SCALABLE VISUALIZATION OF NETWORK FLOWS
Some embodiments provide a method for visualizing network flows between multiple security groups in a network. Each security group includes a set of one or more data computer nodes (DCNs). The method receives data regarding network flows between the DCNs of the security groups. In a scalable user interface visualization, the method displays the network flows by aggregating the network flows between DCNs in pairs of security groups. The method provides a filtering tool to enable visualization in the user interface of specific flows between the DCNs of the plurality of security groups.
1 . A method for visualizing network flows between a plurality of security groups in a network, each security group comprising a set of one or more data computer nodes (DCNs), the method comprising:
receiving data regarding network flows between the DCNs of the plurality of security groups;
in a scalable user interface visualization, displaying the network flows by aggregating the network flows between DCNs in pairs of security groups; and
providing a filtering tool to enable visualization in the user interface of specific flows between the DCNs of the plurality of security groups.
2 . The method of claim 1 , wherein the received data comprises data collected by a network manager that monitors network flows.
3 . The method of claim 2 , wherein the user interface provides a tool for enabling a user to define a subset of the plurality of security groups to be monitored.
4 . The method of claim 1 , further comprising receiving, through the user interface, data defining a subset of the DCNs as seed nodes, wherein each seed node acts as a source node for micro-segmentation.
5 . The method of claim 4 , wherein the seed nodes are displayed in the visualization using a first appearance while the DCNs that are not seed nodes are displayed in the visualization using a second appearance that is different from the first appearance.
6 . The method of claim 1 , wherein the filtering tool provides options to visualize one or more of (i) allowed flows, (ii) blocked flows, and (iii) unsecured flows.
7 . The method of claim 6 , wherein the filtering tool further provides options to visualize flows for any one of (i) existing security groups, (ii) recommended security groups, and (iii) both existing security groups and recommended security groups.
8 . The method of claim 6 , wherein unsecured flows comprise flows for which a firewall rule has not been defined.
9 . The method of claim 6 , wherein the allowed flows, blocked flows, and unsecured flows are each represented by flow lines having a different appearance.
10 . The method of claim 1 , wherein the scalable user interface visualization enables selection of individual security groups and individual DCNs via representations of the security groups and DCNs in the user interface.
11 . The method of claim 10 , wherein selection of a security group causes the user interface to highlight the selected security group and display network flows between DCNs belonging to the security group and DCNs belonging to other security groups.
12 . The method of claim 11 , wherein the network flows between DCNs belonging to the selected security group and DCNs belonging to a particular other security group are displayed as a single flow line along with a notation that indicates a number of flows represented by the single flow line.
13 . The method of claim 12 , wherein, for each set of network flows between DCNs belonging to the selected security group and DCNs belonging to another security group, the user interface displays a separate flow line along with a notation that indicates a number of flows represented by the flow line.
14 . The method of claim 10 , wherein selection of a DCN causes the user interface to highlight the selected DCN and display network flows between the selected DCN and other DCNs displayed in the user interface.
15 . The method of claim 1 , wherein a subset of the DCNs are comprises of IPSets.
16 . The method of claim 1 , wherein a subset of the DCNs comprise unresolved DCNs that are not organized into any of the plurality of security groups.
17 . A non-transitory machine-readable medium storing a program which when executed by at least one processing unit visualizes network flows between a plurality of security groups in a network, each security group comprising a set of one or more data computer nodes (DCNs), the program comprising sets of instructions for:
receiving data regarding network flows between the DCNs of the plurality of security groups;
in a scalable user interface visualization, displaying the network flows by aggregating the network flows between DCNs in pairs of security groups; and
providing a filtering tool to enable visualization in the user interface of specific flows between the DCNs of the plurality of security groups.
18 . The non-transitory machine-readable medium of claim 17 , wherein:
the program further comprises a set of instructions for receiving, through the user interface, data defining a subset of the DCNs as seed nodes;
each seed node acts as a source node for micro-segmentation; and
the seed nodes are displayed in the visualization using a first appearance while the DCNs that are not seed nodes are displayed in the visualization using a second appearance that is different from the first appearance.
19 . The non-transitory machine-readable medium of claim 17 , wherein:
the filtering tool provides options to visualize one or more of (i) allowed flows, (ii) blocked flows, and (iii) unsecured flows;
unsecured flows comprise flows for which a firewall rule has not been defined; and
the allowed flows, blocked flows, and unsecured flows are each represented by flow lines having a different appearance.
20 . The non-transitory machine-readable medium of claim 17 , wherein the scalable user interface visualization enables selection of individual security groups and individual DCNs via representations of the security groups and DCNs in the user interface.
21 . The non-transitory machine-readable medium of claim 20 , wherein:
selection of a security group causes the user interface to highlight the selected security group and display network flows between DCNs belonging to the security group and DCNs belonging to other security groups; and
the network flows between DCNs belonging to the selected security group and DCNs belonging to a particular other security group are displayed as a single flow line along with a notation that indicates a number of flows represented by the single flow line.
22 . The non-transitory machine-readable medium of claim 20 , wherein selection of a DCN causes the user interface to highlight the selected DCN and display network flows between the selected DCN and other DCNs displayed in the user interface.