Ongoing trigger-based scanning of cyber-physical assets
A system and method for trigger-based scanning of cyber-physical assets, including a distributed operating system, parameter evaluation engine, at least one cyber-physical asset, at least one crypt-ledger, a network, and a scanner that detects trigger conditions and events and performs scans of cyber-physical assets based on the trigger and any relevant stored scan rules before storing scan results as time-series data.
1 . A computing system for dynamic geospatially-referenced cyber-physical infrastructure inventory and asset management, comprising:
a first computing device comprising a first processor, a first memory, and a first plurality of programming instructions, when operating on the first computing device, cause the first computing device to:
determine a location of an asset;
generate an encrypted message comprising an identifier of the first computing device and the location of the asset; and
transmit the encrypted message to a second computing device;
the second computing device comprising a second processor, a second memory, and a second plurality of programming instructions, when operating on the second computing device, cause the second computing device to:
receive a triggering event from the first computing device, wherein the triggering event comprises the encrypted message from the first computing device;
attach metadata to the triggering event, wherein the metadata comprises a time at which the triggering event occurred;
retrieve rules associated with the triggering event;
perform one or more port scans of the first computing device based on the retrieved rules;
produce scan results of the port scans;
attach time-series metadata to each scan result; and
generate and encrypt a report with the scan results and the time-series metadata attached to each scan result.
2 . The system of claim 1 , further comprising a third computing device comprising a third processor, a third memory, and a third plurality of programming instructions, when operating on the third processor, cause the third computing device to:
receive an encrypted scan report message from the second computing device;
verify the report's authenticity;
update a graph with the scan results and the time-series metadata;
store the graph; and
establish data structures with data received from one or more network sources.
3 . The system of claim 1 , wherein the second computing device periodically rescans the first computing device based on one or more triggers and updates the graph accordingly.
4 . A computer-implemented method for dynamic geospatially-referenced cyber-physical infrastructure inventory and asset management, the computer-implemented method comprising the steps of:
determining, using a first computing device, a location of an asset;
generating, using the first computing device, an encrypted message comprising an identifier of the first computing device and the location of the asset;
transmitting, using the first computing device, the encrypted message to a second computing device;
receiving, at the second computing device, a triggering event from the first computing device, wherein the triggering event comprises the encrypted message from the first computing device;
attaching, using the second computing device, metadata to the triggering event, wherein the metadata comprises a time at which the triggering event occurred;
retrieving, using the second computing device, rules associated with the triggering event;
performing, using the second computing device, one or more port scans of the first computing device based on the retrieved rules;
producing, using the second computing device, scan results of the port scans;
attaching, using the second computing device, time-series metadata to each scan result; and
generating and encrypting, using the second computing device, a report with the scan results and the time-series metadata attached to each scan result.
5 . The computer-implemented method of claim 4 , further comprising the steps of:
receiving an encrypted scan report message from the second computing device;
verifying the report's authenticity;
updating a graph with the scan results and the time-series metadata;
storing the graph; and
establishing data structures with data received from one or more network sources.
6 . The computer-implemented method of claim 4 , wherein the second computing device periodically rescans the first computing device based on one or more triggers and updates the graph accordingly.
7 . A system for dynamic geospatially-referenced cyber-physical infrastructure inventory and asset management, comprising one or more computers with executable instructions that, when executed, cause the system to:
determine a location of an asset;
generate an encrypted message comprising an identifier of a first computing device and the location of the asset; and
transmit the encrypted message to a second computing device;
receive a triggering event from the first computing device, wherein the triggering event comprises the encrypted message from the first computing device;
attach metadata to the triggering event, wherein the metadata comprises a time at which the triggering event occurred;
retrieve rules associated with the triggering event;
perform one or more port scans of the first computing device based on the retrieved rules;
produce scan results of the port scans;
attach time-series metadata to each scan result; and
generate and encrypt a report with the scan results and the time-series metadata attached to each scan result.
8 . The system of claim 7 , wherein the executable instructions further cause the system to:
receive an encrypted scan report message from the second computing device;
verify the report's authenticity;
update a graph with the scan results and the time-series metadata;
store the graph;
establish data structures with data received from one or more network sources.
9 . The system of claim 7 , wherein the second computing device periodically rescans the first computing device based on one or more triggers and updates the graph accordingly.
10 . Non-transitory, computer-readable storage media having computer-executable instructions embodied thereon that, when executed by one or more processors of a computing system employing asset management for dynamic geospatially-referenced cyber-physical infrastructure inventory, cause the computing system to:
determine a location of an asset;
generate an encrypted message comprising an identifier of a first computing device and the location of the asset location;
transmit the encrypted message to a second computing device;
receive a triggering event from the first computing device, wherein the triggering event comprises the encrypted message from the first computing device;
attach metadata to the triggering event, wherein the metadata comprises a time at which the triggering event occurred;
retrieve rules associated with the triggering event;
perform one or more port scans of the first computing device based on the retrieved rules;
produce scan results of the port scans;
attach time-series metadata to each scan result; and
generate and encrypt a report with the scan results and the time-series metadata attached to each scan result.
11 . The non-transitory, computer-readable storage media of claim 10 , wherein the computer-executable instructions further cause the computing system to:
receive an encrypted scan report message from the second computing device;
verify the report's authenticity;
update a graph with the scan results and the time-series metadata;
store the graph;
establish data structures with data received from one or more network sources.
12 . The non-transitory, computer-readable storage media of claim 10 , wherein the second computing device periodically rescans the first computing device based on one or more triggers and updates the graph accordingly.