Network Component Discovery via Flow Data Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large computer networks, obtaining credentials for discovery operations can be time-consuming and challenging, leading to incomplete or delayed identification of components, especially when credentials are unavailable for certain components.
Innovation Solution
The system identifies attributes of components without available credentials by analyzing network flow data, determining sequences of connections between components, and inferring attributes based on these sequences, allowing for partial identification and mapping of service models within the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If discovery operations are performed using traditional credential-based methods, then components with available credentials can be identified accurately, but components without credentials cannot be identified, leading to incomplete network mapping
Solution Approach 1:
The patent uses network flow data as an intermediary to identify components without credentials. Instead of directly authenticating with each component, the system observes and analyzes network traffic patterns between components to infer their identities and relationships, thereby bypassing the credential requirement barrier
Solution Approach 2:
The patent replaces the mechanical credential-based authentication system with an observational network flow analysis system. Rather than using keys, passwords, or certificates to access component information, the system substitutes this with passive monitoring and analysis of network traffic patterns to deduce component identities
2Measurement precision
If administrators manually obtain credentials for each component, then complete identification can be achieved, but the time and effort required increase significantly
Solution Approach 1:
The system performs self-service discovery by automatically analyzing network flow data to identify components without human intervention. The network traffic itself provides the information needed for identification, eliminating the need for administrators to manually collect credentials from each component
Solution Approach 2:
The patent performs preliminary network flow data collection and analysis to establish component identities before formal discovery operations. By pre-analyzing traffic patterns and building a map of component relationships, the system prepares identification information in advance, avoiding time-consuming credential collection during the discovery process
3Reliability
If discovery services are deployed on-premises, then local network control is improved, but the complexity of deployment and maintenance increases
Solution Approach 1:
The patent creates a universal discovery mechanism that works across different deployment environments (on-premises, cloud, hybrid) by using network flow data, which is universally generated by all network traffic. This single approach replaces multiple environment-specific discovery methods, simplifying deployment while maintaining local network control
Data Source
AI summary
Identifying components of a computer network based on connections between the components includes performing a first discovery operation to identify respective attributes of a first set of components and performing a second discovery operation to infer respective components of the second set of components not identifiable by the first discovery operation. The second discovery operation is performed by sending probes for collecting network flow data indicative of network flows between components of the first set of components and other components of the computer network. The collected network flow data is used to identify connections between ones of the first set of components and ones of the other components, determining sequences of the identified connections, and infer respective attributes of at least some of the second set of components based on the determined sequences of the identified connections.


