Workload Traffic Visualization Using Tagged Multi-Ring Network Maps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack effective methods for decentralized monitoring and visualization of network traffic among application workloads in virtualized data centers, making it difficult for operators to manage and troubleshoot complex communication flows.

Innovation Solution

A graphical user interface is generated to depict application workloads with multi-ring structures, using tags to categorize and visualize communications, and provide visual indications of policy rule applications, allowing users to filter and drill down for detailed information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If decentralized monitoring of network traffic among application workloads is implemented, then visibility into communication flows is improved, but system complexity increases

Engineering Contradiction:
Improvevisibility into communication flowsVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent introduces policy agents as intermediary components deployed within the virtualization infrastructure. These agents collect and report network traffic data between workloads, acting as mediators that enable centralized visibility without requiring direct complex instrumentation of every workload communication path. The agents simplify the monitoring architecture by consolidating data collection functions at strategic points in the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If detailed visualization of workload communications is provided, then troubleshooting capability is improved, but information overload occurs

Engineering Contradiction:
Improvetroubleshooting capabilityVSAvoidinformation volume
Core Design Contradiction:
Difficulty of detecting and measuringVSQuantity of substance

Solution Approach 1:

The visualization interface is segmented into multiple hierarchical levels, allowing users to progress from high-level workload groupings to detailed communication paths only when needed. The system divides network traffic information into categories and subcategories, enabling operators to focus on specific segments of the network rather than being presented with all traffic data simultaneously. This segmented approach maintains troubleshooting capability while preventing information overload.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds hierarchical dimensionality to the visualization, organizing workloads into multiple levels of abstraction (workload groups, individual workloads, communication paths). This dimensional organization allows operators to navigate through layers of information, viewing only the relevant level of detail for their current task, thereby managing information volume while maintaining comprehensive troubleshooting capability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If security policy rules are applied to workload communications, then security control is improved, but operational complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The policy agents operate autonomously within the virtualization infrastructure, automatically collecting traffic data and applying security policy rules without requiring manual configuration for each communication path. The system enables security control through self-service mechanisms where the infrastructure itself enforces policies, reducing operational complexity while maintaining strong security controls.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security policy rules are established in advance and configured at higher levels of the hierarchy before deployment to workloads. This preliminary configuration allows security controls to be applied automatically when workloads are created or modified, reducing operational complexity by eliminating the need for manual policy application to each individual communication path while maintaining comprehensive security control.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12489688B1Inter-application workload network traffic monitoring and visualization
Publication Date: 2025.12.02 JUNIPER NETWORKS INC
  • US12489688B1 patent drawing
  • US12489688B1 patent drawing
  • US12489688B1 patent drawing

AI summary

Graphical user interfaces are generated that, when displayed, provide a visual and interactive representation of one or more aspects associated with the execution of one or more applications on a computer network. The graphical user interfaces may in include graphical depictions representation policy objects, each policy object assigned one or more tags, each tag assigned to a category or a sub-category. The tags, when taken in combination, may identify an application, and one or more other characteristics associated with each of the policy objects. The graphical elements representing the policy objects may be displayed in the graphical user interfaces so that the policy objects assigned to tags in a category are positioned in an outer ring, and policy objects assigned to sub-category tags are positioned in a inner ring surrounded by the outer ring, with interconnection elements representing communications between policy objects extending within an interior area.