Container-aware application dependency identification
Abstract
Techniques disclosed herein provide an approach for identifying application dependencies in a hybrid environment in which one or more applications run in operating system (OS)-less containers. One embodiment provides a computer-implemented method that includes monitoring network traffic at one or more host computer systems, wherein OS-less containers run in at least one of the host computer systems. The method further includes monitoring network traffic at virtual bridges to which the OS-less containers are attached, and identifying network dependencies based on the monitored network traffic at the host computer systems and the monitored network traffic at the virtual bridges. In addition, the method includes determining the application dependencies based on the identified network dependencies.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method of identifying application dependencies in a hybrid environment in which one or more applications run in operating system (OS)-less containers, where an OS-less container comprises a container without its own operating system that runs on a host operating system, comprising:
monitoring network traffic at one or more host computer systems, wherein OS-less containers run in at least one of the one or more host computer systems; monitoring network traffic at virtual bridges to which the OS-less containers are attached, wherein monitoring the network traffic at the virtual bridges includes:
identifying OS-less container services running in the one or more host computer systems; and
for each of the OS-less container services:
identifying an external port used on a corresponding host computer system of the host computer systems to accept requests from the OS-less container service and an internal port used by the OS-less container to process the requests by issuing a request for information regarding the external port and the internal port to the host operating system;
identifying network dependencies based on the monitored network traffic at the host computer systems and the monitored network traffic at the virtual bridges; and determining the application dependencies based on the identified network dependencies.
2 . The method of claim 1 , wherein determining the application dependencies of a first application and a second application includes generating a hash map comprising from internet protocol (IP) address, to IP address, and port number as keys and applications as values, and wherein a dependency of the first application on the second application is identified when the first and second applications are associated with a same key in the hash map.
3 . The method of claim 1 , wherein the network traffic at the host computer systems and the network traffic at the virtual bridges are monitored via agents registered to the host computer systems.
4 . The method of claim 3 , wherein the agents further identify the network dependencies and transmit information on connections to a central service which determines the application dependencies.
5 . The method of claim 1 , wherein monitoring the network traffic at the host computer systems includes:
identifying services running in the host computer systems; identifying a listening port for each of the services; and monitoring incoming and outgoing connections associated with the identified services.
6 . The method of claim 1 , wherein at least one of the host computer systems is a virtual machine.
7 . The method of claim 1 , further comprising displaying the determined application dependencies to a user via a user interface.
8 . A system for identifying application dependencies in a hybrid environment in which one or more applications run in operating system (OS)-less containers, where an OS-less container comprises a container without its own operating system that runs on a host operating system, the system comprising:
at least one memory; and at least one processor coupled to the at least one memory, the at least one processor and the at least one memory configured to:
monitor network traffic at one or more host computer systems, wherein OS-less containers run in at least one of the one or more host computer systems;
monitor network traffic at virtual bridges to which the OS-less containers are attached, wherein monitoring the network traffic at the virtual bridges includes:
identifying OS-less container services running in the one or more host computer systems; and
for each of the OS-less container services:
identifying an external port used on a corresponding host computer system of the host computer systems to accept requests from the OS-less container service and an internal port used by the OS-less container to process the requests by issuing a request for information regarding the external port and the internal port to the host operating system;
identify network dependencies based on the monitored network traffic at the host computer systems and the monitored network traffic at the virtual bridges; and
determine the application dependencies based on the identified network dependencies.
9 . The system of claim 8 , wherein determining the application dependencies of a first application and a second application includes generating a hash map comprising from internet protocol (IP) address, to IP address, and port number as keys and applications as values, and wherein a dependency of the first application on the second application is identified when the first and second applications are associated with a same key in the hash map.
10 . The system of claim 8 , wherein the network traffic at the host computer systems and the network traffic at the virtual bridges are monitored via agents registered to the host computer systems.
11 . The system of claim 10 , wherein the agents further identify the network dependencies and transmit information on connections to a central service which determines the application dependencies.
12 . The system of claim 8 , wherein monitoring the network traffic at the host computer systems includes:
identifying services running in the host computer systems; identifying a listening port for each of the services; and monitoring incoming and outgoing connections associated with the identified services.
13 . The system of claim 8 , wherein at least one of the host computer systems is a virtual machine.
14 . The system of claim 8 , wherein the at least one processor and the at least one memory are further configured to display the determined application dependencies to a user via a user interface.
15 . A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to:
monitor network traffic at one or more host computer systems, wherein operating system (OS)-less containers run in at least one of the one or more host computer systems, and wherein one or more applications run in the OS-less containers, where an OS-less container comprises a container without its own operating system that runs on a host operating system; monitor network traffic at virtual bridges to which the OS-less containers are attached, wherein monitoring the network traffic at the virtual bridges includes:
identifying OS-less container services running in the one or more host computer systems; and
for each of the OS-less container services:
identifying an external port used on a corresponding host computer system of the host computer systems to accept requests from the OS-less container service and an internal port used by the OS-less container to process the requests by issuing a request for information regarding the external port and the internal port to the host operating system;
identify network dependencies based on the monitored network traffic at the host computer systems and the monitored network traffic at the virtual bridges; and determine application dependencies based on the identified network dependencies.
16 . The non-transitory computer-readable medium of claim 15 , wherein determining the application dependencies of a first application and a second application includes generating a hash map comprising from internet protocol (IP) address, to IP address, and port number as keys and applications as values, and wherein a dependency of the first application on the second application is identified when the first and second applications are associated with a same key in the hash map.
17 . The non-transitory computer-readable medium of claim 15 , wherein the network traffic at the host computer systems and the network traffic at the virtual bridges are monitored via agents registered to the host computer systems.
18 . The non-transitory computer-readable medium of claim 17 , wherein the agents further identify the network dependencies and transmit information on connections to a central service which determines the application dependencies.
19 . The non-transitory computer-readable medium of claim 15 , wherein monitoring the network traffic at the host computer systems includes:
identifying services running in the host computer systems; identifying a listening port for each of the services; and monitoring incoming and outgoing connections associated with the identified services.
20 . The non-transitory computer-readable medium of claim 15 , wherein at least one of the host computer systems is a virtual machine.Join the waitlist — get patent alerts
Track US2022407818A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.