Adaptive Session Forwarding for VM Migration Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtual machine live migration disrupts data connections due to the disconnection from security devices like firewalls, and existing methods rely on inefficient virtual machine management system APIs, which are not practical for continuous operation.
Innovation Solution
A mechanism that detects network events during virtual machine migration, allowing security session forwarding to be modified by network security devices without relying on virtual machine management systems, ensuring continuous data operation by routing packets to the new location.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If virtual machine live migration is detected by querying virtual machine management system APIs, then migration information can be obtained, but the system complexity increases and efficiency decreases due to constant connections required
Solution Approach 1:
The patent extracts the detection function from the virtual machine management system by having network security devices independently detect migration through network traffic analysis. This removes the dependency on management system APIs and constant connections, reducing system complexity while maintaining detection capability.
Solution Approach 2:
Network security devices perform self-service detection by monitoring network traffic patterns themselves rather than relying on external management system queries. This autonomous detection approach eliminates the need for constant connections to management systems while maintaining reliable migration detection.
2Reliability
If security session forwarding is not updated during virtual machine migration, then security policies remain consistent, but data connections are interrupted and traffic stops
Solution Approach 1:
The patent implements feedback by having network security devices monitor network traffic to detect migration events, then automatically update security session forwarding based on detected migration. This closed-loop approach maintains connection continuity by responding to migration events while keeping session management automated rather than manually complex.
Solution Approach 2:
The patent performs preliminary action by pre-establishing security session forwarding rules that can be quickly updated upon migration detection. This allows seamless transition during migration by having forwarding rules ready to be activated, maintaining connection continuity without complex real-time negotiation.
3Adaptability or versatility
If virtual machine migration is detected through network events, then dependency on centralized management systems is reduced, but detection precision may be affected
Solution Approach 1:
The patent uses network traffic patterns as an intermediary to detect virtual machine migration. By analyzing traffic characteristics, source/destination addresses, and flow patterns, the system achieves independent detection while maintaining precision through multiple correlation checks of network event data.
Solution Approach 2:
The patent monitors changes in network traffic parameters such as source IP addresses, destination IP addresses, port assignments, and traffic flow patterns to detect migration. By tracking multiple parameter changes simultaneously, the system achieves both independence from management systems and high detection precision through correlated parameter analysis.
Data Source
AI summary
A network system includes a first network access device having an input/output (IO) module of a firewall to capture a packet of a network session originated from a first node associated with the first network access device, a first security device having a firewall processing module to determine based on the captured packet whether the first node is a destination node that is receiving VM migration from a second node that is associated with a second network access device. The first security device is to update a first flow table within the first network access device. The network system further includes a second security device to receive a message from the first security device concerning the VM migration to update a second flow table of the second network access device, such that further network traffic of the network session is routed to the first node without interrupting the network session.


