Network Traffic Analysis for Application Topology Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for generating application topologies require Deep Dive Component Monitoring (DDCM) software, which impacts server performance, is time-consuming to implement, and demands compatibility with various devices and servers, especially in diverse networks like those with mobile devices and cloud computing.

Innovation Solution

Employing port spanning and mirroring techniques on network devices to gather and analyze network traffic, generating application topologies by comparing traffic patterns with predetermined and user-defined templates, thereby reducing resource usage and speeding up the process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If Deep Dive Component Monitoring (DDCM) software is installed on each device or server to generate application topologies, then monitoring accuracy and application topology generation capability are improved, but server performance deteriorates and implementation time increases

Engineering Contradiction:
Improvemonitoring accuracyVSAvoidserver performance
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts the monitoring function from individual devices by using port spanning and mirroring techniques on network devices to capture traffic. Instead of installing DDCM software on each server, the monitoring is performed externally by capturing and analyzing network traffic packets, thereby eliminating the performance impact on monitored devices while maintaining monitoring accuracy

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces network devices (switches, routers) as intermediaries that perform the actual traffic capture through port spanning and mirroring. These intermediary devices collect traffic data without requiring software installation on end devices, and forward the captured traffic to the application topology generation system, thus resolving the conflict between monitoring capability and device performance

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If Deep Dive Component Monitoring (DDCM) software is installed on each device or server to generate application topologies, then monitoring accuracy is improved, but implementation time and device complexity increase

Engineering Contradiction:
Improvemonitoring accuracyVSAvoidimplementation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent removes the requirement to install and configure DDCM software on each individual device. Instead, it extracts traffic monitoring capabilities to network infrastructure devices that already exist in the environment, eliminating time-consuming software installation, configuration, and compatibility checking across multiple devices

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent leverages the universal port spanning and mirroring capabilities that are already present in standard network devices. These multi-functional network devices can perform traffic capture for multiple different monitoring purposes without requiring device-specific software, thereby reducing implementation time and complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Extent of automation

If Deep Dive Component Monitoring (DDCM) software is installed on each device or server to generate application topologies, then application topology generation capability is improved, but compatibility requirements across diverse devices increase

Engineering Contradiction:
Improveapplication topology generation capabilityVSAvoidcompatibility with various devices
Core Design Contradiction:
Extent of automationVSAdaptability or versatility

Solution Approach 1:

The patent extracts the monitoring functionality from device-specific software installations and relocates it to network infrastructure level. By capturing traffic at the network layer through port spanning and mirroring, the system eliminates the need to adapt to different device operating systems, hardware configurations, and software versions, thereby maintaining automation capability while improving compatibility across diverse devices

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses network traffic packets as copies of the actual communication data flowing between devices. Instead of installing software on each device to monitor its operations directly, the system captures copies of traffic data through network mirroring and analyzes these copies to generate application topologies, thereby achieving device-agnostic monitoring that works across diverse device types

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9455888B2Application topology based on network traffic
Publication Date: 2016.09.27 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9455888B2 patent drawing
  • US9455888B2 patent drawing
  • US9455888B2 patent drawing

AI summary

Methods and apparatuses for generating an application topology are provided. A processor determines a first application profile based, at least in part, on a first network packet. A processor determines a second application profile based, at least in part, on a second network packet. A processor determines a link between a first application and a second application based, at least in part, on address information of the first network packet. A processor generates a topology comprising the first and second application profiles based, at least in part, on the link, the first application profile and the second application profile. A processor updates the first and second application profiles based, at least in part, on matching the first application profile and second application profile with an application deployment template.