Virtual Machine Network Traffic Management via Application Firewall Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtual desktop environments, managing network traffic for virtual machines is challenging due to the difficulty in configuring firewalls and network management resources, especially when different applications are attached and made available based on the current user allocated to the virtual machine.

Innovation Solution

A method is implemented to enhance network traffic management by identifying applications available on virtual machines, determining firewall rules for these applications, and enforcing these rules at virtual network interface cards (VNICs) to permit or block communications, ensuring only administrator-approved traffic is forwarded.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If application volumes are attached to virtual machines to provide different applications to different users, then application availability and user-specific functionality are improved, but network traffic management complexity and firewall configuration difficulty increase

Engineering Contradiction:
Improveapplication availabilityVSAvoidnetwork traffic management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments network traffic management by creating application-specific firewall rules that are associated with individual applications or application volumes. This allows the firewall to handle each application's traffic independently rather than managing all traffic uniformly, thereby reducing overall management complexity while maintaining high adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic firewall rule application where rules are automatically applied or removed based on the attachment state of application volumes. When an application volume is attached to a virtual machine, the corresponding firewall rules are activated; when detached, the rules are deactivated. This dynamic approach adapts to changing configurations without requiring manual intervention.

Inventive Principle:
Principle #15Dynamics

2Reliability

If firewall rules are configured for each application to enable precise network traffic control, then security is improved, but configuration time and administrative overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent employs preliminary action by pre-configuring firewall rules for applications before they are attached to virtual machines. The firewall rules are prepared in advance and stored in the system, ready to be automatically applied when an application volume is mounted. This eliminates the need for manual firewall configuration at the time of application deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service by automatically applying the appropriate firewall rules when an application volume is attached to a virtual machine. The attachment process itself triggers the firewall rule application without requiring administrator intervention. The system autonomously manages the correlation between applications and their security policies.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If manual firewall configuration is used for each virtual machine, then flexibility in customizing network policies is improved, but ease of operation deteriorates due to the need to manually update rules when applications are attached or detached

Engineering Contradiction:
Improvenetwork policy customizationVSAvoidease of configuration
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements feedback by monitoring the attachment state of application volumes to virtual machines and automatically adjusting firewall rules based on this feedback. When the system detects that an application volume has been attached or detached, it automatically updates the firewall configuration accordingly. This closed-loop approach maintains flexibility while eliminating manual operational burdens.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary mechanism that bridges application volume management and firewall configuration. This intermediary automatically translates application attachment events into corresponding firewall rule applications, serving as a mediator between the application layer and network security layer. This eliminates the need for direct manual configuration while preserving policy customization capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11394689B2Application based network traffic management
Publication Date: 2022.07.19 VMWARE INC
  • US11394689B2 patent drawing
  • US11394689B2 patent drawing
  • US11394689B2 patent drawing

AI summary

Described herein are systems, methods, and software to enhance network traffic management for virtual machines. In one implementation, a host for a virtual machine may identify applications available for execution on the virtual machine from mounted application volumes and identify firewall rules for the applications. Once identified, the host may identify network traffic for the virtual machine, and forward or block the network traffic for the virtual machine based on the firewall rules.