Collecting and processing context attributes on a host
Abstract
Some embodiments of the invention provide a novel architecture for capturing contextual attributes on host computers that execute one or more machines, and for consuming the captured contextual attributes to perform services on the host computers. The machines are virtual machines (VMs) in some embodiments, containers in other embodiments, or a mix of VMs and containers in still other embodiments. Some embodiments execute a guest-introspection (GI) agent on each machine from which contextual attributes need to be captured. In addition to executing one or more machines on each host computer, these embodiments also execute a context engine and one or more attribute-based service engines on each host computer. Through the GI agents of the machines on a host, the context engine of that host in some embodiments collects contextual attributes associated with network events and/or process events on the machines. The context engine then provides the contextual attributes to the service engines, which, in turn, use these contextual attributes to identify service rules for processing.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method for supporting context-based services on a host computer on which a plurality of machines and a set of one or more service engines execute, the method comprising:
at a context collector executing on the host computer:
collecting contextual attributes for events occurring on a set of machines;
receiving requests from the set of service engines for contextual attributes for data message flows associated with the set of machines; and
providing sets of contextual attributes to the set of service engines for the service engines to use to process data message flows associated with the events.
22 . The method of claim 21 further comprising generating a particular service rule for a particular service engine for one of the events, the particular service engine using the particular service rule to perform a service operation on at least one data message flow.
22 . The method of claim 22 , wherein generating the particular service rule comprises directing the particular service engine to generate the service rule.
23 . The method of claim 22 , wherein generating the particular service rule comprises generating the particular service rule at the context collector and providing the generated service rule to the particular service engine.
25 . The method of claim 21 , wherein receiving the requests comprises
receiving data message flow identifiers from the set of service engines; and matching the data message flow identifiers to collected contextual attribute sets stored by the context collector;
26 . The method of claim 25 , wherein providing sets of contextual attributes comprises in response to the received data message flow identifiers, providing the matching contextual attribute sets to the set of service engines, each service engine using the contextual attribute sets to identify service rules that specify service operations that the service engine has to perform on data message flows processed by the service engine.
27 . The method of claim 21 , wherein providing sets of contextual attributes comprises providing to the set of service engines mapping records that map the collected contextual attribute sets with data message flow identifiers, each service engine matching identifiers of the data message flows that the service engine processes with one or more mapping records in order to identify contextual attribute sets associated with the processed data message flows, and using the identified contextual attributes sets to identify service rules that specify service operations that the service engine has to perform on data message flows processed by the service engine.
28 . The method of claim 21 , wherein the events comprise new network connection events.
29 . The method of claim 21 , wherein collecting the contextual attribute sets comprises receiving at least a subset of the contextual attribute sets from guest introspection agents executing on two or more machines.
30 . The method of claim 21 , wherein collecting the contextual attribute sets comprises receiving contextual attribute sets with identifiers of associated flows, and each of a plurality of sets of contextual attributes comprises one or more attributes other than layer 2 (L2), layer 3 (L3) and layer 4 (L4) data-message header values.
31 . A non-transitory machine readable medium storing a context collector program for supporting context-based services on a host computer on which a plurality of machines and a set of one or more service engines execute, the context collector program comprising sets of instructions for:
collecting contextual attributes for events occurring on a set of machines; receiving requests from the set of service engines for contextual attributes for data message flows associated with the set of machines; and providing sets of contextual attributes to the set of service engines for the service engines to use to process data message flows associated with the events.
32 . The non-transitory machine readable medium of claim 31 , wherein the program further comprises a set of instructions for generating a particular service rule for a particular service engine for one of the events, the particular service engine using the particular service rule to perform a service operation on at least one data message flow.
33 . The non-transitory machine readable medium of claim 32 , wherein the set of instructions for generating the particular service rule comprises a set of instructions for generating the particular service rule comprises directing the particular service engine to generate the service rule.
34 . The non-transitory machine readable medium of claim 32 , wherein the set of instructions for generating the particular service rule comprises sets of instructions for generating the particular service rule at the context collector and providing the generated service rule to the particular service engine.
35 . The non-transitory machine readable medium of claim 31 , wherein the set of instructions for receiving the requests comprises sets of instructions for
receiving data message flow identifiers from the set of service engines; and matching the data message flow identifiers to collected contextual attribute sets stored by the context collector;
36 . The non-transitory machine readable medium of claim 35 , wherein the set of instructions for providing sets of contextual attributes comprises a set of instructions for providing, in response to the received data message flow identifiers, the matching contextual attribute sets to the set of service engines, each service engine using the contextual attribute sets to identify service rules that specify service operations that the service engine has to perform on data message flows processed by the service engine.
37 . The non-transitory machine readable medium of claim 31 , wherein the set of instructions for providing sets of contextual attributes comprises a set of instructions for providing to the set of service engines mapping records that map the collected contextual attribute sets with data message flow identifiers, each service engine matching identifiers of the data message flows that the service engine processes with one or more mapping records in order to identify contextual attribute sets associated with the processed data message flows, and using the identified contextual attributes sets to identify service rules that specify service operations that the service engine has to perform on data message flows processed by the service engine.
38 . The non-transitory machine readable medium of claim 31 , wherein the events comprise new network connection events.
39 . The non-transitory machine readable medium of claim 31 , wherein the set of instructions for collecting the contextual attribute sets comprises a set of instructions for receiving at least a subset of the contextual attribute sets from guest introspection agents executing on two or more machines.
40 . The non-transitory machine readable medium of claim 31 , wherein the set of instructions for collecting the contextual attribute sets comprises a set of instructions for receiving contextual attribute sets with identifiers of associated flows, and wherein each of a plurality of sets of contextual attributes comprises one or more attributes other than layer 2 (L2), layer 3 (L3) and layer 4 (L4) data-message header values.Join the waitlist — get patent alerts
Track US2022261273A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.