Application Service Graph Representation for IT Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing complex information technology environments with numerous network computing devices and application processes is challenging due to the difficulty in identifying and mapping application services, their interactions, and categorizing them effectively for efficient management and security analysis.
Innovation Solution
The solution involves identifying and fingerprinting application services, grouping them using clustering techniques, analyzing interactions, and constructing a graph representation to visualize their relationships and categorize them based on defined metrics and confidence scores, allowing for focused management and security assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual identification and mapping of application services is performed, then management precision is improved, but productivity deteriorates due to time-consuming manual processes
Solution Approach 1:
The system performs automatic identification, fingerprinting, and grouping of application services without requiring manual administrator intervention. The automated fingerprinting process analyzes process characteristics and automatically clusters services into groups, eliminating the need for manual mapping while maintaining accurate service identification and relationships.
Solution Approach 2:
The patent replaces manual mechanical processes with automated computational processes. Instead of administrators manually identifying and mapping services, the system uses automated fingerprinting algorithms, clustering computations, and graph generation processes to achieve the same management objectives efficiently.
2Measurement precision
If detailed analysis of all application processes is performed, then measurement precision is improved, but device complexity increases
Solution Approach 1:
The system segments the complex task of analyzing all application processes into manageable components: fingerprinting individual processes, clustering similar processes into groups, and then analyzing interactions between groups. This segmentation allows detailed analysis to be performed systematically without overwhelming complexity.
Solution Approach 2:
The patent merges similar application processes into unified groups based on their fingerprints and characteristics. By combining processes that perform similar functions into single representative entities, the system reduces the number of individual processes that need to be analyzed separately while maintaining comprehensive coverage of all application services.
3Productivity
If automatic service identification is implemented, then productivity is improved, but reliability may deteriorate due to potential inaccuracies in automated fingerprinting
Solution Approach 1:
The system incorporates feedback mechanisms where the automated fingerprinting and grouping results are validated and refined through continuous monitoring and analysis of process interactions. The graph representation and service maps are updated based on observed behavior patterns, allowing the system to correct and improve its automated identifications over time.
Solution Approach 2:
The patent uses multiple fingerprinting parameters and characteristics to create comprehensive process identifiers. By analyzing multiple aspects of process behavior simultaneously (command line arguments, executable paths, process tree relationships), the system increases the reliability of automated identification while maintaining high productivity.
Data Source
AI summary
Identifications of program processes executing on an information technology environment are received. The identified program processes are clustered into a plurality of different groups. Identifications of interactions between at least a portion of the program processes are received. The identified interactions are analyzed to determine one or more interaction metrics between different group pairs in the plurality of different groups. A graph representation that includes at least a portion of the plurality of different groups as graph nodes in the graph representation is generated. The graph representation includes one or more graph edges determined to be included based on the one or more interaction metrics.


