Automatic Workload Segmentation for Data Center Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and securing large and complex data centers with multiple interconnected applications is challenging due to the difficulty in configuring, managing, and segmenting workloads effectively.

Innovation Solution

An apparatus and method that automatically segment workloads into groups based on communication connection attributes using a processor and software agents, clustering workloads into tiers and applications by analyzing similarity and variance measures in communication connections, and assigning weights to edges in a graph representation of the computing system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data centers run multiple interconnected applications with large numbers of machines, then application functionality and processing capacity are improved, but system complexity and difficulty of configuration and management increase

Engineering Contradiction:
Improveapplication processing capacityVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the complex data center system into multiple independent application groups, where each group contains workloads that collectively run a specific application. This segmentation is achieved by analyzing communication connection attributes and clustering workloads based on their interaction patterns. By dividing the large interconnected system into smaller, isolated application groups, the patent reduces overall system complexity while preserving the processing capacity of multiple applications running concurrently.

Inventive Principle:
Principle #1Segmentation

2Quantity of substance

If the number of virtual machines and applications in a data center increases, then computing power and application diversity are improved, but the difficulty of securing and managing the system increases

Engineering Contradiction:
Improvenumber of virtual machinesVSAvoidease of management
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent divides the large number of virtual machines into smaller groups, where each group corresponds to a specific application. This segmentation allows administrators to manage and secure each application group independently rather than managing all virtual machines as a single complex system, thereby improving ease of operation while maintaining the ability to run many virtual machines.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary system that automatically discovers application groups by analyzing communication connection attributes between virtual machines. This intermediary automation layer mediates between the large number of virtual machines and the administrators, eliminating the need for manual configuration and management of each individual machine, thus improving ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If workloads are manually configured and managed, then control and security are improved, but time consumption and operational complexity increase

Engineering Contradiction:
Improvesecurity controlVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables the system to automatically discover and segment application groups by analyzing communication connection attributes among workloads. This self-service approach eliminates the need for manual configuration by administrators, significantly reducing time consumption. The automatic segmentation maintains security control by creating isolated groups that can be managed with appropriate access controls, while the system performs the complex analysis and grouping operations autonomously.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10853143B2Automatic segmentation of data-center applications
Publication Date: 2020.12.01 AKAMAI TECHNOLOGIES INC
  • US10853143B2 patent drawing
  • US10853143B2 patent drawing
  • US10853143B2 patent drawing

AI summary

An apparatus includes an interface and a processor. The interface is configured to receive attributes of communication connections of multiple workloads running in a computing system. The processor is configured to automatically segment the multiple workloads into groups based on the attributes of the communication connections, wherein the workloads in each group collectively run a respective application.