Analyzing flow group attributes using configuration tags

US11140090B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11140090-B2
Application numberUS-201916520238-A
CountryUS
Kind codeB2
Filing dateJul 23, 2019
Priority dateJul 23, 2019
Publication dateOct 5, 2021
Grant dateOct 5, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Some embodiments provide a novel method for correlating configuration data received from the network manager computer with flow group records. In some embodiments, the correlation with the configuration data identifies a group associated with at least one of: (i) the source machine, (ii) destination machine, and (iii) service rules applied to the flows. The correlation with the configuration data, in some embodiments, also identifies whether a service rule applied to the flows is a default service rule. In some embodiments, the correlation with the configuration is based on a tag included in the flow group record that identifies a configuration version, and a configuration associated with the identified configuration version is used to identify the group association or the identity of the default service rule.

First claim

Opening claim text (preview).

We claim: 1. A method for processing pluralities of data flow attribute sets and pluralities of configuration data sets each associated with a plurality of host computers, the method comprising: at a plurality of times, receiving a plurality of configuration tags identifying a plurality of different configuration data sets used to configure the plurality of host computers during the plurality of times; receiving (i) a plurality of attribute sets related to groups of flows processed on the host computers, and (ii) for each attribute set, a configuration tag identifying a configuration data set associated with the attribute set; using the configuration tags to identify the configuration data sets associated with the received attribute sets related to the group of flows processed on the host computers; and using the identified configuration data sets to analyze the groups of flows processed on the host computers; receiving reports from a network manager computer regarding a plurality of configuration data sets, wherein a reported configuration data set includes a new machine specification and the network manager delays deploying the new machine until the configuration data set including the new machine is reported. 2. The method of claim 1 , wherein the configuration tag associated with the attribute set of a group identifies a configuration data set at the time of the collection of the attribute set. 3. The method of claim 2 , wherein an attribute set for a group of flows comprises a plurality of configuration tags associated with individual flows in the group of flows. 4. The method of claim 2 , wherein the configuration tags are associated with service rules used to process individual flows. 5. The method of claim 4 further comprising determining whether a service rule is a default service rule by using a configuration data set associated with a configuration tag associated with the service rule used to process an individual flow. 6. A method for processing pluralities of data flow attribute sets and pluralities of configuration data sets each associated with a plurality of host computers, the method comprising: at a plurality of times, receiving a plurality of configuration tags identifying a plurality of different configuration data sets used to configure the plurality of host computers during the plurality of times, wherein the configuration tags are associated with service rules used to process individual flows; receiving (i) a plurality of attribute sets related to groups of flows processed on the host computers, and (ii) for each attribute set, a configuration tag identifying a configuration data set associated with the attribute set; using the configuration tags to identify the configuration data sets associated with the received attribute sets related to the group of flows processed on the host computers, the configuration tag associated with the attribute set of a group identifies a configuration data set at the time of the collection of the attribute set; and using the identified configuration data sets to analyze the groups of flows processed on the host computers; determining whether a service rule is a default service rule by using a configuration data set associated with a configuration tag associated with the service rule used to process an individual flow, wherein a detecting that a default service rule was used to process the individual flow indicates that the flow is unmicrosegmented. 7. The method of claim 1 further comprising adding attributes from the identified configuration data set for an associated attribute set to the associated attribute set to produce an enhanced attribute set. 8. The method of claim 7 , wherein the added attribute is a machine identifier for at least one of a source or destination machine of at least one flow in the group of flows related to the attribute set. 9. The method of claim 7 , wherein the added attribute is a group identifier for at least one of a source or destination machine of at least one flow in the group of flows related to the attribute set. 10. The method of claim 7 , wherein the enhanced attribute set is stored in a time series data storage. 11. The method of claim 10 , wherein the time series data storage is organized at a plurality of levels of temporal granularity. 12. The method of claim 1 , wherein the plurality of reports comprises a first configuration data set report that comprises an initial configuration data set and additional configuration data set reports that comprise more recent configuration data sets. 13. The method of claim 12 , wherein the configuration data set reports for the more recent configuration data sets comprise reports of changes to the immediately previous configuration data set. 14. The method of claim 12 , wherein the additional configuration data set reports are sent within a threshold time from when the more recent configuration data set is implemented by the network manager computer. 15. The method of claim 14 , wherein the threshold time is based on a frequency of receiving attribute sets from the plurality of host computers. 16. The method of claim 1 further comprising sending a confirmation that the report has been received, wherein the network manager computer delays deploying the new machine until the confirmation is received by the network manager computer. 17. A method for processing pluralities of data flow attribute sets and pluralities of configuration data sets each associated with a plurality of host computers, the method comprising: at a plurality of times, receiving a plurality of configuration tags identifying a plurality of different configuration data sets used to configure the plurality of host computers during the plurality of times; receiving (i) a plurality of attribute sets related to groups of flows processed on the host computers, and (ii) for each attribute set, a configuration tag identifying a configuration data set associated with the attribute set; using the configuration tags to identify the configuration data sets associated with the received attribute sets related to the group of flows processed on the host computers; and using the identified configuration data sets to analyze the groups of flows processed on the host computers, said using comprising: aggregating a plurality of attribute sets received for a group of flows from a plurality of host computers, the group of flows associated with at least one configuration of the plurality of host computers; identifying a first set of attributes in the plurality of attributes aggregated for the set of flows; identifying, in the at least one configuration data set associated with the first configuration of the plurality of host computers, a second set of attributes matching the first set of attributes; and associating the aggregated plurality of attributes with a set of machine identifiers associated with the matching second set of attributes.

Assignees

Inventors

Classifications

  • using flow identification · CPC title

  • relying on flow classification, e.g. using integrated services [IntServ] · CPC title

  • H04L47/41Primary

    by acting on aggregated flows or links · CPC title

  • in wire-line communication networks, e.g. low power modes or reduced link rate · CPC title

  • using network fault recovery (ring fault isolation or reconfiguration in loop networks without recovery actions by a network management system H04L12/437) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11140090B2 cover?
Some embodiments provide a novel method for correlating configuration data received from the network manager computer with flow group records. In some embodiments, the correlation with the configuration data identifies a group associated with at least one of: (i) the source machine, (ii) destination machine, and (iii) service rules applied to the flows. The correlation with the configuration da…
Who is the assignee on this patent?
Vmware Inc
What technology area does this patent fall under?
Primary CPC classification H04L47/2441. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 05 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).