US2024004689A1PendingUtilityA1

Recommendation generation based on selection of selectable elements of visual representation

Assignee: VMWARE INCPriority: Jul 23, 2019Filed: Jun 19, 2023Published: Jan 4, 2024
Est. expiryJul 23, 2039(~13 yrs left)· nominal 20-yr term from priority
G06F 9/45558H04L 43/026H04L 63/0263G06F 2009/4557G06F 2009/45595G06F 2009/45591H04L 41/085H04L 43/065H04L 41/0859H04L 41/16H04L 41/22G06F 9/45533G06F 2009/45587Y02D30/50
72
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Some embodiments provide a novel method for collecting and reporting attributes of data flows associated with machines executing on a plurality of host computers to an analysis appliance and providing visual representations of the data to a user. Some embodiments provide a visual representation of the collected data that allows a user to select a set of machines and flows and initiate recommendation generation based on the selected machines and flows. The recommendation generation, in some embodiments, includes identifying flows for which rules have not been defined and filtering the identified rules to remove flows for which rules should not be defined. Some embodiments use the identified rues to identify services and groups associated with the rules and generate recommendations for rules, groups and services based on the identified flows, groups and services. The recommendations, in some embodiments, are implemented as a single PATCH API.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method for detecting anomalous behavior of machines executing on a plurality of host computers, the method comprising:
 receiving from the host computers sets of attributes relating to groups of flows processed on the host computers, at least a group of the received attribute sets comprising an indication of an anomaly behavior detected with respect to at least one processed flow;   using the anomalous behavior indication to select one of the received attribute sets for further anomalous behavior analysis;   based on anomalous behavior analysis, providing an indication of a detected anomalous behavior for display on a user interface.   
     
     
         22 . The method of  claim 21 , wherein the anomalous behavior indication is a flag bit that indicates anomalous behavior detection. 
     
     
         23 . The method of  claim 21 , wherein the anomalous behavior indication is a value that indicates a type of anomalous behavior detected. 
     
     
         24 . The method of  claim 23 , wherein the value for a particular group of flows indicates one of (1) a newly added service rule not having been used to process at least one flow in the particular group of flows to which the newly added service rule applies, (2) a default service rule having been used to process at least one flow in the particular group of flows, and (3) no service rule having been specified for communications between source and destination machine of at least one flow in the particular group of flows. 
     
     
         25 . The method of  claim 23 , wherein the value for a particular group of flows indicates one of (1) a port associated with at least one flow in the particular group of flows not matching a port expected based on an application associated with the at least one flow, (2) a previously blocked flow having been allowed, and (3) an insecure version of an application having been used. 
     
     
         26 . The method of  claim 21 , wherein the further analysis comprises analyzing previously received sets of attributes stored in a time series data storage. 
     
     
         27 . A method for processing pluralities of data flow attribute sets associated with a plurality of host computers, the method comprising:
 identifying first and second sets of data flow attribute sets received from first and second host computers that relate to a same set of flows between a same set of source machines and a same set of destination machines;   producing a merged data flow attribute set for the identified first and second sets of data flows that comprises the unique data flow attributes of the first and second data flow attribute sets;   performing anomalous behavior analysis on the merged data flow attribute set to identify a flow between at least two machines for further investigation by an administrator.   
     
     
         28 . The method of  claim 27 , wherein the merged data flow attribute set comprises contextual attributes different than layers 2, 3 and 4 flow header values. 
     
     
         29 . The method of  claim 28 , wherein the anomalous behavior analysis identifies a flow that should not be allowed based on a current service rule configuration. 
     
     
         30 . The method of  claim 29 , wherein identifying the flow that should not be allowed comprises a flow between first and second machines for which a service rule is defined to block communication. 
     
     
         31 . The method of  claim 30 , wherein the first machine belongs to a first group of machines and the second machine belongs to a second group of machines and the service rule specifies a blocking action for data messages between the first and second groups of machines. 
     
     
         32 . The method of  claim 30 , wherein the first machine belongs to a first range of addresses and the second machine belongs to a second range of addresses and the service rule specifies a blocking action for data messages between the first and second ranges of addresses. 
     
     
         33 . The method of  claim 27 , wherein identifying the flow comprises determining that a volume of data messages between the two machines is anomalously high. 
     
     
         34 . The method of  claim 27 , wherein the anomalous behavior analysis is performed on a set of merged data attribute sets that are related to the merged attribute data set of the identified flow. 
     
     
         35 . The method of  claim 34 , wherein the related merged attribute data sets comprise a plurality of merged attribute data sets stored in a time series data storage. 
     
     
         36 . The method of  claim 35 , wherein the time series data storage is organized at a plurality of levels of temporal granularity. 
     
     
         37 . The method of  claim 36 , wherein data for a previous 24 hours is organized on an hourly basis, data for a previous 30 days is organized on a daily basis, and data received more than 30 days earlier is organized on a monthly basis. 
     
     
         38 . The method of  claim 27  further comprising generating a recommendation for presentation to the administrator based on the anomalous behavior analysis for the identified flow.

Join the waitlist — get patent alerts

Track US2024004689A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.