IP Library Granted Patent US 12,596,561
Granted Patent B2
US 12,596,561 · App. 16/234,424 · Granted Apr 7, 2026

System and method of dynamically assigning device tiers based on application

Inventors: Francis Niestemski (Longmeadow, MA); Devin Blinn Avery (Madbury, NH); Ryan E. Perkowski (Middletown, DE); Nicholas York (San Ramon, CA)
Assignee: Virtual Instruments Worldwide, Inc.
G06F9/45558G06F9/5077H04L41/0233H04L41/06H04L41/065H04L41/0681H04L41/0896H04L41/145H04L43/026H04L43/0876H04L43/12H04L43/16H04L47/2441H04L47/2483H04L67/1097G06F2009/4557G06F2009/45591G06F2009/45595H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,596,561
App. No.
16/234,424
Granted
Apr 7, 2026
Kind
B2
Abstract

A method comprises receiving a virtual machine identifiers, receiving VM identifier indicating an application instance, for each application instance: determining a tier of service, assigning the tier of service to the VM executing that particular application, assigning a polling interval to the application instance based on the assigned tier of service, retrieving metrics from each application instances at the polling interval, for each of the plurality of VM: determining a mapping that maps each virtual machine to a host, assigning the tier of service to the host, assigning at least one polling interval to the VM, retrieving metrics of the VM at the assigned polling interval, assigning a polling interval to each host, retrieving metrics from each hosts at the assigned polling interval, comparing each of the received metrics associated tier metrics thresholds, if an alarm trigger condition is satisfied, then triggering an alarm event, and outputting an alarm notification.

Claims (96)

1 . A system comprising:

one or more processors; and

memory containing instructions configured to control the one or more processors to:

execute a plurality of application instances of an enterprise network;

execute a plurality of virtual machines of the enterprise network that execute at least one of the plurality of application instances;

receive a plurality of application identifiers, each of the plurality of application identifiers identifying at least one of the plurality of executing application instances of the enterprise network;

receive a plurality of virtual machine (VM) identifiers, each of the plurality of virtual machine identifiers identifying one executing virtual machine of the plurality of executing virtual machines of the enterprise network executing at least one of the plurality of application instances;

determine, based on the received application identifiers and the virtual machine identifiers, which of the plurality of application instances of the enterprise network is executing on which one of the plurality of virtual machines;

for each executing application instance:

determine a tier of service of that particular application instance;

assign the tier of service that particular application instance to the virtual machine executing that particular application instance;

assign at least one polling interval to the application instance based on that particular application instance's assigned tier of service, each polling interval indicating a time when metrics are retrieved from that particular application instance; and

retrieve metrics from each of the plurality of application instances at the assigned polling interval;

for each of the plurality of executing virtual machines:

determine a mapping that maps each of the plurality of virtual machines to a host of a plurality of hosts of the enterprise network executing that virtual machine;

assign the tier of service at that particular virtual machine to the host executing that particular virtual machine;

assign at least one polling interval to the virtual machine based on that particular virtual machine's assigned tier of service, each polling interval indicating a time when metrics are retrieved from that particular virtual machine; and

retrieve metrics from the virtual machine at the assigned polling interval;

assign at least one polling interval to each host based on that particular host's tier of service, each polling interval indicating a time when metrics are retrieved from that particular host, wherein for each host with two or more tiers of service, assigning one polling interval based on the most important tier of service of the two or more tiers of service of that host;

retrieve metrics from each of the plurality of hosts at the assigned polling interval;

compare each of the received metrics from each of the plurality of application instances to a first tier metric threshold, the first tier metric threshold being based on a type of the particular metric retrieved and the particular tier of service for that application;

compare each of the received metrics from each of the plurality of virtual machines to a second tier metric threshold, the second tier metric threshold being based on a type of the particular metric retrieved and the particular tier of service for that virtual machine;

compare each of the received metrics from each of the plurality of host to a third tier metric threshold, the third tier metric threshold being based on a type of the particular metric retrieved and the particular tier of service for that host;

determine, based on the comparisons, whether an alarm trigger condition is satisfied;

in response to determining the alarm trigger condition is satisfied, trigger an alarm event;

output an alarm notification, the alarm notification based on the alarm event, the alarm notification identifying the application, the tier of service of the application and metric that triggered the alarm event;

detect an increased computing load of a particular application instance of the plurality of executing application instances;

in response to detecting the increased computing load of the particular application instance, add an execution of an additional application instance, wherein the additional application instance inherits the tier service of the particular application instance; and

in response to adding the additional application instance, adjust the alarm trigger condition.

2 . The system of claim 1 further comprising:

at least a subset of different virtual machines with different tiers of service having different polling intervals.

3 . The system of claim 1 , wherein the tier of service for that particular application instance is retrieved from an IT management software.

4 . The system of claim 1 , wherein the tier of service for that particular application instance is retrieved from an application performance integration platform.

5 . The system of claim 1 , wherein the tier of service for that particular application instance is retrieved from a user of the enterprise.

6 . The system of claim 1 wherein the plurality of virtual machine identifiers are retrieved from a plurality of virtual machine data probes integrated within the enterprise network.

7 . The system of claim 1 wherein the first tier metric threshold is configured by a user of the enterprise network.

8 . A method comprising:

executing a plurality of application instances of an enterprise network;

executing a plurality of virtual machines of the enterprise network that execute at least one of the plurality of application instances;

receiving a plurality of application identifiers, each of the plurality of application identifiers identifying at least one of the plurality of executing application instances of the enterprise network;

receiving a plurality of virtual machine (VM) identifiers, each of the plurality of virtual machine identifiers identifying one executing virtual machine of the plurality of executing virtual machines of the enterprise network executing at least one of the plurality of application instances;

determining, based on the received application identifiers and the virtual machine identifiers indicating which of the plurality of application instances of the enterprise network is executing on which one of the plurality of virtual machines;

for each executing application instance:

determining a tier of service of that particular application instance;

assigning the tier of service that particular application instance to the virtual machine executing that particular application;

assigning at least one polling interval to the application instance based on that particular application instance's assigned tier of service, each polling interval indicating a time when metrics are retrieved from that particular application instance; and

retrieving metrics from each of the plurality of application instances at the assigned polling interval;

for each of the plurality of executing virtual machines:

determining a mapping that maps each of the plurality of virtual machines to a host of a plurality of hosts of the enterprise network executing that virtual machine;

assigning the tier of service at that particular virtual machine to the host executing that particular virtual machine;

assigning at least one polling interval to the virtual machine based on that particular virtual machine's assigned tier of service, each polling interval indicating a time when metrics are retrieved from that particular virtual machine; and

retrieving metrics the virtual machine at the assigned polling interval;

assigning at least one polling interval to each host based on that particular host's tier of service, each polling interval indicating a time when metrics are retrieved from that particular host, wherein for each host with two or more tiers of service, assigning one polling interval based on the most important tier of service of the two or more tiers of service of that host;

retrieving metrics from each of the plurality of hosts at the assigned polling interval;

comparing each of the received metrics from each of the plurality of application instances to a first tier metric threshold, the first tier metric threshold being based on a type of the particular metric retrieved and the particular tier of service for that application;

comparing each of the received metrics from each of the plurality of virtual machines to a second tier metric threshold, the second tier metric threshold being based on a type of the particular metric retrieved and the particular tier of service for that virtual machine;

comparing each of the received metrics from each of the plurality of host to a third tier metric threshold, the third tier metric threshold being based on a type of the particular metric retrieved and the particular tier of service for that host;

determining, based on the comparisons, whether an alarm trigger condition is satisfied;

in response to determining the alarm trigger condition is satisfied, trigger an alarm event;

outputting an alarm notification, the alarm notification based on the alarm event, the alarm notification identifying the application, the tier of service of the application and metric that triggered the alarm event;

detecting an increased computing load of a particular application instance of the plurality of executing application instances;

in response to detecting the increased computing load of the particular application instance, adding an execution of an additional application instance, wherein the additional application instance inherits the tier service of the particular application instance;

in response to adding the additional application instance, adjusting the alarm trigger condition.

9 . The method of claim 8 further comprising at least a subset of different virtual machines with different tiers of service having different polling intervals.

10 . The method of claim 8 wherein the tier of service for that particular application instance is retrieved from an IT management software.

11 . The method of claim 8 wherein the tier of service for that particular application instance is retrieved from an application performance integration platform.

12 . The method of claim 8 wherein the tier of service for that particular application instance is retrieved from a user of the enterprise.

13 . The method of claim 8 wherein the plurality of virtual machine identifiers are retrieved from a plurality of virtual machine data probes integrated within the enterprise network.

14 . The method of claim 8 wherein the first tier metric threshold is configured by a user of the enterprise network.

15 . A computer program product comprising a non-transitory machine readable medium having program code embodied therewith, the program code executable by a computing system to cause the computing system to perform:

executing a plurality of application instances of an enterprise network;

executing a plurality of virtual machines of the enterprise network that execute at least one of the plurality of application instances;

receiving a plurality of application identifiers, each of the plurality of application identifiers identifying at least one of the plurality of executing application instances of the enterprise network;

receiving a plurality of virtual machine (VM) identifiers, each of the plurality of virtual machine identifiers identifying one executing virtual machine of the plurality of executing virtual machines of the enterprise network executing at least one of the plurality of application instances;

determining, based on the received application identifiers and the virtual machine identifiers indicating which of the plurality of application instances of the enterprise network is executing on which one of the plurality of virtual machines;

for each executing application instance:

determining a tier of service of that particular application instance;

assigning the tier of service that particular application instance to the virtual machine executing that particular application;

assigning at least one polling interval to the application instance based on that particular application instance's assigned tier of service, each polling interval indicating a time when metrics are retrieved from that particular application instance; and

retrieving metrics from each of the plurality of application instances at the assigned polling interval;

for each of the plurality of executing virtual machines:

determining a mapping that maps each of the plurality of virtual machines to a host of a plurality of hosts of the enterprise network executing that virtual machine;

assigning the tier of service at that particular virtual machine to the host executing that particular virtual machine;

assigning at least one polling interval to the virtual machine based on that particular virtual machine's assigned tier of service, each polling interval indicating a time when metrics are retrieved from that particular virtual machine; and

retrieving metrics the virtual machine at the assigned polling interval;

assigning at least one polling interval to each host based on that particular host's tier of service, each polling interval indicating a time when metrics are retrieved from that particular host, wherein for each host with two or more tiers of service, assigning one polling interval based on the most important tier of service of the two or more tiers of service of that host;

retrieving metrics from each of the plurality of hosts at the assigned polling interval;

comparing each of the received metrics from each of the plurality of application instances to a first tier metric threshold, the first tier metric threshold being based on a type of the particular metric retrieved and the particular tier of service for that application;

comparing each of the received metrics from each of the plurality of virtual machines to a second tier metric threshold, the second tier metric threshold being based on a type of the particular metric retrieved and the particular tier of service for that virtual machine;

comparing each of the received metrics from each of the plurality of host to a third tier metric threshold, the third tier metric threshold being based on a type of the particular metric retrieved and the particular tier of service for that host;

determining, based on the comparisons, whether an alarm trigger condition is satisfied;

in response to determining the alarm trigger condition is satisfied, trigger an alarm event;

outputting an alarm notification, the alarm notification based on the alarm event, the alarm notification identifying the application, the tier of service of the application and metric that triggered the alarm event;

detecting an increased computing load of a particular application instance of the plurality of executing application instances;

in response to detecting the increased computing load of the particular application instance, adding an execution of an additional application instance, wherein the additional application instance inherits the tier service of the particular application instance;

in response to adding the additional application instance, adjusting the alarm trigger condition.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2022
From: VIRTUAL INSTRUMENTS CORPORATION
To: VIRTUAL INSTRUMENTS WORLDWIDE, INC.
Reel/Frame 059964/0258 →
SECURITY INTEREST Recorded Jan 10, 2022
From: VIRTUAL INSTRUMENTS CORPORATION; VIRTUAL INSTRUMENTS WORLDWIDE, INC.; XANGATI, INC.
To: MIDTOWN MADISON MANAGEMENT LLC
Reel/Frame 058668/0268 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2020
From: NIESTEMSKI, FRANCIS; AVERY, DEVIN BLINN; PERKOWSKI, RYAN E.; YORK, NICHOLAS
To: VIRTUAL INSTRUMENTS CORPORATION
Reel/Frame 053233/0326 →
Continuity (2)
Provisional Application 62611892 · Dec 29, 2017
Related Publication 20190205153A1 · Jul 4, 2019
References Cited (121)
US 6421809B1 · Wuytack et al. · 2002 [cited by applicant]
US 6480470B1 · Breivik · 2002 [cited by applicant]
US 6499107B1 · Gleichauf et al. · 2002 [cited by applicant]
US 7185192B1 · Kahn · 2007 [cited by applicant]
US 7193968B1 · Kapoor et al. · 2007 [cited by applicant]
US 7634595B1 · Brown · 2009 [cited by applicant]
US 7711822B1 · Duvur et al. · 2010 [cited by applicant]
US 7783740B2 · Siorek et al. · 2010 [cited by applicant]
US 8065133B1 · Asbridge · 2011 [cited by applicant]
US 8495611B2 · McCarthy · 2013 [cited by examiner]
US 8589552B1 · Jones · 2013 [cited by examiner]
US 8738972B1 · Bakman · 2014 [cited by examiner]
US 9026687B1 · Govande · 2015 [cited by applicant]
US 9462077B2 · Zohar et al. · 2016 [cited by applicant]
US 9928183B2 · Svendsen · 2018 [cited by examiner]
US 10044566B1 · Grisco · 2018 [cited by applicant]
US 10216812B2 · Witkop · 2019 [cited by applicant]
US 10505959B1 · Wang · 2019 [cited by applicant]
US 10735430B1 · Stoler · 2020 [cited by examiner]
US 20020083169A1 · Aki · 2002 [cited by examiner]
US 20020156883A1 · Natarajan · 2002 [cited by applicant]
US 20030095504A1 · Ogier · 2003 [cited by examiner]
US 20030167327A1 · Baldwin · 2003 [cited by applicant]
US 20040083285A1 · Nicolson · 2004 [cited by applicant]
US 20050081208A1 · Gargya · 2005 [cited by applicant]
US 20050229182A1 · Grover · 2005 [cited by applicant]
US 20060129415A1 · Thukral et al. · 2006 [cited by applicant]
US 20060184626A1 · Agapi · 2006 [cited by applicant]
US 20060242647A1 · Kimbrel · 2006 [cited by applicant]
US 20060271677A1 · Mercier · 2006 [cited by applicant]
US 20070136541A1 · Herz · 2007 [cited by examiner]
US 20070169125A1 · Qin · 2007 [cited by applicant]
US 20070180280A1 · Bolan · 2007 [cited by examiner]
US 20080019499A1 · Benfield · 2008 [cited by applicant]
US 20080104248A1 · Yahiro · 2008 [cited by examiner]
US 20090016236A1 · Alcala · 2009 [cited by applicant]
US 20090025004A1 · Barnard · 2009 [cited by examiner]
US 20090106256A1 · Safari · 2009 [cited by applicant]
US 20090125909A1 · Li · 2009 [cited by examiner]
US 20090198766A1 · Chen · 2009 [cited by examiner]
US 20090241113A1 · Seguin · 2009 [cited by applicant]
US 20090259749A1 · Barrett · 2009 [cited by applicant]
US 20090319580A1 · Lorenz · 2009 [cited by applicant]
US 20100248771A1 · Brewer · 2010 [cited by examiner]
US 20100275212A1 · Saha et al. · 2010 [cited by applicant]
US 20110107148A1 · Franklin · 2011 [cited by examiner]
US 20110141119A1 · Ito · 2011 [cited by examiner]
US 20110225017A1 · Radhakrishnan · 2011 [cited by applicant]
US 20120030352A1 · Sauma Vargas · 2012 [cited by applicant]
US 20120044811A1 · White · 2012 [cited by applicant]
US 20120076001A1 · Saitou · 2012 [cited by examiner]
US 20120089726A1 · Doddavula · 2012 [cited by examiner]
US 20120131593A1 · DePetro · 2012 [cited by applicant]
US 20120192197A1 · Doyle · 2012 [cited by applicant]
US 20120221810A1 · Shah et al. · 2012 [cited by applicant]
US 20130054221A1 · Artzi et al. · 2013 [cited by applicant]
US 20130060932A1 · Ofek · 2013 [cited by applicant]
US 20130067089A1 · Synytskyy · 2013 [cited by examiner]
US 20130117847A1 · Friedman · 2013 [cited by applicant]
US 20130152200A1 · Alme · 2013 [cited by applicant]
US 20130185729A1 · Vasic · 2013 [cited by examiner]
US 20130285855A1 · Dupray et al. · 2013 [cited by applicant]
US 20130340079A1 · Gottlieb et al. · 2013 [cited by applicant]
US 20140052610A1 · Aggarwal et al. · 2014 [cited by applicant]
US 20140112187A1 · Kang · 2014 [cited by applicant]
US 20140164957A1 · Shin et al. · 2014 [cited by applicant]
US 20140173034A1 · Liu · 2014 [cited by examiner]
US 20140173113A1 · Vemuri · 2014 [cited by examiner]
US 20140181839A1 · Xu et al. · 2014 [cited by applicant]
US 20140331277A1 · Frascadore · 2014 [cited by applicant]
US 20140358972A1 · Guarrieri et al. · 2014 [cited by applicant]
US 20150046920A1 · Allen · 2015 [cited by applicant]
US 20150074251A1 · Tameshige · 2015 [cited by applicant]
US 20150222527A1 · Shah · 2015 [cited by examiner]
US 20160004475A1 · Beniyama · 2016 [cited by applicant]
US 20160044035A1 · Huang · 2016 [cited by applicant]
US 20160055038A1 · Ghosh · 2016 [cited by examiner]
US 20160100066A1 · Yamada · 2016 [cited by examiner]
US 20160119234A1 · Valencia Lopez · 2016 [cited by applicant]
US 20160275642A1 · Abeykoon et al. · 2016 [cited by applicant]
US 20160359897A1 · Yadav · 2016 [cited by applicant]
US 20170034207A1 · Low et al. · 2017 [cited by applicant]
US 20170053076A1 · Lulla · 2017 [cited by examiner]
US 20170085456A1 · Whitner · 2017 [cited by examiner]
US 20170123849A1 · Tian · 2017 [cited by applicant]
US 20170168866A1 · Kono · 2017 [cited by applicant]
US 20170201574A1 · Luo · 2017 [cited by examiner]
US 20170293414A1 · Pierce · 2017 [cited by examiner]
US 20170317899A1 · Taylor · 2017 [cited by applicant]
US 20180067776A1 · Chen · 2018 [cited by examiner]
US 20180081501A1 · Johnston · 2018 [cited by examiner]
US 20180115585A1 · Rubakha · 2018 [cited by applicant]
US 20180130202A1 · Wang et al. · 2018 [cited by applicant]
US 20180165451A1 · Kawakita · 2018 [cited by applicant]
US 20180262432A1 · Ozen · 2018 [cited by examiner]
US 20180322415A1 · Bendre et al. · 2018 [cited by applicant]
US 20180324045A1 · Grisco · 2018 [cited by applicant]
US 20180329794A1 · Prieto et al. · 2018 [cited by applicant]
US 20190065230A1 · Tsirkin · 2019 [cited by applicant]
US 20190073239A1 · Konnath · 2019 [cited by examiner]
US 20190089617A1 · Raney · 2019 [cited by applicant]
US 20190163589A1 · McBride · 2019 [cited by applicant]
US 20190171509A1 · Hardy et al. · 2019 [cited by applicant]
US 20190243671A1 · Yadav · 2019 [cited by applicant]
US 20190311629A1 · Sierra et al. · 2019 [cited by applicant]
EP 2262173 · 2010 [cited by applicant]
International Application No. PCT/US2018/067760, International Search Report and Written Opinion dated Mar. 8, 2019. [cited by applicant]
Androulidakis, G. et al., “Improving Network Anomaly Detection via Selective Flow-Based Sampling,” IET Communications, vol. 2, No. 3, pp. 399-409, Mar. 2008. [cited by applicant]
Cejka, Tomas et al., “Nemea: A Framework for Network Traffic Analysis,” Proceedings of the 12th Conference on Network and Service Management (CNSM 2016), pp. 195-201, Nov. 2016. [cited by applicant]
Chandramouli, Ramaswamy, “Security Assurance Requirements for Hypervisor Deployment Features,” Seventh International Conference on Digital Society, Feb. 2013. [cited by applicant]
Kind, Andreas et al., “Histogram-Based Traffic Anomaly Detection,” IEEE Transactions on Network Service Management, vol. 6, No. 2, pp. 110-121, Jun. 2009. [cited by applicant]
Ramamoorthy, S. et al. “A Preventive Method for Host Level Security in Cloud Infrastructure,” Proceedings of the 3rd International Symposium on Big Data and Cloud Computing Challenges, Feb. 2016. [cited by applicant]
Sethi, Chhabi et al., “Trusted-Cloud: A Cloud Security Model for Infrastructure as a Service (laaS),” International Journal of Advanced Research in Computer Science and Software Engineering, vol. 6, No. 3, Mar. 2016. [cited by applicant]
Urias, Vincent E. et al., “Hypervisor Assisted Forensics and Incident Response in the Cloud,” 2016 IEEE International Conference on Computer and Information Technology, Dec. 2016. [cited by applicant]
Wang, Wei et al., “Network Traffic Monitoring, Analysis and Anomaly Detection,” Guest Editorial, IEEE Network, pp. 6-7, May 2011. [cited by applicant]
International Application No. PCT/US2019/058976, Search Report and Written Opinion dated Mar. 25, 2020. [cited by applicant]
International Application No. PCT/US2019/059282, Search Report and Written Opinion dated Apr. 7, 2020. [cited by applicant]
Bhumip Khasnabish “Emerging Enterprise Storage Systems: Storage or System Area Networks (SANs)”, [Online], pp. 192-195, [Retrieved from Internet on Aug. 25, 2021], , (Year: 2002). [cited by applicant]
Suresh Muknahallipatna et al., “The Effect of End to End Latency in a Distributed Storage Area Network on Microsoft Exchangew Server 2003 Performance”, [Online], pp. 1-9, [Retrieved from Inter3ent on Aug. 25, 2021], (Ye… [cited by applicant]
T. Brothers, N. Mandagere et al., “Microsoft Exchange Implementation on A Distributed Storage Area Network”, [Online], pp. 251-251, [Retrieved from Internet on Aug. 25, 2021], , (Year: 2008). [cited by applicant]
Vladimir V. Riabov, “Storage Area Networks (SANs)”, [Online], pp. 1-11, [Retrieved from Internet on Aug. 25, 2021], (Year: 2005). [cited by applicant]