IP Library Granted Patent US 11,777,907
Granted Patent B2
US 11,777,907 · App. 17/211,434 · Granted Oct 3, 2023

Computer asset discovery for digital transformation

Inventors: Abhishek Kumar Gautam (Delhi, IN); Kailash Chandra Verma (Gurugram, IN); Pijush Kanti Biswas (New Delhi, IN)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/029G06N5/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,777,907
App. No.
17/211,434
Granted
Oct 3, 2023
Kind
B2
Abstract

Computer assets within a defined network are identified using scanning services respectively connected to each of a plurality of network zones within the defined network. A plurality of interne protocol (IP) addresses within the particular one of the network zones are identified by a particular scanning service contained within the particular one of the network zones. The particular scanning service collects information associated with each of the plurality of IP addresses and infers, using the collected information, additional information about the plurality of IP addresses. The particular scanning service validates the additional information and presents analytics based upon the collected information and the additional information. Firewalls contained within the particular one of the network zones are configured to allow access by the particular scanning service.

Claims (61)

1. A computer-implemented process of identifying computer assets within a defined network using scanning services respectively connected to each of a plurality of network zones within the defined network, comprising:

identifying, by a particular scanning service contained within the particular one of the network zones, a plurality of internet protocol (IP) addresses within the particular one of the network zones;

collecting, by the particular scanning service, collected information associated with each of the plurality of IP addresses;

inferring, by the particular scanning service and using the collected information associated with each of the plurality of IP addresses, additional information about the plurality of IP addresses;

validating, by the particular scanning service, the additional information; and

presenting, using a graphical user interface connected to the particular scanning service, analytics based upon the collected information and the additional information, wherein

firewalls contained within the particular one of the network zones are configured to allow access by the particular scanning service, and

the identifying, the collecting, and the inferring are performed for each of the plurality of network zones.

2. The method of claim 1 , wherein

the collecting includes accessing well-known known ports for each of the plurality of IP addresses.

3. The method of claim 2 , wherein

the accessing is performed without credentials.

4. The method of claim 1 , wherein

the collecting is performed over a predetermined amount of time.

5. The method of claim 1 , wherein

the inferring includes comparing the collected information to computer asset signatures contained within a database.

6. The method of claim 5 , wherein

the database is located externally to the defined network.

7. The method of claim 1 , wherein

the collecting includes submitting predefined requests to certain ports associated with the plurality of IP addresses.

8. The method of claim 1 , wherein

the analytics include collected data and inferred data from all scanning services connected to the plurality of network zones.

9. A computer hardware system configured to identify computer assets within a defined network using scanning services respectively connected to each of a plurality of network zones within the defined network, comprising:

a hardware processor configured to perform the following executable operations:

identifying, by a particular scanning service contained within the particular one of the network zones, a plurality of interne protocol (IP) addresses within the particular one of the network zones;

collecting, by the particular scanning service, collected information associated with each of the plurality of IP addresses;

inferring, by the particular scanning service and using the collected information associated with each of the plurality of IP addresses, additional information about the plurality of IP addresses;

validating, by the particular scanning service, the additional information; and

presenting, using a graphical user interface connected to the particular scanning service, analytics based upon the collected information and the additional information, wherein

firewalls contained within the particular one of the network zones are configured to allow access by the particular scanning service, and

the identifying, the collecting, and the inferring are performed for each of the plurality of network zones.

10. The system of claim 9 , wherein

the collecting includes accessing well-known known ports for each of the plurality of IP addresses.

11. The system of claim 10 , wherein

the accessing is performed without credentials.

12. The system of claim 9 , wherein

the collecting is performed over a predetermined amount of time.

13. The system of claim 9 , wherein

the inferring includes comparing the collected information to computer asset signatures contained within a database.

14. The system of claim 13 , wherein

the database is located externally to the defined network.

15. The system of claim 9 , wherein

the collecting includes submitting predefined requests to certain ports associated with the plurality of IP addresses.

16. The system of claim 9 , wherein

the analytics include collected data and inferred data from all scanning services connected to the plurality of network zones.

17. A computer program product for identifying computer assets within a defined network using scanning services respectively connected to each of a plurality of network zones within the defined network, comprising:

a computer readable storage medium having stored therein program code,

the program code, which when executed by a computer hardware system, cause the computer hardware system to perform:

identifying, by a particular scanning service contained within the particular one of the network zones, a plurality of interne protocol (IP) addresses within the particular one of the network zones;

collecting, by the particular scanning service, collected information associated with each of the plurality of IP addresses;

inferring, by the particular scanning service and using the collected information associated with each of the plurality of IP addresses, additional information about the plurality of IP addresses;

validating, by the particular scanning service, the additional information; and

presenting, using a graphical user interface connected to the particular scanning service, analytics based upon the collected information and the additional information, wherein

firewalls contained within the particular one of the network zones are configured to allow access by the particular scanning service, and

the identifying, the collecting, and the inferring are performed for each of the plurality of network zones.

18. The computer program product of claim 17 , wherein

the collecting includes accessing well-known known ports for each of the plurality of IP addresses.

19. The computer program product of claim 18 , wherein

the accessing is performed without credentials.

20. The computer program product of claim 17 , wherein

the inferring includes comparing the collected information to computer asset signatures contained within a database.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2021
From: GAUTAM, ABHISHEK KUMAR; VERMA, KAILASH CHANDRA; BISWAS, PIJUSH KANTI
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 055705/0184 →
Continuity (1)
Related Publication 20220311740A1 · Sep 29, 2022