Virtual Switch Security Inspection via Direct Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for network-security inspection in virtualized environments are complex to provision and can be easily compromised, lacking effective and efficient solutions for securing virtual network traffic.

Innovation Solution

The method involves 'hooking' into virtual network links using virtualization vendors' APIs to intercept and inspect all virtual network traffic through security agents attached to each port of a virtual switch, bypassing the virtual switch for direct inspection and transmission, enabling fast and secure security processing with minimal overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a firewall is added as a virtual machine with all traffic passing through it, then network security inspection is provided, but the provisioning becomes complicated and the system can be easily defeated if network configuration is modified

Engineering Contradiction:
Improvenetwork security inspectionVSAvoidprovisioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a virtual switch as an intermediary component that sits between virtual machines and the physical network. The virtual switch handles traffic forwarding and security inspection centrally, eliminating the need for complex firewall virtual machine provisioning. Security policies are enforced at the virtual switch level, providing reliable security inspection without complicating the overall system provisioning.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a firewall virtual machine is used for security inspection, then security coverage is provided, but the inspection performance is slow and requires special agents

Engineering Contradiction:
Improvesecurity coverageVSAvoidinspection performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the security inspection function from the virtual machine level and moves it to the virtual switch level. By taking out the security processing from individual VM firewalls and centralizing it at the virtual switch, the system achieves both comprehensive security coverage and high inspection performance without requiring special agents on each security virtual machine.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The virtual switch is designed to perform multiple functions simultaneously: traffic forwarding, security inspection, and packet filtering. This multi-functional approach eliminates the need for separate firewall virtual machines and special agents, providing universal security coverage across all VMs while maintaining high inspection performance through centralized processing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traffic is forwarded through a special channel for security inspection, then security processing is enabled, but the forwarding speed decreases and special agents are required

Engineering Contradiction:
Improvesecurity processingVSAvoidtraffic forwarding speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent merges the security inspection function with the existing virtual switch infrastructure. Instead of creating separate special channels for security processing, the virtual switch integrates security policies into its normal traffic forwarding path. This combining approach enables security processing without sacrificing forwarding speed, as the virtual switch handles both functions through its optimized switching architecture.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9672189B2Methods for effective network-security inspection in virtualized environments
Publication Date: 2017.06.06 CHECK POINT SOFTWARE TECH LTD
  • US9672189B2 patent drawing
  • US9672189B2 patent drawing
  • US9672189B2 patent drawing

AI summary

The present invention discloses methods for effective network-security inspection in virtualized environments, the methods including the steps of: providing a data packet, embodied in machine-readable signals, being sent from a sending virtual machine to a receiving virtual machine via a virtual switch; intercepting the data packet by a sending security agent associated with the sending virtual machine; injecting the data packet into an inspecting security agent associated with a security virtual machine via a direct transmission channel which bypasses the virtual switch; forwarding the data packet to the security virtual machine by employing a packet-forwarding mechanism; determining, by the security virtual machine, whether the data packet is allowed for transmission; upon determining the data packet is allowed, injecting the data packet back into the sending security agent via the direct transmission channel; and forwarding the data packet to the receiving virtual machine via the virtual switch.