IP Library Granted Patent US 12,190,139
Granted Patent B1
US 12,190,139 · App. 17/690,525 · Granted Jan 7, 2025

Secure support of customization scripts using pipelining

Inventors: Dean Connable Wills (Berkeley, CA); Karthik Krishnamurthy (San Ramon, CA); Ivan Sopin (Dublin, CA); Allan Bradley Winslow (Rancho Mission Viejo, CA); Brian Henry Kirouac (Cupertino, CA); Senthilnathan Arunagirinathan (Fremont, CA)
Assignee: Cisco Technology, Inc.
G06F9/45512G06F21/629
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,190,139
App. No.
17/690,525
Filed
Mar 9, 2022
Granted
Jan 7, 2025
Kind
B1
Art Unit
2192
USPC
717/132
Abstract

In one embodiment, a device performs a detection stage of an automated instrumentation pipeline during which the device detects an application server type by examining a command line of a process of an application. The device performs, based on the application server type, an extraction stage of the automated instrumentation pipeline during which the device extracts application server attributes. The device performs, based on the application server attributes, a naming stage of the automated instrumentation pipeline during which the device forms a naming hierarchy for processes of the application. The detection stage, the extraction stage, and the naming stage of the automated instrumentation pipeline do not have access to a controlled space of the application. The device inserts, based in part on the naming hierarchy, arguments into command lines of processes of the application that cause the processes of the application to be instrumented at runtime.

Claims (44)

1. A method comprising:

performing, by a device, a detection stage of an automated instrumentation pipeline during which the device detects an application server type by examining a command line of a process of an application;

performing, by the device and based on the application server type, an extraction stage of the automated instrumentation pipeline during which the device extracts application server attributes;

performing, by the device and based on the application server attributes, a naming stage of the automated instrumentation pipeline during which the device forms a naming hierarchy for processes of the application,

wherein the detection stage, the extraction stage, and the naming stage of the automated instrumentation pipeline do not have access to a controlled space of the application; and

inserting, by the device and based in part on the naming hierarchy, arguments into command lines of processes of the application that cause the processes of the application to be instrumented at runtime.

2. The method as in claim 1 , wherein the controlled space of the application comprises at least one of: a file system or a network connection associated with the application.

3. The method as in claim 1 , wherein the application server type comprises at least one of: Tomcat, JBoss, Glassfish, WebLogic, or WebSphere.

4. The method as in claim 1 , further comprising:

injecting a preload library into each process of the application, to capture command line arguments of that process.

5. The method as in claim 1 , wherein processes of the application that perform a same function are grouped by the naming hierarchy as a single tier.

6. The method as in claim 1 , wherein the device performs the naming stage of the automated instrumentation pipeline according to one or more defined naming rules.

7. The method as in claim 1 , further comprising:

disabling instrumentation for a portion of the application, using the naming hierarchy.

8. The method as in claim 1 , wherein the detection stage, the extraction stage, and the naming stage are performed in a sandbox environment.

9. The method as in claim 1 , further comprising:

constructing an attribute map for a particular process of the application indicative of a process identifier, its command line arguments, environment variables, and a current working directory, wherein the device performs the detection stage on the particular process based in part on the attribute map.

10. The method as in claim 1 , wherein the application is a Java application.

11. An apparatus, comprising:

one or more network interfaces;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process when executed configured to:

perform a detection stage of an automated instrumentation pipeline during which the apparatus detects an application server type by examining a command line of a process of an application;

perform, based on the application server type, an extraction stage of the automated instrumentation pipeline during which the apparatus extracts application server attributes;

perform, based on the application server attributes, a naming stage of the automated instrumentation pipeline during which the apparatus forms a naming hierarchy for processes of the application,

wherein the detection stage, the extraction stage, and the naming stage of the automated instrumentation pipeline do not have access to a controlled space of the application; and

insert, based in part on the naming hierarchy, arguments into command lines of processes of the application that cause the processes of the application to be instrumented at runtime.

12. The apparatus as in claim 11 , wherein the controlled space of the application comprises at least one of: a file system or a network connection associated with the application.

13. The apparatus as in claim 11 , wherein the application server type comprises at least one of: Tomcat, JBoss, Glassfish, WebLogic, or WebSphere.

14. The apparatus as in claim 11 , wherein the process when executed is further configured to:

inject a preload library into each process of the application, to capture command line arguments of that process.

15. The apparatus as in claim 11 , wherein processes of the application that perform a same function are grouped by the naming hierarchy as a single tier.

16. The apparatus as in claim 11 , wherein the apparatus performs the naming stage of the automated instrumentation pipeline according to one or more defined naming rules.

17. The apparatus as in claim 11 , wherein the process when executed is further configured to:

disable instrumentation for a portion of the application, using the naming hierarchy.

18. The apparatus as in claim 11 , wherein the detection stage, the extraction stage, and the naming stage are performed in a sandbox environment.

19. The apparatus as in claim 11 , wherein the process when executed is further configured to:

construct an attribute map for a particular process of the application indicative of a process identifier, its command line arguments, environment variables, and a current working directory, wherein the apparatus performs the detection stage on the particular process based in part on the attribute map.

20. A tangible, non-transitory, computer-readable medium storing program instructions that cause a device to execute a process comprising:

performing, by the device, a detection stage of an automated instrumentation pipeline during which the device detects an application server type by examining a command line of a process of an application;

performing, by the device and based on the application server type, an extraction stage of the automated instrumentation pipeline during which the device extracts application server attributes;

performing, by the device and based on the application server attributes, a naming stage of the automated instrumentation pipeline during which the device forms a naming hierarchy for processes of the application,

wherein the detection stage, the extraction stage, and the naming stage of the automated instrumentation pipeline do not have access to a controlled space of the application; and

inserting, by the device and based in part on the naming hierarchy, arguments into command lines of processes of the application that cause the processes of the application to be instrumented at runtime.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE 4TH INVENTOR'S NAME PREVIOUSLY RECORDED AT REEL: 059211 FRAME: 0146. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 17, 2022
From: WILLS, DEAN CONNABLE; KRISHNAMURTHY, KARTHIK; SOPIN, IVAN; WINSLOW, ALLAN BRADLEY; KIROUAC, BRIAN HENRY; ARUNAGIRINATHAN, SENTHILNATHAN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 059691/0888 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2022
From: WILLS, DEAN CONNABLE; KRISHNAMURTHY, KARTHIK; SOPIN, IVAN; WINSLOW, ALLEN BRADLEY; KIROUAC, BRIAN HENRY; ARUNAGIRINATHAN, SENTHILNATHAN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 059211/0146 →
Continuity (1)
Provisional Application 63194896 · May 28, 2021
References Cited (15)
US 11093518B1 · Lu · 2021 [cited by examiner]
US 11106442B1 · Hsiao · 2021 [cited by examiner]
US 11436328B1 · Strogov · 2022 [cited by examiner]
US 20050091582A1 · Snover et al. · 2005 [cited by applicant]
US 20110145786A1 · Fayed et al. · 2011 [cited by applicant]
US 20110219208A1 · Asaad · 2011 [cited by examiner]
US 20170078161A1 · Cimprich et al. · 2017 [cited by applicant]
US 20170161044A1 · Singh et al. · 2017 [cited by applicant]
US 20190116209A1 · Harrison et al. · 2019 [cited by applicant]
“Install OneAgent on Linux”, online: https://www.dynatrace.com/support/help/technology-support/operating-systems/linux/installation/install-oneagent-on-linux/, accessed Jun. 10, 2021, 8 pages, Dynatrace LLC. [cited by applicant]
“Customize the Names of Process Groups”, online: https://www.dynatrace.com/support/help/how-to-use-dynatrace/process-groups/configuration/customize-the-name-of-process-groups/, accessed Jun. 10, 2021, 5 pages, DynaTrace… [cited by applicant]
“Customize the Structure of Process Groups”, online: https://www.dynatrace.com/support/help/how-to-use-dynatrace/process-groups/configuration/adapt-the-composition-of-default-process-groups/, accessed Jun. 10, 2021, 5 p… [cited by applicant]
“Cobra”, online: https://github.com/spf13/cobra, accessed Feb. 9, 2020, 5 pages, github.com. [cited by applicant]
“Id.so, LD-Linux.so—Dynamic Linker/Loader”, online: https://man7.org/linux/man-pages/man8/ld.so.8.html, accessed Feb. 9, 2022, 13 pages. [cited by applicant]
“Policy Language” online: https://www.openpolicyagent.org/docs/latest/policy-language/, accessed Feb. 9, 2022, 51 pages. [cited by applicant]