Merging Duplicate Configuration Items in CMDB
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The remote network management platform's differences in discovery and vulnerability detection lead to duplicate configuration items in the CMDB, causing confusion and inefficiencies in resolving vulnerabilities, and result in a cluttered database with redundant information.
Innovation Solution
Implementing rule-based techniques to identify and merge duplicate configuration items and vulnerabilities, using matching algorithms and preference rules for attribute values, allowing for the deletion of unmatched items and consolidation of vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If vulnerability detection tools represent configuration items differently than discovery applications, then vulnerability detection accuracy is improved, but duplicate configuration items are created in the CMDB
Solution Approach 1:
The patent merges duplicate configuration items from different data sources (discovery applications and vulnerability detection tools) by comparing attributes and consolidating matching items into single unified entries in the CMDB, thereby reducing the total number of configuration items while preserving vulnerability detection accuracy
Solution Approach 2:
The patent changes the parameters used for identifying configuration items by establishing attribute-based matching criteria that reconcile differences between discovery and vulnerability detection representations, allowing items represented differently by the two tool types to be identified as the same configuration item
2Reliability
If multiple configuration items represent the same component, then vulnerability information can be captured from different sources, but database clutter and memory waste increase
Solution Approach 1:
The patent merges duplicate configuration items by consolidating their attributes and associated vulnerability information into a single unified configuration item entry, thereby maintaining complete vulnerability information while eliminating redundant storage and reducing database clutter
3Loss of information
If duplicate configuration items are not merged, then all vulnerability data is preserved, but time to resolve vulnerabilities increases due to confusion
Solution Approach 1:
The patent merges duplicate configuration items into unified entries that consolidate all vulnerability information, thereby preserving complete vulnerability data while eliminating the confusion that causes delays in vulnerability resolution by providing a single clear target for remediation efforts
Data Source
AI summary
An embodiment may involve a plurality of configuration items and an unmatched configuration item, wherein the unmatched configuration item is associated with a first set of attribute values and a first vulnerability, wherein the first vulnerability is associated with a first set of field values. The embodiment may further involve one or more processors configured to: (i) determine that the unmatched configuration item and a particular configuration item both represent a specific component, wherein the particular configuration item is associated with a second set of attribute values and a second vulnerability, wherein the second vulnerability is associated with a second set of field values; (ii) merge the unmatched configuration item into the particular configuration item; (iii) determine that the first vulnerability and the second vulnerability both represent a specific vulnerability; (iv) merge the first vulnerability into the second vulnerability; and (v) delete the unmatched configuration item and the first vulnerability.


