Automated Software Detection via Configuration Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cluster-based computing environments, traditional methods for detecting software applications are time-consuming and computationally intensive, especially when applications are deployed without tags or annotations, making it difficult for administrators to identify and manage installed software.

Innovation Solution

The use of configuration objects to create a catalog of signatures, which are compared with information from the computing environment to identify software applications, allowing for automated detection without scanning file systems, and enabling redistribution of applications across clusters to optimize processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional file system scanning techniques are used to detect software applications, then application identification can be achieved, but the process becomes time-consuming and computationally intensive

Engineering Contradiction:
Improveapplication identification accuracyVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts the essential identification information from the complex file system scanning process by using configuration objects that contain pre-defined application signatures. Instead of scanning entire file systems, the system extracts and compares specific configuration parameters (volumes, commands, config maps, secrets) against a catalog of known application signatures, dramatically reducing detection time while maintaining identification accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary action by pre-defining configuration object templates and signatures for known software applications before the detection process. These pre-configured signatures contain expected configuration parameters and values that can be quickly matched against running applications, eliminating the need for time-consuming file system scans during actual detection operations.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If traditional file system scanning techniques are used to detect software applications, then application identification can be achieved, but the computational resources required increase significantly

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the necessary configuration parameters from running applications (volumes, commands, config maps, secrets) and compares them against a signature catalog, rather than processing entire file systems. This extraction approach reduces computational resource consumption while maintaining the ability to accurately identify applications through targeted parameter matching.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary action by pre-compiling configuration object templates and application signatures during system setup. These pre-defined signatures contain expected configuration patterns that enable rapid matching with minimal computational overhead during actual detection, significantly reducing real-time resource requirements compared to traditional scanning methods.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If configuration objects with signatures are used to detect software applications, then detection speed improves, but the system complexity increases due to signature catalog management

Engineering Contradiction:
Improvedetection speedVSAvoidsignature catalog management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing configuration objects as multi-functional entities that serve both as application deployment specifications and as detection signatures. The same configuration object templates used to define and run applications also serve as the basis for creating detection signatures, eliminating the need for separate signature management systems and reducing overall system complexity while maintaining high detection speed.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If applications are deployed in containers without tags or annotations, then deployment flexibility improves, but application identification becomes more difficult

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidapplication identification difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces configuration objects as an intermediary between container deployment and application identification. These configuration objects contain identifiable signatures and parameters that serve as mediators, allowing applications to be deployed flexibly in containers without traditional tags while still enabling identification through the configuration-based signature matching mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11163557B2Automated techniques for detecting the usage of software applications in a computing environment using configuration objects
Publication Date: 2021.11.02 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11163557B2 patent drawing
  • US11163557B2 patent drawing
  • US11163557B2 patent drawing

AI summary

The systems and methods provided herein provide techniques for discovering applications installed in a cluster-based computing environment. A catalog of signatures is obtained. One or more clusters are scanned to obtain information about configuration parameters in the one or more clusters. The catalog of signatures is compared with the information from scanning comprising configuration parameters to identify software applications installed on a per-cluster basis.