Network Traffic Analysis for Application Topology Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for generating application topologies require Deep Dive Component Monitoring (DDCM) software, which impacts server performance, is time-consuming to implement, and demands compatibility with various devices and servers, especially in diverse networks like those with mobile devices and cloud computing.
Innovation Solution
Employing port spanning and mirroring techniques on network devices to gather and analyze network traffic, generating application topologies by comparing traffic patterns with predetermined and user-defined templates, thereby reducing resource usage and speeding up the process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If Deep Dive Component Monitoring (DDCM) software is installed on each device or server to generate application topologies, then monitoring accuracy and application topology generation capability are improved, but server performance deteriorates and implementation time increases
Solution Approach 1:
The patent extracts the monitoring function from individual devices by using port spanning and mirroring techniques on network devices to capture traffic. Instead of installing DDCM software on each server, the monitoring is performed externally by capturing and analyzing network traffic packets, thereby eliminating the performance impact on monitored devices while maintaining monitoring accuracy
Solution Approach 2:
The patent introduces network devices (switches, routers) as intermediaries that perform the actual traffic capture through port spanning and mirroring. These intermediary devices collect traffic data without requiring software installation on end devices, and forward the captured traffic to the application topology generation system, thus resolving the conflict between monitoring capability and device performance
2Measurement precision
If Deep Dive Component Monitoring (DDCM) software is installed on each device or server to generate application topologies, then monitoring accuracy is improved, but implementation time and device complexity increase
Solution Approach 1:
The patent removes the requirement to install and configure DDCM software on each individual device. Instead, it extracts traffic monitoring capabilities to network infrastructure devices that already exist in the environment, eliminating time-consuming software installation, configuration, and compatibility checking across multiple devices
Solution Approach 2:
The patent leverages the universal port spanning and mirroring capabilities that are already present in standard network devices. These multi-functional network devices can perform traffic capture for multiple different monitoring purposes without requiring device-specific software, thereby reducing implementation time and complexity
3Extent of automation
If Deep Dive Component Monitoring (DDCM) software is installed on each device or server to generate application topologies, then application topology generation capability is improved, but compatibility requirements across diverse devices increase
Solution Approach 1:
The patent extracts the monitoring functionality from device-specific software installations and relocates it to network infrastructure level. By capturing traffic at the network layer through port spanning and mirroring, the system eliminates the need to adapt to different device operating systems, hardware configurations, and software versions, thereby maintaining automation capability while improving compatibility across diverse devices
Solution Approach 2:
The patent uses network traffic packets as copies of the actual communication data flowing between devices. Instead of installing software on each device to monitor its operations directly, the system captures copies of traffic data through network mirroring and analyzes these copies to generate application topologies, thereby achieving device-agnostic monitoring that works across diverse device types
Data Source
AI summary
Methods and apparatuses for generating an application topology are provided. A processor determines a first application profile based, at least in part, on a first network packet. A processor determines a second application profile based, at least in part, on a second network packet. A processor determines a link between a first application and a second application based, at least in part, on address information of the first network packet. A processor generates a topology comprising the first and second application profiles based, at least in part, on the link, the first application profile and the second application profile. A processor updates the first and second application profiles based, at least in part, on matching the first application profile and second application profile with an application deployment template.


