Intelligent Application Grouping From Filtered Network Connectivity Records
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network surveillance methods fail to identify meaningful communications in enterprise networks, leading to an overabundance of data points and difficulty in determining which computing nodes cooperate to provide specific applications, as they do not effectively distinguish between critical and non-critical communications.
Innovation Solution
An intelligent application grouping approach that collects, augments, and processes network data to create Connectivity Records (CRs) with intelligence, including location tagging, directionality, protocol identification, and application context, and applies service-oriented architecture (SOA) grouping to distill meaningful applications from the network traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If network surveillance collects all communications data in enterprise networks, then complete network visibility is achieved, but data complexity and difficulty in identifying meaningful communications increases
Solution Approach 1:
The patent segments network communications into discrete connectivity records, each representing a specific communication event between computing nodes. By dividing the continuous network traffic stream into individual recordable units with specific attributes (source, destination, protocol, application context), the system achieves comprehensive visibility while making the data manageable and analyzable through structured organization
Solution Approach 2:
The patent introduces an intermediary processing layer that sits between raw network traffic and analysis tools. This intermediary captures communications, structures them into standardized connectivity records with relevant attributes, and presents organized data to analysis systems. This mediator transforms raw complex network data into structured, meaningful information that reveals application dependencies without overwhelming complexity
2Quantity of substance
If traditional network surveillance methods are used, then all communications are captured, but ability to distinguish critical from non-critical communications deteriorates
Solution Approach 1:
The patent applies local quality by enriching each connectivity record with specific attributes relevant to that communication event, such as application context, protocol type, and directional flow. This localized enrichment allows each record to be evaluated on its own merits for criticality, enabling precise identification of important communications without requiring analysis of all data uniformly
Solution Approach 2:
The patent changes parameters by transforming raw communication data into structured connectivity records with multiple dimensions including source/destination identifiers, protocol types, application contexts, and temporal information. These parameter transformations enable sophisticated filtering and analysis to distinguish critical communications (those with specific application contexts or patterns) from non-critical ones
3Manufacturing precision
If computing nodes are tracked individually, then detailed network activity is recorded, but difficulty in determining which nodes cooperate to provide specific applications increases
Solution Approach 1:
The patent merges individual connectivity records into application-level groupings by identifying patterns of communication between computing nodes. When multiple nodes exhibit coordinated communication patterns consistent with providing a specific application service, their individual records are combined into a unified application dependency model, revealing which nodes cooperate without losing individual node precision
Data Source
AI summary
A method is described that comprises collecting communication data travelling among a plurality of computing nodes in a networked environment. The method includes using the communication data to create a plurality of connectivity records, wherein each connectivity record comprises a communication between a source computing node and a destination computing node of the plurality of computing nodes. The method includes associating the communication with an application context and protocol. The method includes processing the plurality of connectivity records to eliminate connectivity records that meet at least one criteria, wherein the plurality of connectivity records includes associated application contexts and protocols, wherein a first portion of the plurality of connectivity records comprises the eliminated connectivity records, wherein a second portion of the plurality of connectivity records comprises the remainder of the connectivity records. The method includes building a graph using the second portion of the connectivity records.


