Agentless Infrastructure Drift Detection via API Probes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Globally distributed teams with growing infrastructure face challenges in managing unified distributed build and configuration information due to agent-based solutions that create overhead and security risks, particularly in unreliable and insecure environments.

Innovation Solution

An agentless infrastructure-agnostic drift detection and management system that uses microservices to obtain metric information, applies machine learning for analysis, and automatically applies remedies to detect and mitigate configuration changes, while protecting critical host login credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If agent-based solutions are used for real-time management of infrastructure and application components, then monitoring capability is improved, but system overhead and security risks increase

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidsystem overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the monitoring agent from the system by implementing an agentless architecture. Instead of deploying agents on infrastructure components, the system uses external probes and APIs to collect metrics, thereby eliminating agent-related overhead and security risks while maintaining monitoring capabilities

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary layer consisting of probes and API interfaces that mediate between the monitoring system and infrastructure components. This intermediary approach allows data collection without direct agent installation, reducing system complexity and security exposure

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If agents are deployed on critical infrastructure hosts, then data collection capability is improved, but security vulnerabilities and availability risks increase

Engineering Contradiction:
Improvedata collection capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent removes agents from critical infrastructure hosts entirely, replacing them with agentless data collection methods using probes and APIs. This extraction eliminates the security vulnerability and availability risk associated with running external code on critical systems while preserving data collection capabilities

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The infrastructure components provide their own metrics and status information through built-in APIs and self-service mechanisms, eliminating the need for external agents to collect data. This self-service approach reduces security risks while maintaining comprehensive monitoring

Inventive Principle:
Principle #25Self-service

3Loss of time

If commercial off-the-shelf agent-based solutions are used, then implementation speed is improved, but integration compatibility and security integration decrease

Engineering Contradiction:
Improveimplementation speedVSAvoidintegration compatibility
Core Design Contradiction:
Loss of timeVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal agentless architecture that can integrate with multiple infrastructure types and commercial solutions through standardized APIs and protocols. This multi-functional design provides rapid implementation across diverse environments while maintaining integration compatibility and security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11695666B2System and method for agentless infrastructure agnostic application drift detection and management
Publication Date: 2023.07.04 JPMORGAN CHASE BANK NA
  • US11695666B2 patent drawing
  • US11695666B2 patent drawing
  • US11695666B2 patent drawing

AI summary

A system and a method for monitoring and detecting drifts and configuration changes in an infrastructure that facilitates the availability of software applications to a large organization are provided. The method includes: obtaining metric information that indicates values of various parameters that relate to the infrastructure; comparing the obtained metric information with expected values thereof; determining whether a drift has occurred based on a result of the comparison; and providing a notification of a detected drift. When a drift is detected, a potential remedy may be diagnosed and automatically applied.