Visual Security Policy Creation in Virtualized Clusters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The process of configuring security policies in virtualized computing systems is time-consuming, error-prone, and poses scalability issues due to the manual configuration of parameters and the need for multiple administrators, especially in dynamic environments where user access and application types change frequently, leading to potential security breaches and degraded user experience.

Innovation Solution

A visual approach using a graphical user interface to create and manage security policies in a clustered virtualization environment, where security policies are configured based on inbound and outbound rules, with a whitelist model ensuring only permitted connections between categorized virtual machines, and providing a visual representation of policy enforcement and violations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of security policies is performed by multiple administrators, then security policies can be enforced on network devices, but the process becomes time-consuming and complex

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidpolicy configuration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service automation where the security policy management system automatically configures and enforces security policies without requiring manual intervention from multiple administrators. The system autonomously performs tasks such as identifying applications, determining security requirements, and configuring network devices, thereby eliminating the time-consuming manual coordination between IT administrators, network administrators, and security administrators while maintaining reliable security enforcement

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring security policies and rules before they are needed. The system proactively identifies applications, determines their security requirements in advance, and prepares security policies beforehand. This allows the system to rapidly enforce security policies when needed without requiring time-consuming manual configuration processes to occur at the moment of deployment

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual configuration of security policies is performed, then security parameters can be set, but errors increase and vulnerability to security breaches rises

Engineering Contradiction:
Improvesecurity policy accuracyVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automates the complex process of security policy configuration through self-service mechanisms. It automatically identifies applications, determines security requirements, generates appropriate security policies, and configures network devices without manual intervention. This automation eliminates human errors associated with manual configuration while managing the complexity internally, presenting a simplified interface to users while maintaining high security accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system acts as an intermediary between security requirements and network device configuration. It translates high-level security requirements into detailed configuration parameters for network devices, switches, and routers. This intermediary layer manages the complexity of security policy configuration by providing abstraction, ensuring accurate translation of security intent into technical configurations without exposing users to the underlying complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security policies are manually configured, then policies can be applied to applications, but scalability is limited as users and policies change frequently

Engineering Contradiction:
Improvesecurity policy applicationVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic security policy management that automatically adapts to changing conditions. It continuously monitors the virtualized computing environment, detects new applications and users, and automatically updates security policies in real-time. This dynamic approach enables the system to scale efficiently as users join or leave the enterprise and as new applications are deployed, maintaining reliable security enforcement without manual reconfiguration

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system provides self-service automation for scaling security policies. When new users, applications, or devices are added to the environment, the system automatically detects these changes and generates appropriate security policies without human intervention. This self-service capability enables seamless scaling of security coverage across the enterprise, maintaining policy consistency and reliability regardless of the number of users or applications

Inventive Principle:
Principle #25Self-service

4Reliability

If different types of policy language are required for different application types, then security policies can be tailored to specific applications, but the configuration process becomes more complicated

Engineering Contradiction:
Improveapplication-specific securityVSAvoidpolicy language complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements a universal security policy framework that can handle multiple application types through a single unified interface. It provides multi-functionality by automatically detecting the application type (file server, video conferencing, web-scale, etc.) and selecting the appropriate security policy template or language internally. This universal approach maintains application-specific security requirements while presenting a consistent, simplified configuration experience to users, eliminating the need for them to learn different policy languages for different applications

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11057432B2Creation of security policies using a visual approach
Publication Date: 2021.07.06 NUTANIX INC
  • US11057432B2 patent drawing
  • US11057432B2 patent drawing
  • US11057432B2 patent drawing

AI summary

A request to create a set of security policies for an application is received at a graphical user interface. Information identifying a set of source VMs, a set of destination VMs, and a set of target VMs also are received, wherein the target VMs are executing the application and are supported by (a) node(s) in a clustered virtualization environment. A set of inbound rules identifying (a) category(ies) of source VMs permitted to initiate connections with a subset of target VMs and a set of outbound rules identifying (a) category(ies) of destination VMs to which the subset of target VMs are permitted to initiate connections are received at the graphical user interface. Upon receiving a request to apply the security policies, the policies are configured based at least in part on the inbound and outbound rules and a visual representation of the security policies is presented in the graphical user interface.