Network Zone Scanning for Asset Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in accurately identifying and tracking computer assets across multiple subnets and geographically dispersed locations due to outdated and incomplete configuration management databases, especially when dealing with thousands of assets, which complicates digital transformation efforts.
Innovation Solution
A method utilizing scanning services connected to multiple network zones within an enterprise network to identify and validate IP addresses, collect information, and infer additional details without requiring software agents on devices, thereby allowing for analytics on the IT landscape without needing credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If agents are run on each device to collect asset information, then measurement precision of asset data is improved, but device complexity and ease of operation deteriorate due to credential management requirements
Solution Approach 1:
The patent introduces scanning services as intermediary components deployed in network zones that mediate between the asset discovery system and individual devices. These scanning services collect asset information without requiring direct agent installation on each device, thereby eliminating credential management complexity while maintaining measurement precision through centralized scanning operations.
Solution Approach 2:
The patent extracts the credential management requirement from the asset discovery process by removing agents from individual devices. Instead, asset information is collected externally through scanning services that operate at the network zone level, separating the data collection function from the target devices and eliminating the need for device-specific credentials.
2Reliability
If agents are installed on each device for asset discovery, then reliability of asset data collection is improved, but device complexity increases
Solution Approach 1:
Scanning services act as intermediary components deployed in network zones that collect asset information without requiring agent installation on individual devices. This intermediary approach maintains reliable data collection through centralized scanning while eliminating the complexity of distributing and managing software agents across thousands of devices.
Solution Approach 2:
The patent segments the asset discovery function from the target devices by deploying scanning services at the network zone level rather than installing agents on each device. This segmentation separates the data collection responsibility from individual devices, reducing device complexity while maintaining collection reliability through the segmented scanning service architecture.
3Quantity of substance
If comprehensive scanning across multiple network zones is performed, then quantity of asset information discovered is improved, but ease of operation worsens due to firewall access requirements
Solution Approach 1:
The scanning services are designed with multi-functionality to handle diverse asset discovery tasks across different network zones through a unified interface. This universal approach allows comprehensive asset information collection across multiple zones while simplifying operations, as the same scanning service infrastructure handles all zones without requiring separate credential or firewall configurations for each zone.
4Measurement precision
If credentials are required to access computer asset information, then measurement precision of asset details is improved, but ease of operation deteriorates
Solution Approach 1:
The patent extracts credential management from the asset discovery process by removing the requirement for device-specific credentials. Scanning services collect detailed asset information through network-based scanning without needing to authenticate with individual devices, thereby maintaining measurement precision while eliminating the complexity of managing credentials across numerous devices.
Data Source
AI summary
Computer assets within a defined network are identified using scanning services respectively connected to each of a plurality of network zones within the defined network. A plurality of interne protocol (IP) addresses within the particular one of the network zones are identified by a particular scanning service contained within the particular one of the network zones. The particular scanning service collects information associated with each of the plurality of IP addresses and infers, using the collected information, additional information about the plurality of IP addresses. The particular scanning service validates the additional information and presents analytics based upon the collected information and the additional information. Firewalls contained within the particular one of the network zones are configured to allow access by the particular scanning service.


