Elastic Asset-Based Licensing for Vulnerability Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional vulnerability management systems rely on IP addresses for licensing, which is inadequate in modern dynamic environments with virtualization, cloud, and DevOps, leading to inaccurate and incomplete vulnerability assessments due to multiple and changing IP addresses, causing unnecessary costs and inefficiencies.
Innovation Solution
An asset-based approach using an elastic licensing model that employs an asset identification algorithm, including UUID, MAC, NetBIOS, and FQDN, to accurately track and manage assets, allowing for flexible licensing based on the number of unique assets scanned within a given period, with the ability to decommission unused assets and handle temporary surges without requiring additional licenses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If IP-based licensing is used in vulnerability management systems, then licensing is simple to implement, but accuracy of asset identification deteriorates in dynamic environments with multiple and changing IP addresses
Solution Approach 1:
The patent segments the identification process into multiple components: primary identification using IP addresses, secondary identification using device fingerprints (MAC addresses, hardware identifiers), and tertiary identification using contextual information. This multi-layered segmentation allows the system to maintain simplicity while improving accuracy by falling back to alternative identification methods when IP addresses are insufficient or changing.
Solution Approach 2:
The patent introduces device fingerprints and hardware identifiers as intermediary elements between the IP address and the actual asset identification. These intermediaries provide a stable layer of identification that persists across IP address changes, allowing the system to maintain accurate asset tracking without requiring complex re-identification processes.
2Loss of energy
If periodic vulnerability scanning is performed, then system resources are conserved, but visibility and insight into dynamic assets deteriorates in modern computing environments
Solution Approach 1:
The patent implements periodic vulnerability scanning at optimized intervals, combining this with event-driven triggers. The system performs scans at scheduled times to conserve resources, but also initiates scans when specific events occur (such as asset additions, network changes, or security threats), ensuring visibility into dynamic assets without continuous resource consumption.
Solution Approach 2:
The patent incorporates feedback mechanisms where scan results and asset state changes trigger subsequent scanning actions. When the system detects new assets, network topology changes, or security vulnerabilities, it automatically adjusts scanning frequency and targets, optimizing the balance between resource consumption and asset visibility based on real-time conditions.
3Ease of operation
If IP addresses are used to uniquely identify assets, then licensing can be straightforwardly managed, but reliability of asset identification deteriorates when assets have multiple or dynamic IP addresses
Solution Approach 1:
The patent creates a universal identification framework that works across multiple identification methods. The system can identify assets using IP addresses, device fingerprints, hardware identifiers, or combinations thereof, depending on what is available and reliable in each context. This multi-functional approach maintains simple license management while reliably identifying assets regardless of their network configuration.
Solution Approach 2:
The patent dynamically changes identification parameters based on asset type and environment. For static assets with consistent IP addresses, it uses IP-based identification for simplicity. For dynamic assets like mobile devices or cloud instances, it switches to device fingerprints and hardware identifiers, maintaining reliable identification while adapting to changing conditions.
4Quantity of substance
If vulnerability scans are performed on assets with multiple IP addresses, then comprehensive coverage is achieved, but license consumption increases under IP-based licensing models
Solution Approach 1:
The patent merges multiple IP addresses associated with the same asset into a single unified asset record. When the system detects that multiple IP addresses belong to the same device (through device fingerprints or other identification methods), it consolidates them and performs vulnerability scanning once per unique asset rather than once per IP address, achieving comprehensive coverage while reducing license consumption.
Solution Approach 2:
The patent creates a virtual representation or copy of the asset that aggregates all its IP addresses and scanning results. Instead of treating each IP address as a separate target requiring separate licenses, the system creates a unified asset model that represents the actual device, allowing comprehensive vulnerability assessment across all interfaces while charging for only one asset.
Data Source
AI summary
The disclosure generally relates to a vulnerability management system configured to implement an asset-based identification algorithm to identify, update, and otherwise reconcile assets in a network according to various identification attributes that are ordered on a spectrum from authoritative to speculative based on an ability that each identification attribute has to accurately link a host to a given asset. The identification algorithm may further enable an elastic asset-based licensing approach, wherein each asset that is scanned in a current licensing period consumes a single license and licenses are reclaimed from any old assets that are not scanned in a current licensing period (i.e., the old assets do not count towards a total licensed asset count. Furthermore, asset counts may be allowed to temporarily exceed the total licensed asset count without requiring license upsells, with true-up payments only required if and/or when asset counts reflect general expansion of a customer network.


