Application Discovery Graphs for Accurate Security Posture Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security management systems lack comprehensive computing logic and infrastructure for effective application discovery in computing environments, leading to stale or deficient mapping data, human errors, and increased risk of unauthorized access and malicious operations due to inaccurate application mapping.

Innovation Solution

An application discovery engine generates an annotated application discovery graph using configuration, support-text, and access log data to identify and map applications, providing security posture management by integrating security data triangulation and graph-based analysis to enhance accuracy and reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual maintenance of application mapping data is used, then ease of operation is improved, but reliability deteriorates due to human errors and stale data

Engineering Contradiction:
Improveease of maintenanceVSAvoidaccuracy of mapping data
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs self-service through automated application discovery operations that continuously monitor and update application mappings without human intervention. The discovery engine automatically executes operations to identify applications, extract their characteristics, and maintain accurate mappings, eliminating reliance on manual maintenance while ensuring data freshness and accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes with automated computational systems. Instead of human operators manually maintaining mapping data, the system uses an application discovery engine that executes automated discovery operations, processes application data, and updates mappings programmatically, thereby eliminating human errors while maintaining operational efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If configuration-based application mapping is used, then ease of operation is improved, but measurement precision deteriorates due to excessive irrelevant resources

Engineering Contradiction:
Improvesimplicity of mappingVSAvoidaccuracy of application identification
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The discovery engine extracts only the relevant characteristics and attributes needed for accurate application identification from the configuration data. Instead of relying on complete configuration sets that include irrelevant resources, the system selectively extracts key identifying features, thereby improving measurement precision while maintaining operational simplicity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies local quality by focusing discovery operations on specific application components and characteristics that are most relevant for identification. Rather than processing all configuration data uniformly, the engine targets specific local attributes of applications, improving accuracy while reducing the overhead of processing irrelevant resources.

Inventive Principle:
Principle #3Local quality

3Device complexity

If support-text-based application discovery is used, then device complexity is reduced, but measurement precision deteriorates due to errors from reliance on application owner knowledge

Engineering Contradiction:
Improvesystem complexityVSAvoidaccuracy of application mapping
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The system implements feedback mechanisms where the discovery engine continuously monitors application behavior, access patterns, and operational data to validate and correct application mappings. This feedback loop enables the system to self-correct errors and improve accuracy over time without increasing system complexity, as the feedback is integrated into the existing discovery operations.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The discovery engine performs multiple functions using a single unified system: it discovers applications, extracts characteristics, validates mappings, and updates configurations. This multi-functionality eliminates the need for separate manual processes while maintaining reasonable system complexity, thereby improving accuracy without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If comprehensive application discovery operations are implemented, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improveaccuracy of security posture managementVSAvoidcomplexity of discovery system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The comprehensive application discovery process is segmented into distinct operational phases: initial application identification, characteristic extraction, mapping generation, validation, and continuous monitoring. Each segment handles a specific aspect of discovery, making the overall complex process manageable and maintainable while ensuring high reliability through systematic coverage of all necessary discovery tasks.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12554839B2Application discovery engine in a security management system
Publication Date: 2026.02.17 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12554839B2 patent drawing
  • US12554839B2 patent drawing
  • US12554839B2 patent drawing

AI summary

Methods, systems, and computer storage media for providing data security posture management using an application discovery engine in a security management system. Application discovery supports identifying and mapping various applications within a computing environment. In particular, application discovery can be provided as part of security management operations to assess security posture of applications, identify vulnerabilities, and ensure compliance with regulations. In operation, application discovery data associated with a plurality computing resources of a computing environment is accessed. An annotated application discovery graph comprising a plurality of entities that represent the plurality of computing resources is generated. The annotated application discovery graph is deployed to support generating security postures for computing environments. A request is received for a security posture of the computing environment. A security posture visualization that includes an application discovery graph annotation is generated. The security posture visualization is communicated to cause display of the security posture visualization.