eliminating human errors while maintaining communication control.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The segmentation service acts as an intermediary between virtual machine instances and the virtual network infrastructure. It monitors communications between instances and automatically configures routing rules to enable necessary communications while blocking unauthorized ones, improving both ease of operation and communication reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If automatic segmentation based on communication monitoring is implemented, then segmentation accuracy and security are improved, but system resource consumption increases

Engineering Contradiction:
Improvesegmentation accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies partial action by monitoring and analyzing only the necessary communication patterns required for segmentation decisions, rather than analyzing all possible network traffic. The segmentation service focuses on identifying communication dependencies between virtual machine instances and configures segmentation based on these essential patterns, achieving accurate segmentation with reduced computational overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10476738B1Virtual network segmentation
Publication Date: 2019.11.12 AMAZON TECH INC
  • US10476738B1 patent drawing
  • US10476738B1 patent drawing
  • US10476738B1 patent drawing

AI summary

Techniques for segmenting a network are described herein. Network locations in a network are grouped such that each group is disjoint with respect to all other groups. The grouping is based on a set of network communication event notifications. The network communication event notifications are used to determine internal and external dependencies for each group and the external and internal dependencies are used to segment the network.