Tiered Application Discovery in Virtual Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-tiered application environments, it is challenging to enforce network policies without identifying which individual application processes belong to which multi-tiered applications, as communications between application components cannot be determined as proper or improper without first identifying the multi-tiered application of each individual process.
Innovation Solution
A method is provided to identify and categorize guest elements in a virtual computing environment into tier groups by matching their identifiers with an inventory maintained by a management element, and monitoring communication traffic to determine the multi-tiered application for each guest element based on the communication patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network policies are enforced without identifying multi-tiered application structures, then network security can be maintained at a basic level, but proper differentiation between legitimate and improper communications cannot be achieved
Solution Approach 1:
The patent segments the application environment into distinct tiers (web server tier, application server tier, database tier) by categorizing guest elements into tier groups. This segmentation allows network policies to be enforced based on tier relationships, enabling accurate differentiation between legitimate intra-application communications and improper communications from different applications.
Solution Approach 2:
The patent introduces a management element as an intermediary that maintains an inventory of guest element identifiers and their tier group assignments. This intermediary component enables the system to automatically determine multi-tiered application structures and enforce network policies without requiring complex manual configuration or analysis of each communication pattern.
2Reliability
If communication monitoring is implemented to identify multi-tiered applications, then network security and policy enforcement are improved, but the complexity of monitoring and analyzing communication traffic increases
Solution Approach 1:
The patent performs preliminary categorization of guest elements into tier groups by matching their identifiers against the inventory maintained by the management element. This preliminary action establishes the multi-tiered application structure before communication monitoring begins, allowing the system to efficiently determine application relationships without complex real-time analysis of communication patterns.
Solution Approach 2:
The patent uses communication traffic monitoring to provide feedback that confirms or refines the identified multi-tiered application structures. By analyzing communication patterns between guest elements in different tier groups, the system validates its identification accuracy and can adjust its understanding of application relationships based on observed communication behavior.
Data Source
AI summary
The technology disclosed herein enables identification of multi-tiered applications in virtual computing elements. In a particular embodiment, a method provides identifying a plurality of guest elements executing on one or more host computing systems for a virtual computing environment and categorizing each of the plurality of guest elements into a tier group of a plurality of tier groups. The method further provides monitoring communication traffic between the plurality of guest elements and determining a multi-tiered application for each of the plurality of guest elements based on the communication traffic.


