Visual Data Flow Analysis for SDDC Security Posture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.
Innovation Solution
A method is introduced that collects and reports attributes of data flows from machines executing on host computers, using a logical network managed by a virtualization manager, and processes this data through a policy, analytics, and correlation engine appliance for analysis and visualization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If data is collected from multiple sources and aggregated, then the comprehensiveness of security analysis is improved, but the complexity of data processing increases
Solution Approach 1:
The patent segments the data collection and processing system into distinct functional components: flow exporters on host computers collect flow data, context exporters collect contextual information, and these are processed separately before being aggregated at the analysis appliance. This segmentation allows each component to handle specific data types efficiently, reducing overall processing complexity while maintaining data completeness.
Solution Approach 2:
The patent introduces intermediary components including flow collectors that aggregate flow data from multiple sources, context exporters that collect contextual information, and correlation engines that match flow records with contextual data. These intermediaries simplify the processing architecture by handling data aggregation and correlation tasks, reducing the complexity burden on the main analysis appliance.
2Measurement precision
If detailed flow data and context data are collected and correlated, then the precision of security analysis is improved, but the time required for data processing increases
Solution Approach 1:
The patent implements preliminary action by pre-collecting and pre-processing flow data and contextual information before security analysis is needed. Flow exporters continuously collect flow records, and context exporters gather contextual data in advance, storing them in buffers and data structures. When security analysis is required, the correlation engine can quickly match and correlate pre-prepared data, significantly reducing processing time while maintaining high accuracy.
Solution Approach 2:
The patent applies parameter changes by dynamically adjusting data collection and processing parameters based on system conditions. The flow collector and context exporter can modify sampling rates, aggregation intervals, and correlation thresholds to balance analysis precision with processing time requirements, allowing the system to adapt to different security monitoring scenarios.
Data Source
AI summary
Some embodiments provide a novel method for collecting and reporting attributes of data flows associated with machines executing on a plurality of host computers to an analysis appliance and providing visual representations of the data to a user. Some embodiments provide a visual representation of the collected data that allows a user to select a set of machines and flows and initiate recommendation generation based on the selected machines and flows. The recommendation generation, in some embodiments, includes identifying flows for which rules have not been defined and filtering the identified rules to remove flows for which rules should not be defined. Some embodiments use the identified rues to identify services and groups associated with the rules and generate recommendations for rules, groups and services based on the identified flows, groups and services. The recommendations, in some embodiments, are implemented as a single PATCH API.


