Merging Duplicate Configuration Items in CMDB

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The remote network management platform's differences in discovery and vulnerability detection lead to duplicate configuration items in the CMDB, causing confusion and inefficiencies in resolving vulnerabilities, and result in a cluttered database with redundant information.

Innovation Solution

Implementing rule-based techniques to identify and merge duplicate configuration items and vulnerabilities, using matching algorithms and preference rules for attribute values, allowing for the deletion of unmatched items and consolidation of vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If vulnerability detection tools represent configuration items differently than discovery applications, then vulnerability detection accuracy is improved, but duplicate configuration items are created in the CMDB

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidnumber of configuration items
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent merges duplicate configuration items from different data sources (discovery applications and vulnerability detection tools) by comparing attributes and consolidating matching items into single unified entries in the CMDB, thereby reducing the total number of configuration items while preserving vulnerability detection accuracy

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent changes the parameters used for identifying configuration items by establishing attribute-based matching criteria that reconcile differences between discovery and vulnerability detection representations, allowing items represented differently by the two tool types to be identified as the same configuration item

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple configuration items represent the same component, then vulnerability information can be captured from different sources, but database clutter and memory waste increase

Engineering Contradiction:
Improvevulnerability information completenessVSAvoiddatabase storage efficiency
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent merges duplicate configuration items by consolidating their attributes and associated vulnerability information into a single unified configuration item entry, thereby maintaining complete vulnerability information while eliminating redundant storage and reducing database clutter

Inventive Principle:
Principle #5Merging (Combining)

3Loss of information

If duplicate configuration items are not merged, then all vulnerability data is preserved, but time to resolve vulnerabilities increases due to confusion

Engineering Contradiction:
Improvevulnerability data retentionVSAvoidvulnerability resolution time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent merges duplicate configuration items into unified entries that consolidate all vulnerability information, thereby preserving complete vulnerability data while eliminating the confusion that causes delays in vulnerability resolution by providing a single clear target for remediation efforts

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11838312B2Merging duplicate items identified by a vulnerability analysis
Publication Date: 2023.12.05 SERVICENOW INC
  • US11838312B2 patent drawing
  • US11838312B2 patent drawing
  • US11838312B2 patent drawing

AI summary

An embodiment may involve a plurality of configuration items and an unmatched configuration item, wherein the unmatched configuration item is associated with a first set of attribute values and a first vulnerability, wherein the first vulnerability is associated with a first set of field values. The embodiment may further involve one or more processors configured to: (i) determine that the unmatched configuration item and a particular configuration item both represent a specific component, wherein the particular configuration item is associated with a second set of attribute values and a second vulnerability, wherein the second vulnerability is associated with a second set of field values; (ii) merge the unmatched configuration item into the particular configuration item; (iii) determine that the first vulnerability and the second vulnerability both represent a specific vulnerability; (iv) merge the first vulnerability into the second vulnerability; and (v) delete the unmatched configuration item and the first vulnerability.