Security-Aware Virtual Machine Scheduling and Placement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face inefficiencies in applying network security rules due to the distribution of virtual machines (VMs) across multiple hosts, which increases the time and resources required to implement and operationalize these rules.
Innovation Solution
A system and method for security-aware scheduling and migration that groups VMs with shared security policies on the same host, utilizing a push-pull mechanism to enable real-time VM placement and security configuration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If VMs are distributed across multiple hosts, then resource utilization is improved, but the time and resources required to apply network security rules increase
Solution Approach 1:
The patent applies segmentation by categorizing VMs into different security groups based on their security policy requirements. VMs with the same security policy are segmented into the same group and placed on the same host, while VMs with different policies are separated. This segmentation enables efficient application of security rules to groups rather than individual VMs across multiple hosts.
Solution Approach 2:
The patent merges VMs that share the same security policy onto the same host. By combining multiple VMs with identical security requirements into a single host, the system reduces the number of hosts that need to be configured with security rules, thereby decreasing the time and resources required to apply network security policies while maintaining effective security coverage.
2Loss of time
If VMs with the same security policy are placed on the same host, then the time to apply security rules is reduced, but the flexibility of VM placement is reduced
Solution Approach 1:
The patent implements dynamic VM placement by continuously monitoring host availability, security policy requirements, and resource capacity. The system can dynamically adjust VM placements based on changing conditions, such as host failures, security policy updates, or resource availability. This dynamic approach maintains placement flexibility while ensuring that VMs with the same security policy are co-located on the same host when possible.
Solution Approach 2:
The patent changes the parameters of VM placement by introducing security policy categorization as a primary placement criterion. Instead of using only resource-based placement parameters, the system incorporates security policy matching as a key parameter, allowing VMs with identical security requirements to be grouped together. This parameter change enables faster security rule application while maintaining adaptability through flexible reconfiguration capabilities.
3Quantity of substance
If multiple hosts are used to host VMs, then resource capacity is increased, but the complexity of managing security policies increases
Solution Approach 1:
The patent applies universality by creating a unified security policy management system that can manage security rules across multiple hosts through a single interface. The system provides multi-functional capabilities including automated VM categorization, intelligent host selection, and centralized security policy deployment. This universal approach allows the system to manage security policies across multiple hosts without increasing operational complexity, as the same management mechanisms work consistently regardless of the number of hosts involved.
Data Source
AI summary
An illustrative embodiment disclosed herein is an apparatus including a processor and a memory. In some embodiments, the memory includes programmed instructions that, when executed by the processor, cause the apparatus to apply a category to a first virtual machine (VM) and a second VM, schedule the first VM and the second VM to be placed on a host at least based on the first VM and the second VM including the category, and apply a security policy to the first VM and the second VM at least based on the first VM and the second VM including the category.


