Graph-Based Infrastructure Model for Application Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing complex and dynamic enterprise computing environments is challenging due to the difficulty in maintaining an accurate representation of the infrastructure, as existing methods like probing and packet capture are inefficient in identifying software applications, especially with encryption, and manual methods are impractical for large and complex setups.

Innovation Solution

A method and apparatus that build a graph-based model of the computer infrastructure, using agent software to gather information and apply sub-graph isomorphism techniques to identify and match template graphs, enabling the identification of known and unknown applications, and updating a configuration management database.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual methods are used to maintain configuration management database, then accuracy of infrastructure representation can be maintained, but the method becomes impractical for large and complex computing environments

Engineering Contradiction:
Improveaccuracy of infrastructure representationVSAvoidpracticality of maintenance method
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The system employs automated agents deployed on computing devices that self-serve by automatically collecting configuration data, identifying software applications, and updating the configuration management database without human intervention. This resolves the contradiction by replacing manual maintenance (impractical for large systems) with self-service automation that maintains accuracy across complex environments.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes with automated computational systems. Agents use probing techniques to automatically gather configuration data and apply machine learning models to identify software applications, substituting human manual work with automated computational mechanisms that scale to large complex environments while maintaining representation accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If probing techniques are used to identify software applications, then known applications can be detected, but the method fails to identify applications with encrypted communications or non-standard ports

Engineering Contradiction:
Improveefficiency of application identificationVSAvoidcompleteness of application detection
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system changes the parameters used for application identification by moving beyond traditional probing methods that rely on known ports and signatures. Instead, it collects multiple parameters including network traffic patterns, file system changes, registry modifications, and process behavior, then uses machine learning to analyze these varied parameters for comprehensive application detection including encrypted and non-standard applications.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a composite identification approach by combining multiple data sources and analysis methods. Agents collect diverse configuration data from multiple sources (network traffic, file systems, registries, processes) and combine these using machine learning models to create a comprehensive identification system that overcomes the limitations of any single probing technique.

Inventive Principle:
Principle #40Composite materials

3Difficulty of detecting and measuring

If packet capture techniques are used to analyze network traffic, then IP addresses and port numbers can be identified, but the method cannot identify applications when packet encryption is used

Engineering Contradiction:
Improveease of network endpoint identificationVSAvoidapplication identification information
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

The system performs preliminary actions by collecting configuration data before encrypted communications occur. Agents monitor file system changes, registry modifications, and process creations that precede encrypted network activity, allowing identification of applications based on their configuration footprint rather than relying solely on decryptable network traffic analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces configuration data as an intermediary between network traffic and application identification. Instead of directly analyzing encrypted packets (which loses information), the system uses configuration data from agents as an intermediary source that reveals application identity through file systems, registries, and process information, bypassing the encryption barrier.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If basic pattern matching techniques are used to match application signatures, then known applications can be identified, but the method cannot detect unknown or modified applications

Engineering Contradiction:
Improveaccuracy of known application identificationVSAvoidability to identify unknown applications
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system transitions from static pattern matching to dynamic analysis. Instead of relying on fixed signatures that only match known applications, the patent employs machine learning models that adaptively analyze configuration data patterns, allowing identification of both known applications through learned patterns and unknown applications through anomaly detection and behavioral analysis.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback mechanisms where the machine learning model continuously learns from collected configuration data. The system gathers configuration information, trains models on this data, and uses the trained models to identify applications, with the process feeding back into improved model performance. This feedback loop enables the system to adapt to new and modified applications while maintaining reliability for known applications.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8190416B2Computer network management
Publication Date: 2012.05.29 MICRO FOCUS LLC
  • US8190416B2 patent drawing
  • US8190416B2 patent drawing
  • US8190416B2 patent drawing

AI summary

According to one embodiment of the present invention, there is provided a method of identifying components of a computer infrastructure, comprising building a graph-based model of at least a part of the computer infrastructure, determining the presence within the built graph of a predetermined sub-graph, and where it is so determined identifying the sub-graph within the built graph.