-
公开(公告)号:US11431678B2
公开(公告)日:2022-08-30
申请号:US16351083
申请日:2019-03-12
申请人: VMware, Inc.
发明人: Arnold Poon , Sirisha Myneni , Rajiv Mordani , Aditi Vutukuri
IPC分类号: H04L9/40 , H04L61/103 , G06F9/455 , H04L69/22
摘要: In an embodiment, a computer-implemented method for enabling enhanced firewall rules via ARP-based annotations is described. In an embodiment, a method comprises detecting, by a hypervisor implemented in a first host, that a first process is executing on the first host. The hypervisor determines first context information for the first process, generates a first request, encapsulates the first request and the first context information in a first packet, and transmits the first packet to a central controller to cause the central controller to update the controller's table to indicate that the first process is executing on the first host. In response to receiving a second packet from the central controller and determining that the second packet comprises a first response, the hypervisor extracts second context information from the second packet and, based on the second context information, determines that a second process is executing on a second host.
-
公开(公告)号:US11321213B2
公开(公告)日:2022-05-03
申请号:US16745248
申请日:2020-01-16
申请人: VMware, Inc.
摘要: Some embodiments provide a novel method for collecting and reporting attributes of data flows associated with machines executing on a plurality of host computers to an analysis appliance. Some embodiments collect, each time a request for a new data message flow is initiated, a set of contextual attributes (i.e., context data) associated with the requested new data message flow. The method, in some embodiments, generates a correlation data set and provides the correlation data set to be included in flow data regarding the requested data message flow to be used by the analysis appliance to correlate context data and flow data received as separate data sets from multiple host computers.
-
公开(公告)号:US20210029051A1
公开(公告)日:2021-01-28
申请号:US16520238
申请日:2019-07-23
申请人: VMware, Inc.
发明人: Rajiv Mordani , Arnold Poon , Aditi Vutukuri , Anita Lu , Ming Wen
IPC分类号: H04L12/891 , H04L12/851 , H04L12/26
摘要: Some embodiments provide a novel method for correlating configuration data received from the network manager computer with flow group records. In some embodiments, the correlation with the configuration data identifies a group associated with at least one of: (i) the source machine, (ii) destination machine, and (iii) service rules applied to the flows. The correlation with the configuration data, in some embodiments, also identifies whether a service rule applied to the flows is a default service rule. In some embodiments, the correlation with the configuration is based on a tag included in the flow group record that identifies a configuration version, and a configuration associated with the identified configuration version is used to identify the group association or the identity of the default service rule.
-
公开(公告)号:US20210026830A1
公开(公告)日:2021-01-28
申请号:US16520232
申请日:2019-07-23
申请人: VMware, Inc.
发明人: Jayant Jain , Russell Lu , Ly Loi , Rick Lund , Arnold Poon
摘要: Some embodiments provide a novel method for collecting and reporting attributes of data flows associated with machines executing on a plurality of host computers to an analysis appliance. The analysis appliance, in some embodiments, receives definitions of keys and provides them to the host computers. In some embodiments, existing keys are modified based on the analysis. Additionally, or alternatively, new keys are provided based on the analysis. In some embodiments, the analysis appliance receives the flow group records (e.g., sets of attributes) based on the keys and the configuration data from each host computer.
-
公开(公告)号:US11765174B2
公开(公告)日:2023-09-19
申请号:US16213545
申请日:2018-12-07
申请人: VMware, Inc.
发明人: Arijit Chanda , Venkat Rajagopalan , Rajiv Mordani , Arnold Poon , Rajiv Krishnamurthy , Farzad Ghannadian , Sirisha Myneni
CPC分类号: H04L63/102 , H04L63/205 , G06F9/45533
摘要: Techniques for providing application-independent access control in a cloud-services computing environment are provided. In one embodiment, a method for providing application-independent access control is provided. The method includes obtaining a user identity for accessing the cloud-services computing environment and receiving a user request to perform a task using an application. The method further includes collecting process-related data for performing the task using the application and obtaining one or more network routing addresses. The method further includes determining, based on the user identity, the process-related data, and the one or more network routing addresses, whether the task is to be performed. If that the task is to be performed, the task is caused to be performed using the application; and if the task is not to be performed, the user request is denied.
-
公开(公告)号:US20210224179A1
公开(公告)日:2021-07-22
申请号:US16745248
申请日:2020-01-16
申请人: VMware, Inc.
摘要: Some embodiments provide a novel method for collecting and reporting attributes of data flows associated with machines executing on a plurality of host computers to an analysis appliance. Some embodiments collect, each time a request for a new data message flow is initiated, a set of contextual attributes (i.e., context data) associated with the requested new data message flow. The method, in some embodiments, generates a correlation data set and provides the correlation data set to be included in flow data regarding the requested data message flow to be used by the analysis appliance to correlate context data and flow data received as separate data sets from multiple host computers.
-
公开(公告)号:US20210026863A1
公开(公告)日:2021-01-28
申请号:US16520227
申请日:2019-07-23
申请人: VMware, Inc.
发明人: Rajiv Mordani , Arnold Poon , Aditi Vutukuri , Vinith Podduturi
摘要: Some embodiments provide a novel method for receiving a plurality of attribute sets from a set of host computers, each attribute set associated with a group of one or more flows that is created by using a key to associate individual flows into the group of flows. The appliance, in some embodiments, identifies at least two received attribute sets from two different host computers that relate to a same set of flows between a same set of source machines and a same set of destination machines. The appliance merges the two identified attribute sets into one merged attribute set and analyzes the merged attribute set to identify a set of properties of the flows in the groups of flows associated with the two identified attribute sets, in some embodiments.
-
公开(公告)号:US20200065080A1
公开(公告)日:2020-02-27
申请号:US16112396
申请日:2018-08-24
申请人: VMware, Inc.
发明人: Sirisha Myneni , Arijit Chanda , Laxmikant Vithal Gunda , Arnold Poon , Farzad Ghannadian , Kausum Kumar
摘要: Some embodiments provide a simplified mechanism to deploy and control a multi-segmented application by using application-based manifests that express how application segments of the multi-segment application are to be defined or modified, and how the communication profiles between these segments. In some embodiments, these manifests are application specific. Also, in some embodiments, deployment managers in a software defined datacenter (SDDC) provide these manifests as templates to administrators, who can use these templates to express their intent when they are deploying multi-segment applications in the datacenter. Application-based manifests can also be used to control previously deployed multi-segmented applications in the SDDC. Using such manifests would enable the administrators to be able to manage fine grained micro-segmentation rules based on endpoint and network attributes.
-
公开(公告)号:US20200014663A1
公开(公告)日:2020-01-09
申请号:US16028347
申请日:2018-07-05
申请人: VMware, Inc.
发明人: Tori Chen , Sirisha Myneni , Arijit Chanda , Arnold Poon , Farzad Ghannadian , Venkat Rajagopalan
摘要: Some embodiments of the invention provide a novel architecture for providing context-aware middlebox services at the edge of a physical datacenter. In some embodiments, the middlebox service engines run in an edge host (e.g., an NSX Edge) that provides routing services and connectivity to external networks (e.g., networks external to an NSX-T deployment). Some embodiments use a novel architecture for capturing contextual attributes on host computers that execute one or more machines and providing the captured contextual attributes to context-aware middlebox service engines providing the context-aware middlebox services. In some embodiments, a context header insertion processor uses contextual attributes to generate a header including data regarding the contextual attributes (a “context header”) that is used to encapsulate a data message that is processed by the SFE and sent to the context-aware middlebox service engine.
-
公开(公告)号:US11288256B2
公开(公告)日:2022-03-29
申请号:US16520232
申请日:2019-07-23
申请人: VMware, Inc.
发明人: Jayant Jain , Russell Lu , Ly Loi , Rick Lund , Arnold Poon
摘要: Some embodiments provide a novel method for collecting and reporting attributes of data flows associated with machines executing on a plurality of host computers to an analysis appliance. The analysis appliance, in some embodiments, receives definitions of keys and provides them to the host computers. In some embodiments, existing keys are modified based on the analysis. Additionally, or alternatively, new keys are provided based on the analysis. In some embodiments, the analysis appliance receives the flow group records (e.g., sets of attributes) based on the keys and the configuration data from each host computer.
-
-
-
-
-
-
-
-
-