IP Library Granted Patent US 10,282,426
Granted Patent B1
US 10,282,426 · App. 14/218,511 · Granted May 7, 2019

Asset inventory reconciliation services for use in asset management architectures

Inventors: Aaron Lerner (Portland, OR); Adam Montville (Portland, OR)
Assignee: Tripwire, Inc.
G06F17/3007G06F17/30507G06F17/30578
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,282,426
App. No.
14/218,511
Granted
May 7, 2019
Kind
B1
Abstract

Disclosed below are representative embodiments of methods, apparatus, and systems for managing, monitoring, controlling, and/or classifying assets in an information technology (“IT”) environment. Certain embodiments leverage both services oriented architecture concepts and event mechanisms to create a platform with which additional controls can easily integrate.

Claims (35)

1. A system, comprising:

one or more processors; and

one or more computer-readable storage media storing computer-executable instructions, the computer-executable instructions including,

instructions for implementing an asset discovery handler component, the asset discovery handler component being configured to receive asset information from an asset collector component, and to normalize the asset information to a common format, the asset information describing an asset in an IT environment; and

instructions for implementing an asset reconciliation component, the asset reconciliation component being configured to apply defined reconciliation rules to compare information pertaining to a newly discovered asset to information pertaining to previously reconciled assets to determine if a match exists, and, in response to the determination:

if the information pertaining to the newly discovered asset matches the information pertaining to one of the previously reconciled assets, to determine that the newly discovered asset is not a new asset, and associating it with an existing unique reconciliation identifier of the previously reconciled asset; and

if the information pertaining to the newly discovered asset fails to match the information pertaining to at least one of the previously reconciled assets, to determine that the newly discovered asset is a new asset, and, in response to the determination, to assign a new unique reconciliation identifier to the new asset.

2. The system of claim 1 , wherein the asset information includes an IP address and a hostname for the asset.

3. The system of claim 1 , wherein assets that the system already manages are stored in an asset inventory, and wherein the asset inventory provides asset information across multiple tools in the system.

4. The system of claim 3 , wherein the asset inventory provides information to a reporting tool that generates reports describing security controls in the IT environment.

5. The system of claim 3 , wherein the asset inventory further stores tag data associated with the assets in the asset inventory.

6. The system of claim 5 , wherein the tag data comprises one or more tags, each of which is configured to be associated with multiple of the assets in the asset inventory.

7. A non-transitory computer readable medium storing program instructions for causing a computer to perform the method of:

implementing an asset discovery handler component, the asset discovery handler component being configured to receive asset information from an asset collector component, and to normalize the asset information to a common format, the asset information describing an asset in an IT environment; and

implementing an asset reconciliation component, the asset reconciliation component being configured to apply defined reconciliation rules to compare information pertaining to a newly discovered asset to information pertaining to previously reconciled assets to determine if a match exists, and, in response to the determination:

if the information pertaining to the newly discovered asset matches the information pertaining to one of the previously reconciled assets, to determine that the newly discovered asset is not a new asset, and associating it with an existing unique reconciliation identifier of the previously reconciled asset; and

if the information pertaining to the newly discovered asset fails to match the information pertaining to at least one of the previously reconciled assets, to determine that the newly discovered asset is a new asset, and, in response to the determination, to assign a new unique reconciliation identifier to the new asset.

8. The non-transitory computer readable medium of claim 7 , wherein the asset information includes an IP address and a hostname for the asset.

9. The non-transitory computer readable medium of claim 7 , wherein assets that are already managed by the system are stored in an asset inventory, and wherein the asset inventory provides asset information across multiple tools in the system.

10. The non-transitory computer readable medium of claim 9 , wherein the asset inventory provides information to a reporting tool that generates reports describing security controls in the IT environment.

11. The non-transitory computer readable medium of claim 9 , wherein the asset inventory further stores tag data associated with the assets in the asset inventory.

12. The non-transitory computer readable medium of claim 11 , wherein the tag data comprises one or more tags, each of which is configured to be associated with multiple of the assets in the asset inventory.

13. The system of claim 1 , further comprising instructions for implementing a compliance and configuration tool to discover and assess a configuration of the newly discovered asset and to determine whether the asset complies with at least one of an internal and an external policy.

14. The system of claim 13 , wherein the compliance and configuration tool is configured to use one or more software agents that are implemented on the newly discovered asset to monitor and report the configuration.

15. The non-transitory computer readable medium of claim 7 , further comprising implementing a compliance and configuration tool to discover and assess a configuration of the newly discovered asset and to determine whether the asset complies with at least one of an internal and an external policy.

16. The non-transitory computer readable medium of claim 15 , wherein the compliance and configuration tool is configured to use one or more software agents that are implemented on the newly discovered asset to monitor and report the configuration.

17. The non-transitory computer readable medium of claim 15 , wherein assessing the configuration further comprises:

capturing a baseline configuration;

performing one or more integrity checks to compare a subsequent configuration to the baseline configuration to identify at least one change to the baseline configuration; and

confirming that the at least one change is authorized.

18. The non-transitory computer readable medium of claim 17 , wherein confirming that the at least one change is authorized comprises:

crosschecking the at least one change with one or more of: defined IT compliance policies, documented change tickets in a change control management (CCM) system, a list of approved changes, and automatically generated lists created by patch management and software provisioning tools; and

in response to said crosschecking, automatically recognizing whether the at least one change is authorized or unauthorized.

19. The non-transitory computer readable medium of claim 18 , further comprising, in response to identifying that the change is authorized, generating a report concerning the asset, the report containing one or more of: compliance information, configuration information, and usage information.

20. The non-transitory computer readable medium of claim 18 , further comprising, in response to identifying that the change is unauthorized, generating a report concerning the asset, the report containing one or more of: compliance information, configuration information, and usage information.

Assignments (11)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0639 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073664/0124 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2014
From: LERNER, AARON; MONTVILLE, ADAM
To: TRIPWIRE, INC.
Reel/Frame 034213/0459 →
Continuity (1)
Provisional Application 61800134 · Mar 15, 2013