Implicit Configuration Items for Source Code in CMDB
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional configuration management databases (CMDBs) exclude source code forms of applications, limiting the utility of remote network management platforms for security, software development operations, and service management, as only executable versions are typically populated, excluding custom applications under development.
Innovation Solution
The use of implicit configuration items to represent units of source code under development, with modified discovery procedures and reconciliation processes to populate an implicit relationship table, enabling association with explicit configuration items, facilitating defect and vulnerability tracking between source code and deployed executable applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional CMDBs only populate executable versions of software applications, then the CMDB structure remains simple and manageable, but source code forms of applications are excluded, limiting the utility of the remote network management platform for security, software development operations, and service management
Solution Approach 1:
The patent segments configuration items into two distinct types: explicit configuration items (for executable versions) and implicit configuration items (for source code forms). This segmentation allows the CMDB to handle both types appropriately while maintaining the ability to track relationships between them through separate tables (explicit configuration item table, implicit configuration item table, and implicit relationship table), thereby increasing platform versatility without overwhelming the CMDB structure with a single undifferentiated approach
Solution Approach 2:
The patent introduces an implicit relationship table as an intermediary structure that connects implicit configuration items (source code) with explicit configuration items (executable versions). This intermediary enables the platform to track relationships between source code and deployed applications, facilitating security and development operations without requiring direct integration that would complicate the core CMDB structure
2Reliability
If only executing versions of applications are discovered and populated in the CMDB, then the discovery process remains straightforward, but custom applications under development exist outside the CMDB, preventing defect and vulnerability tracking between source code and deployed applications
Solution Approach 1:
The patent enables discovery of source code forms (implicit configuration items) as a preliminary action before applications are compiled and deployed as executable versions. By populating the CMDB with implicit configuration items representing source code under development, the system establishes a foundation for tracking defects and vulnerabilities from the earliest stage in the software development lifecycle, enabling continuous reliability monitoring through the entire development pipeline
Solution Approach 2:
The patent establishes feedback loops between implicit configuration items (source code) and explicit configuration items (deployed applications) through the implicit relationship table. This feedback mechanism enables the system to track vulnerabilities and defects from source code through compilation and deployment, allowing security and development operations teams to monitor and respond to issues across the entire application lifecycle rather than only after deployment
Data Source
AI summary
Persistent storage may contain: (i) an explicit configuration item table with entries of explicit configuration items representing hardware devices and executable software applications deployed on the hardware devices, (ii) an implicit configuration item table with entries of implicit configuration items representing units of source code, wherein at least some of the executable software applications are compiled versions of the units of source code, and (iii) an implicit relationship table associating pairs of the configuration items. One or more processors may be configured to receive information related to a particular unit of source code; write, to the implicit configuration item table, at least some of the information as an implicit configuration item; determine that the implicit configuration item has one or more identifying attributes in common with an explicit configuration item; and write, to the implicit relationship table, a new entry associating the implicit configuration item and the explicit configuration item.


