Systems and methods for configuration management database (CMDB) based application segmentation
Systems and methods for Configuration Management Database (CMDB) based application segmentation include obtaining transactional data for a plurality of users of an enterprise, wherein the transactional data relates to usage of a plurality of applications by the plurality of users; obtaining Configuration Management Database (CMDB) data of the enterprise, wherein the CMDB data includes information about hardware and software assets of the enterprise; matching application information within the transactional data and the CMDB data; and generating one or more application segments based on the matching.
1 . A non-transitory computer-readable storage medium having computer readable code stored thereon for programming at least one processor to perform steps of:
obtaining transactional data for a plurality of users of an enterprise, wherein the transactional data relates to usage of a plurality of applications by the plurality of users;
obtaining Configuration Management Database (CMDB) data of the enterprise, wherein the CMDB data includes information about hardware and software assets of the enterprise;
matching application information within the transactional data and the CMDB data, the matching comprising performing, in an order of decreasing confidence, a plurality of matching techniques including at least:
(i) matching directly using Fully Qualified Domain Names (FQDNs) in both the transactional data and the CMDB data;
(ii) matching application Internet Protocol (IP) addresses present in the CMDB data using app-server IP mappings from the transactional data;
(iii) matching based on FQDN prefixes;
(iv) matching using a one-to-one mapping between FQDNs and IP addresses for applications;
(v) matching FQDNs in the CMDB data using app-server IP address mappings from the transactional data;
generating one or more application segments based on the matching; and
using the one or more application segments to define access to the plurality of applications by the plurality of users.
2 . The non-transitory computer-readable storage medium of claim 1 , wherein the steps further comprise:
providing an access policy for the plurality of applications based on the one or more application segments.
3 . The non-transitory computer-readable storage medium of claim 1 , wherein performing the plurality of matching techniques comprise performing a plurality of matching techniques between the transactional data and the CMDB data.
4 . The non-transitory computer-readable storage medium of claim 3 , wherein the plurality of matching techniques are performed in an order based on a confidence of each of the plurality of matching techniques, wherein direct FQDN matching is prioritized over IP-based matching, prefix-based matching, and one-to-one FQDN-IP mapping.
5 . The non-transitory computer-readable storage medium of claim 3 , wherein one of the plurality of matching techniques includes matching directly using FQDNs in both the transactional data and the CMDB data, including exact-string matching of FQDNs appearing in both data sets.
6 . The non-transitory computer-readable storage medium of claim 3 , wherein one of the plurality of matching techniques includes matching application IP addresses present in the CMDB data using app-server IP mappings from the transactional data.
7 . The non-transitory computer-readable storage medium of claim 3 , wherein one of the plurality of matching techniques includes matching based on FQDN prefixes.
8 . The non-transitory computer-readable storage medium of claim 3 , wherein one of the plurality of matching techniques includes matching using a 1-to-1 mapping between FQDN and IP addresses for applications in transactional data and the CMDB data.
9 . The non-transitory computer-readable storage medium of claim 3 , wherein one of the plurality of matching techniques includes matching FQDNs in the CMDB data using app-server Internet IP address mappings from the transactional data.
10 . The non-transitory computer-readable storage medium of claim 1 , wherein the steps further comprise:
generating a segmentation report; and
providing the segmentation report to users of the enterprise, including port-protocol usage and transaction volume for use in configuring the access.
11 . A method comprising steps of:
obtaining transactional data for a plurality of users of an enterprise, wherein the transactional data relates to usage of a plurality of applications by the plurality of users;
obtaining Configuration Management Database (CMDB) data of the enterprise, wherein the CMDB data includes information about hardware and software assets of the enterprise;
matching application information within the transactional data and the CMDB data, the matching comprising performing, in an order of decreasing confidence, a plurality of matching techniques including at least:
(i) matching directly using Fully Qualified Domain Names (FQDNs) in both the transactional data and the CMDB data;
(ii), matching application Internet Protocol (IP) addresses present in the CMDB data using app-server IP mappings from the transactional data;
(iii) matching based on FQDN prefixes;
(iv) matching using a one-to-one mapping between FQDNs and IP addresses for applications; and
(v) matching FQDNs in the CMDB data using app-server IP address mappings from the transactional data;
generating one or more application segments based on the matching; and
using the one or more application segments to define access to the plurality of applications by the plurality of users.
12 . The method of claim 11 , wherein the steps further comprise:
providing an access policy for the plurality of applications based on the one or more application segments.
13 . The method of claim 11 , wherein performing the plurality of matching techniques comprise performing a plurality of matching techniques between the transactional data and the CMDB data.
14 . The method of claim 13 , wherein the plurality of matching techniques are performed in an order based on a confidence of each of the plurality of matching techniques, wherein direct FQDN matching is prioritized over IP-based matching, prefix-based matching, and one-to-one FQDN-IP mapping.
15 . The method of claim 13 , wherein one of the plurality of matching techniques includes matching directly using FQDNs in both the transactional data and the CMDB data, including exact-string matching of FQDNs appearing in both data sets.
16 . The method of claim 13 , wherein one of the plurality of matching techniques includes matching application IP addresses present in the CMDB data using app-server IP mappings from the transactional data.
17 . The method of claim 13 , wherein one of the plurality of matching techniques includes matching based on FQDN prefixes.
18 . The method of claim 13 , wherein one of the plurality of matching techniques includes matching using a 1-to-1 mapping between FQDN and IP addresses for applications in transactional data and the CMDB data.
19 . The method of claim 13 , wherein one of the plurality of matching techniques includes matching FQDNs in the CMDB data using app-server IP address mappings from the transactional data.
20 . The method of claim 11 , wherein the steps further comprise:
generating a segmentation report; and
providing the segmentation report to users of the enterprise, including port-protocol usage and transaction volume for use in configuring the access.