Automated Network Asset Discovery and Lifecycle Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing asset management systems rely on manual entry of asset information, leading to gaps in tracking and control, especially in large organizations, and have a limited view of assets, failing to manage ephemeral network assets like IP addresses, domain names, and digital certificates effectively, which poses security and business risks.
Innovation Solution
A technique for network asset lifecycle management that involves scanning networks to identify and manage network assets, including ephemeral ones, through automated discovery and governance processes, without relying on internal systems, to build a global record and perform automated actions for registration renewal and policy compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual entry of asset information is used, then ease of operation is improved, but completeness of asset tracking deteriorates
Solution Approach 1:
The system performs automated network scanning and asset discovery without requiring manual intervention. The scanning system automatically identifies network assets, extracts asset information, and populates the asset database, enabling the system to serve itself in the information collection process.
Solution Approach 2:
The patent replaces the manual mechanical process of asset information entry with an automated electronic scanning and detection system. The system uses network scanning technology to automatically discover and track assets, substituting human-operated manual processes with automated technical systems.
2Device complexity
If traditional asset management systems are used, then device complexity is reduced, but scope of asset coverage deteriorates
Solution Approach 1:
The scanning system is designed to detect and manage multiple types of network assets simultaneously, including but not limited to IP addresses, domain names, digital certificates, and cloud infrastructure accounts. This multi-functional capability allows a single system to cover diverse asset types without requiring separate specialized systems for each asset category.
Solution Approach 2:
The system continuously scans and updates the asset database in real-time, dynamically adapting to changes in the network environment. This dynamic approach enables the system to automatically detect new assets, track asset lifecycle changes, and maintain current information without manual intervention, expanding coverage while maintaining manageable complexity.
3Loss of information
If automated network scanning is implemented, then completeness of asset discovery is improved, but system complexity increases
Solution Approach 1:
The scanning system is divided into distinct functional modules including network scanning components, asset detection components, information extraction components, and database management components. This segmentation allows each module to perform its specific function independently, making the overall complex system more manageable and easier to maintain while achieving comprehensive asset discovery.
4Reliability
If continuous asset monitoring is performed, then reliability of asset management is improved, but resource consumption increases
Solution Approach 1:
The system performs network scanning and asset detection at scheduled intervals rather than continuously, striking a balance between maintaining reliable asset information and conserving computational resources. The periodic scanning approach ensures assets are monitored regularly while avoiding the excessive resource consumption of continuous real-time monitoring.
Data Source
AI summary
Systems and methods for network asset lifecycle management are described. Network assets may include ephemeral Internet-accessible assets such as IP addresses, domain names, digital certificates, and cloud infrastructure accounts. A set of addresses associated with a computer network such as the Internet are scanned. Response data is received from one or more network systems connected to the computer network and processed to identify one or more network assets associated with an entity such as an enterprise organization. Asset data indicative of the identified network assets are then stored to build a record of the network assets associated with the entity.


