Tiered Application Discovery in Virtual Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tiered application environments, it is challenging to enforce network policies without identifying which individual application processes belong to which multi-tiered applications, as communications between application components cannot be determined as proper or improper without first identifying the multi-tiered application of each individual process.

Innovation Solution

A method is provided to identify and categorize guest elements in a virtual computing environment into tier groups by matching their identifiers with an inventory maintained by a management element, and monitoring communication traffic to determine the multi-tiered application for each guest element based on the communication patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network policies are enforced without identifying multi-tiered application structures, then network security can be maintained at a basic level, but proper differentiation between legitimate and improper communications cannot be achieved

Engineering Contradiction:
Improvenetwork policy enforcement accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the application environment into distinct tiers (web server tier, application server tier, database tier) by categorizing guest elements into tier groups. This segmentation allows network policies to be enforced based on tier relationships, enabling accurate differentiation between legitimate intra-application communications and improper communications from different applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a management element as an intermediary that maintains an inventory of guest element identifiers and their tier group assignments. This intermediary component enables the system to automatically determine multi-tiered application structures and enforce network policies without requiring complex manual configuration or analysis of each communication pattern.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If communication monitoring is implemented to identify multi-tiered applications, then network security and policy enforcement are improved, but the complexity of monitoring and analyzing communication traffic increases

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary categorization of guest elements into tier groups by matching their identifiers against the inventory maintained by the management element. This preliminary action establishes the multi-tiered application structure before communication monitoring begins, allowing the system to efficiently determine application relationships without complex real-time analysis of communication patterns.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses communication traffic monitoring to provide feedback that confirms or refines the identified multi-tiered application structures. By analyzing communication patterns between guest elements in different tier groups, the system validates its identification accuracy and can adjust its understanding of application relationships based on observed communication behavior.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10445120B2Tiered application discovery
Publication Date: 2019.10.15 VMWARE INC
  • US10445120B2 patent drawing
  • US10445120B2 patent drawing
  • US10445120B2 patent drawing

AI summary

The technology disclosed herein enables identification of multi-tiered applications in virtual computing elements. In a particular embodiment, a method provides identifying a plurality of guest elements executing on one or more host computing systems for a virtual computing environment and categorizing each of the plurality of guest elements into a tier group of a plurality of tier groups. The method further provides monitoring communication traffic between the plurality of guest elements and determining a multi-tiered application for each of the plurality of guest elements based on the communication traffic.