Visual Data Flow Analysis for SDDC Security Posture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software-defined data centers (SDDCs) face challenges in analyzing fragmented data, making it difficult for users to assess and visualize their security posture effectively.

Innovation Solution

A method is introduced that collects and reports attributes of data flows from machines executing on host computers, using a logical network managed by a virtualization manager, and processes this data through a policy, analytics, and correlation engine appliance for analysis and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If data is collected from multiple sources and aggregated, then the comprehensiveness of security analysis is improved, but the complexity of data processing increases

Engineering Contradiction:
Improvecompleteness of security dataVSAvoiddata processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments the data collection and processing system into distinct functional components: flow exporters on host computers collect flow data, context exporters collect contextual information, and these are processed separately before being aggregated at the analysis appliance. This segmentation allows each component to handle specific data types efficiently, reducing overall processing complexity while maintaining data completeness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including flow collectors that aggregate flow data from multiple sources, context exporters that collect contextual information, and correlation engines that match flow records with contextual data. These intermediaries simplify the processing architecture by handling data aggregation and correlation tasks, reducing the complexity burden on the main analysis appliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If detailed flow data and context data are collected and correlated, then the precision of security analysis is improved, but the time required for data processing increases

Engineering Contradiction:
Improveaccuracy of security assessmentVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-collecting and pre-processing flow data and contextual information before security analysis is needed. Flow exporters continuously collect flow records, and context exporters gather contextual data in advance, storing them in buffers and data structures. When security analysis is required, the correlation engine can quickly match and correlate pre-prepared data, significantly reducing processing time while maintaining high accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies parameter changes by dynamically adjusting data collection and processing parameters based on system conditions. The flow collector and context exporter can modify sampling rates, aggregation intervals, and correlation thresholds to balance analysis precision with processing time requirements, allowing the system to adapt to different security monitoring scenarios.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240004689A1Recommendation generation based on selection of selectable elements of visual representation
Publication Date: 2024.01.04 VMWARE INC
  • US20240004689A1 patent drawing
  • US20240004689A1 patent drawing
  • US20240004689A1 patent drawing

AI summary

Some embodiments provide a novel method for collecting and reporting attributes of data flows associated with machines executing on a plurality of host computers to an analysis appliance and providing visual representations of the data to a user. Some embodiments provide a visual representation of the collected data that allows a user to select a set of machines and flows and initiate recommendation generation based on the selected machines and flows. The recommendation generation, in some embodiments, includes identifying flows for which rules have not been defined and filtering the identified rules to remove flows for which rules should not be defined. Some embodiments use the identified rues to identify services and groups associated with the rules and generate recommendations for rules, groups and services based on the identified flows, groups and services. The recommendations, in some embodiments, are implemented as a single PATCH API.