Security context aware nano-segmentation for container based microservices

    公开(公告)号:US11343231B2

    公开(公告)日:2022-05-24

    申请号:US16547634

    申请日:2019-08-22

    Applicant: VMWARE, INC.

    Abstract: The present disclosure provides an approach for creating one or more firewall rules to regulate communication between containers. The approach includes calculating a trust score for each container. To generate a rule for any two containers, a difference between the trust scores is computed, and if the difference in trust levels is too large, then the more trustworthy container is not allowed to communicate with the less trustworthy container. If the difference in trust scores is not too large, then the trustworthy container is allowed to communicate with the other trustworthy container, or an untrustworthy container is allowed to communicate with another untrustworthy container.

    Recommending network NANO-segmentation for micro-services using flow analysis

    公开(公告)号:US11483284B2

    公开(公告)日:2022-10-25

    申请号:US16436930

    申请日:2019-06-11

    Applicant: VMWARE, INC.

    Abstract: The present disclosure provides an approach for generating one or more firewall rules to regulate communication between containerized services running within containers. The approach includes determining which services communicate with each other, independently of in which containers the services execute. The determining occurs over a period of time. If two services communicated with each other during the period of time, then the firewall allows the services to continue communicating, but only over the same ports as used during the period of time. If two services did not communicate during the period of time, then the firewall does not allow the services to communicate after the expiration of the period of time. In some embodiments, redetermining the communication flow over a new period of time may occur after the initial period of time so as to refresh the firewall rules.

    Datacenter operations using search and analytics

    公开(公告)号:US09767197B1

    公开(公告)日:2017-09-19

    申请号:US14464579

    申请日:2014-08-20

    Applicant: VMWARE, INC.

    CPC classification number: G06F17/30864

    Abstract: A datacenter management system uses data collection proxies to collect performance data and configuration data for different physical and virtual entities in the datacenter. A schema is used to represent the different entities, entity relationships, and entity properties in the datacenter. A search engine identifies the intent of a natural language based search query based on the schema and a datacenter dictionary. The search engine then searches the data based on the search query intent. A dictionary manager converts both periodic and aperiodic data into a time series. This allows the search engine to operate as a time machine identifying both performance data and configuration data for any selectable time period.

    Datacenter search query interpretation system

    公开(公告)号:US10198511B1

    公开(公告)日:2019-02-05

    申请号:US14592845

    申请日:2015-01-08

    Applicant: VMWARE, INC.

    Abstract: A computerized datacenter contextual search query interpretation method includes receiving a search query from a user; displaying search suggestions based on the search query and obtaining a selected one of the search suggestions. Any time period associated with the search query is identified, instructions based on the selected search suggestion and any time period for searching a data model of a datacenter are generated to obtain search results and display a graphical visualization of the search results.

    Datacenter entity information system

    公开(公告)号:US09886445B1

    公开(公告)日:2018-02-06

    申请号:US14592893

    申请日:2015-01-08

    Applicant: VMWARE, INC.

    Abstract: A computerized datacenter entity information method includes obtaining datacenter entity information at an initial time, compressing and storing the datacenter entity information as a datacenter entity frame of reference, obtaining datacenter entity information changes, and compressing and storing the datacenter entity information changes with respect to the datacenter entity frame of reference. In another implementation, the computerized datacenter entity information method includes obtaining datacenter entity information at an initial time, compressing and storing the datacenter entity information as a datacenter entity frame of reference, obtaining datacenter entity information changes, and compressing and storing the datacenter entity information changes with respect to the datacenter entity frame of reference.

    DATACENTER OPERATIONS USING SEARCH AND ANALYTICS

    公开(公告)号:US20180025083A1

    公开(公告)日:2018-01-25

    申请号:US15708745

    申请日:2017-09-19

    Applicant: VMware, Inc.

    CPC classification number: G06F16/951

    Abstract: A datacenter management system uses data collection proxies to collect performance data and configuration data for different physical and virtual entities in the datacenter. A schema is used to represent the different entities, entity relationships, and entity properties in the datacenter. A search engine identifies the intent of a natural language based search query based on the schema and a datacenter dictionary. The search engine then searches the data based on the search query intent. A dictionary manager converts both periodic and aperiodic data into a time series. This allows the search engine to operate as a time machine identifying both performance data and configuration data for any selectable time period.

    Datacenter operations using search and analytics

    公开(公告)号:US11341195B2

    公开(公告)日:2022-05-24

    申请号:US16733955

    申请日:2020-01-03

    Applicant: VMware, Inc.

    Abstract: A datacenter management system uses data collection proxies to collect performance data and configuration data for different physical and virtual entities in the datacenter. A schema is used to represent the different entities, entity relationships, and entity properties in the datacenter. A search engine identifies the intent of a natural language based search query based on the schema and a datacenter dictionary. The search engine then searches the data based on the search query intent. A dictionary manager converts both periodic and aperiodic data into a time series. This allows the search engine to operate as a time machine identifying both performance data and configuration data for any selectable time period.

    SECURITY CONTEXT AWARE NANO-SEGMENTATION FOR CONTAINER BASED MICROSERVICES

    公开(公告)号:US20210006543A1

    公开(公告)日:2021-01-07

    申请号:US16547634

    申请日:2019-08-22

    Applicant: VMWARE, INC.

    Abstract: The present disclosure provides an approach for creating one or more firewall rules to regulate communication between containers. The approach includes calculating a trust score for each container. To generate a rule for any two containers, a difference between the trust scores is computed, and if the difference in trust levels is too large, then the more trustworthy container is not allowed to communicate with the less trustworthy container. If the difference in trust scores is not too large, then the trustworthy container is allowed to communicate with the other trustworthy container, or an untrustworthy container is allowed to communicate with another untrustworthy container.

Patent Agency Ranking