IP Library › Granted Patent US 11,956,335
Granted Patent B1
US 11,956,335 · App. 17/751,504 · Granted Apr 9, 2024

Automated mapping of multi-tier applications in a distributed system

Inventors: Naveen Goela (Berkeley, CA); Rishi Kant (Foster City, CA); Andrew R. White (Apex, NC); Christian L. Hunt (Chapel Hill, NC); David Irwin (Cary, NC)
Assignee: Tanium Inc.
H04L67/75G06F16/2477H04L41/12H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,956,335
App. No.
17/751,504
Granted
Apr 9, 2024
Kind
B1
Abstract

An application mapping procedure obtains and aggregates application mapping information from a plurality of machines in a distributed system. An application dependency map, including first layer of application mapping information, is initialized, and then a first query is sent to one or more of the machines. In response, information identifying entities that have participated in predefined communications with entities identified in an existing layer of application mapping information in the application dependency map are received, and a second layer of application mapping information is added to the application dependency map, based at least in part on the information received in response to the first query. After adding the second layer of application mapping information to the application dependency map, a second query is sent to one or more of the of the endpoint machines, the second query being based at least in part on the application dependency map.

Claims (67)

1. A method of mapping applications executed by machines in a network, comprising:

at a server system connected to the network, wherein the machines in the network comprise a plurality of endpoint machines distinct from the server system, performing an application mapping procedure comprising:

initializing an application dependency map, including adding a first layer of application mapping information to the application dependency map, wherein the application dependency map identifies relationships among application components of one or more multi-tier applications;

sending a first query to one or more of the endpoint machines;

receiving, in response to the first query, information identifying application components that have participated in predefined communications with application components identified in an existing layer of application mapping information in the application dependency map;

adding a second layer of application mapping information to the application dependency map, based at least in part on the information received in response to the first query;

after adding the second layer of application mapping information to the application dependency map, sending a second query to one or more of the of the endpoint machines, the second query being based at least in part on the application dependency map.

2. The method of claim 1 , wherein

the plurality of endpoint machines in the network are located at respective nodes in one or more non-static collections of nodes, each non-static collection of nodes forming a linear communication orbit;

the network includes one or more linear communication orbits; and

sending the first query to one or more of the endpoint machines in the network comprises sending the first query via the one or more linear communication orbits.

3. The method of claim 1 , wherein performing the application mapping procedure includes receiving, in response to the first query, information identifying application components of the one or more multi-tier applications that have participated in predefined communications with application components identified in a most recently generated or added layer of application mapping information in the application dependency map.

4. The method of claim 3 , wherein performing the application mapping procedure further includes:

receiving, in response to the second query, information identifying application components that have participated in predefined communications with application components identified in a most recently generated or added layer of application mapping information in the application dependency map; and

updating the application dependency map by adding to the application dependency map, based on the information received in response to the second query, a third layer of application mapping information based on the information received in response to the second query.

5. The method of claim 4 , wherein the application mapping procedure includes:

after adding the third layer of application mapping information to the application dependency map, sending an additional query to one or more of the endpoint machines in the network;

receiving, in response to the additional query, information identifying application components that have participated in predefined communications with application components identified in a most recently generated or added layer of application mapping information in the application dependency map; and

conditionally, in accordance with a determination that the information received in response to the additional query includes information meeting predefined criteria, adding a layer of application mapping information to the application dependency map based on the information received in response to the additional query.

6. The method of claim 1 , wherein the application dependency map maps distributed processing of one or more respective applications, across the plurality of endpoint machines in the network, and the application mapping procedure includes providing, for presentation to a user, an interactive user interface including a representation of at least a portion of the application dependency map and one or more user-selectable processing options with respect to the application dependency map or a respective machine or process participating in performance of a respective application, of the one or more respective applications, mapped by the application dependency map.

7. The method of claim 6 , wherein the one or more user-selectable processing options include a plurality of options for filtering the application dependency map, and the method includes:

identifying portions of the application dependency map satisfying one or more user-selected options of the plurality of options for filtering the application dependency map; and

presenting a representation of the identified portions of the application dependency map satisfying the one or more user-selected options for filtering the application dependency map.

8. The method of claim 1 , wherein application mapping procedure includes, after adding a respective layer of application mapping information to the application dependency map, determining, based on information received in response to a last query sent to the one or more endpoint machines, whether a further iteration of sending a query to one or more endpoint machines in the network is needed.

9. The method of claim 1 , wherein the server system is coupled to an administrator machine, and the method includes receiving from the administrator machine an instruction to generate the application dependency map.

10. The method of claim 9 , wherein the instruction to generate the application dependency map, received from the administrator machine, includes information identifying one or more application entry points or identifiers of one or more machines in the network that include application entry points.

11. The method of claim 1 , including presenting, in conjunction with the application dependency map, security and/or risk information.

12. The method of claim 1 , including presenting, in conjunction with the application dependency map, additional information overlaid on the application dependency map.

13. A server system for mapping applications executed by a plurality of endpoint machines, distinct from the server system, in a network, the server system comprising:

one or more processors; and

memory storing programs, the programs including instructions, which when executed by the one or more processors cause the server system to perform an application mapping procedure that obtains and aggregates application mapping information from the plurality of endpoint machines to generate an application dependency map, the application mapping procedure comprising:

initializing an application dependency map, including adding a first layer of application mapping information to the application dependency map, wherein the application dependency map identifies relationships among application components of one or more multi-tier applications;

sending a first query to one or more of the endpoint machines;

receiving, in response to the first query, information identifying application components that have participated in predefined communications with application components identified in an existing layer of application mapping information in the application dependency map;

adding a second layer of application mapping information to the application dependency map, based at least in part on the information received in response to the first query;

after adding the second layer of application mapping information to the application dependency map, sending a second query to one or more of the of the endpoint machines, the second query being based at least in part on the application dependency map.

14. The server system of claim 13 , wherein

the plurality of endpoint machines in the network are located at respective nodes in one or more non-static collections of nodes, each non-static collection of nodes forming a linear communication orbit;

the network includes one or more linear communication orbits; and

sending the first query to one or more of the endpoint machines in the network comprises sending the first query via the one or more linear communication orbits.

15. A non-transitory computer readable storage medium storing programs configured for execution by a server system for mapping applications executed by a plurality of endpoint machines in a network, the programs comprising instructions for performing an application mapping procedure that includes:

initializing an application dependency map, including adding a first layer of application mapping information to the application dependency map, wherein the application dependency map identifies relationships among application components of one or more multi-tier applications;

sending a first query to one or more of the endpoint machines;

receiving, in response to the first query, information identifying application components that have participated in predefined communications with application components identified in an existing layer of application mapping information in the application dependency map;

adding a second layer of application mapping information to the application dependency map, based at least in part on the information received in response to the first query;

after adding the second layer of application mapping information to the application dependency map, sending a second query to one or more of the of the endpoint machines, the second query being based at least in part on the application dependency map.

16. The non-transitory computer readable storage medium of claim 15 , wherein performing the application mapping procedure includes receiving, in response to the first query, information identifying application components of the one or more multi-tier applications that have participated in predefined communications with application components identified in a most recently generated or added layer of application mapping information in the application dependency map.

17. The non-transitory computer readable storage medium of claim 15 , wherein performing the application mapping procedure further includes:

receiving, in response to the second query, information identifying application components that have participated in predefined communications with application components identified in a most recently generated or added layer of application mapping information in the application dependency map; and

updating the application dependency map by adding to the application dependency map, based on the information received in response to the second query, a third layer of application mapping information based on the information received in response to the second query.

18. The non-transitory computer readable storage medium of claim 17 , wherein the application mapping procedure includes:

after adding the third layer of application mapping information to the application dependency map, sending an additional query to one or more of the endpoint machines in the network;

receiving, in response to the additional query, information identifying application components that have participated in predefined communications with application components identified in a most recently generated or added layer of application mapping information in the application dependency map; and

conditionally, in accordance with a determination that the information received in response to the additional query includes information meeting predefined criteria, adding a layer of application mapping information to the application dependency map based on the information received in response to the additional query.

19. The non-transitory computer readable storage medium of claim 15 , wherein the application dependency map maps distributed processing of one or more respective applications, across the plurality of endpoint machines in the network, and the application mapping procedure includes providing, for presentation to a user, an interactive user interface including a representation of at least a portion of the application dependency map and one or more user-selectable processing options with respect to the application dependency map or a respective machine or process participating in performance of a respective application, of the one or more respective applications, mapped by the application dependency map.

20. The non-transitory computer readable storage medium of claim 19 , wherein the one or more user-selectable processing options include a plurality of options for filtering the application dependency map, and the programs include instructions for:

identifying portions of the application dependency map satisfying one or more user-selected options of the plurality of options for filtering the application dependency map; and

presenting a representation of the identified portions of the application dependency map satisfying the one or more user-selected options for filtering the application dependency map.

21. The non-transitory computer readable storage medium of claim 15 , wherein application mapping procedure includes, after adding a respective layer of application mapping information to the application dependency map, determining, based on information received in response to a last query sent to the one or more endpoint machines, whether a further iteration of sending a query to one or more endpoint machines in the network is needed.

22. The non-transitory computer readable storage medium of claim 15 , wherein the server system is coupled to an administrator machine, and the programs include instructions for receiving from the administrator machine an instruction to generate the application dependency map.

23. The non-transitory computer readable storage medium of claim 22 , wherein the instruction to generate the application dependency map, received from the administrator machine, includes information identifying one or more application entry points or identifiers of one or more machines in the network that include application entry points.

24. The non-transitory computer readable storage medium of claim 15 , wherein the programs include instructions for presenting, in conjunction with the application dependency map, security and/or risk information.

25. The non-transitory computer readable storage medium of claim 15 , wherein one or more programs include instructions for presenting, in conjunction with the application dependency map, additional information overlaid on the application dependency map.

26. The non-transitory computer readable storage medium of claim 15 , wherein

the plurality of endpoint machines in the network are located at respective nodes in one or more non-static collections of nodes, each non-static collection of nodes forming a linear communication orbit;

the network includes one or more linear communication orbits; and

sending the first query to one or more of the endpoint machines in the network comprises sending the first query via the one or more linear communication orbits.

Continuity (4)
Continuation 16943291 · Jul 30, 2020
Continuation In Part 16430336 · Jun 3, 2019
Provisional Application 62881896 · Aug 1, 2019
Provisional Application 62700171 · Jul 18, 2018
Cited By (9)
US 12,229,032 US 12,231,457 US 12,231,467 US 12,284,204 US 12,309,239 US 12,316,486 US 12,556,623 US 12,632,357 US 12,719,916