Elastic Asset-Based Licensing for Vulnerability Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional vulnerability management systems rely on IP addresses for licensing, which is inadequate in modern dynamic environments with virtualization, cloud, and DevOps, leading to inaccurate and incomplete vulnerability assessments due to multiple and changing IP addresses, causing unnecessary costs and inefficiencies.

Innovation Solution

An asset-based approach using an elastic licensing model that employs an asset identification algorithm, including UUID, MAC, NetBIOS, and FQDN, to accurately track and manage assets, allowing for flexible licensing based on the number of unique assets scanned within a given period, with the ability to decommission unused assets and handle temporary surges without requiring additional licenses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If IP-based licensing is used in vulnerability management systems, then licensing is simple to implement, but accuracy of asset identification deteriorates in dynamic environments with multiple and changing IP addresses

Engineering Contradiction:
Improveease of licensing implementationVSAvoidaccuracy of asset identification
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent segments the identification process into multiple components: primary identification using IP addresses, secondary identification using device fingerprints (MAC addresses, hardware identifiers), and tertiary identification using contextual information. This multi-layered segmentation allows the system to maintain simplicity while improving accuracy by falling back to alternative identification methods when IP addresses are insufficient or changing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces device fingerprints and hardware identifiers as intermediary elements between the IP address and the actual asset identification. These intermediaries provide a stable layer of identification that persists across IP address changes, allowing the system to maintain accurate asset tracking without requiring complex re-identification processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of energy

If periodic vulnerability scanning is performed, then system resources are conserved, but visibility and insight into dynamic assets deteriorates in modern computing environments

Engineering Contradiction:
Improvesystem resource consumptionVSAvoidvisibility and insight into dynamic assets
Core Design Contradiction:
Loss of energyVSLoss of information

Solution Approach 1:

The patent implements periodic vulnerability scanning at optimized intervals, combining this with event-driven triggers. The system performs scans at scheduled times to conserve resources, but also initiates scans when specific events occur (such as asset additions, network changes, or security threats), ensuring visibility into dynamic assets without continuous resource consumption.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent incorporates feedback mechanisms where scan results and asset state changes trigger subsequent scanning actions. When the system detects new assets, network topology changes, or security vulnerabilities, it automatically adjusts scanning frequency and targets, optimizing the balance between resource consumption and asset visibility based on real-time conditions.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If IP addresses are used to uniquely identify assets, then licensing can be straightforwardly managed, but reliability of asset identification deteriorates when assets have multiple or dynamic IP addresses

Engineering Contradiction:
Improvesimplicity of license managementVSAvoidreliability of asset identification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates a universal identification framework that works across multiple identification methods. The system can identify assets using IP addresses, device fingerprints, hardware identifiers, or combinations thereof, depending on what is available and reliable in each context. This multi-functional approach maintains simple license management while reliably identifying assets regardless of their network configuration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent dynamically changes identification parameters based on asset type and environment. For static assets with consistent IP addresses, it uses IP-based identification for simplicity. For dynamic assets like mobile devices or cloud instances, it switches to device fingerprints and hardware identifiers, maintaining reliable identification while adapting to changing conditions.

Inventive Principle:
Principle #35Parameter changes

4Quantity of substance

If vulnerability scans are performed on assets with multiple IP addresses, then comprehensive coverage is achieved, but license consumption increases under IP-based licensing models

Engineering Contradiction:
Improvevulnerability scan coverageVSAvoidlicense consumption
Core Design Contradiction:
Quantity of substanceVSLoss of energy

Solution Approach 1:

The patent merges multiple IP addresses associated with the same asset into a single unified asset record. When the system detects that multiple IP addresses belong to the same device (through device fingerprints or other identification methods), it consolidates them and performs vulnerability scanning once per unique asset rather than once per IP address, achieving comprehensive coverage while reducing license consumption.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a virtual representation or copy of the asset that aggregates all its IP addresses and scanning results. Instead of treating each IP address as a separate target requiring separate licenses, the system creates a unified asset model that represents the actual device, allowing comprehensive vulnerability assessment across all interfaces while charging for only one asset.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11716344B2Elastic asset-based licensing model for use in a vulnerability management system
Publication Date: 2023.08.01 TENABLE INC
  • US11716344B2 patent drawing
  • US11716344B2 patent drawing
  • US11716344B2 patent drawing

AI summary

The disclosure generally relates to a vulnerability management system configured to implement an asset-based identification algorithm to identify, update, and otherwise reconcile assets in a network according to various identification attributes that are ordered on a spectrum from authoritative to speculative based on an ability that each identification attribute has to accurately link a host to a given asset. The identification algorithm may further enable an elastic asset-based licensing approach, wherein each asset that is scanned in a current licensing period consumes a single license and licenses are reclaimed from any old assets that are not scanned in a current licensing period (i.e., the old assets do not count towards a total licensed asset count. Furthermore, asset counts may be allowed to temporarily exceed the total licensed asset count without requiring license upsells, with true-up payments only required if and/or when asset counts reflect general expansion of a customer network.