IP Library Granted Patent US 11,805,106
Granted Patent B2
US 11,805,106 · App. 17/139,701 · Granted Oct 31, 2023

System and method for trigger-based scanning of cyber-physical assets

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX, INC.
H04L63/0428G06F16/909G06F16/951G06N7/01H04L9/14H04L9/3236H04L9/3297H04L63/061H04L63/12H04L63/123H04L63/1408H04L63/1433G06N5/01G06N5/045G06N5/046G06N20/00H04L9/50H04L63/0442H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,805,106
App. No.
17/139,701
Granted
Oct 31, 2023
Kind
B2
Abstract

A system and method for trigger-based scanning of cyber-physical assets, including a distributed operating system, parameter evaluation engine, at least one cyber-physical asset, at least one crypt-ledger, a network, and a scanner that detects trigger conditions and events and performs scans of cyber-physical assets based on the trigger and any relevant stored scan rules before storing scan results as time-series data.

Claims (21)

1. A system for dynamic geospatially-referenced cyber-physical infrastructure inventory and asset management, comprising:

a first computing device coupled to a physical asset and comprising a first processor, a first memory, a geolocation device, and a first plurality of programming instructions stored in the memory and operating on the processor, wherein the first plurality of programmable instructions, when operating on the first processor, cause the first computing device to periodically perform the following actions:

determine a geographical location of the physical asset using the geolocation device;

generate an encrypted asset status update message, the encrypted asset status update message comprising a device identifier of the first computing device and the geographical location of the physical asset; and

transmit the encrypted asset status update message via a network to a second computing device; and

the second computing device comprising a second processor, a second memory, and a second plurality of programming instructions stored in the second memory and operating on the second processor, wherein the second programmable instructions, when operating on the second processor, cause the second computing device to:

receive a triggering event from the first computing device, the trigger event comprising a plurality of packets received over a network satisfying a preconfigured condition;

attach time-series metadata to the triggering event comprising a time at which the triggering event occurred;

retrieve a plurality of stored scan rules associated with the triggering event from the second memory or a database;

perform an initial scan of one or more ports of the first computing device using the plurality of scan rules;

produce an initial scan result comprising a first list of network vulnerabilities;

attach initial time-series metadata to the initial scan result comprising a time at which the initial scan was initiated;

analyze the first list of network vulnerabilities to determine whether an additional scan is needed;

when the additional scan is needed, perform the additional scan and produce an additional scan result comprising a second list of network vulnerabilities;

attach additional time-series metadata to the additional scan result comprising a time at which the additional scan was initiated; and

generate and encrypt a scan report message comprising the initial scan result and its attached time-series metadata, and the additional scan result and its attached time-series metadata;

transmit the encrypted scan report message to the second computing device;

wherein:

the second computing device verifies the authenticity of the encrypted scan report message and modifies a cyber-physical graph to include the first list of network vulnerabilities and the initial time-series data, and the second list of network vulnerabilities and the additional time-series metadata, based upon the contents of the verified encrypted scan report message; and

the cyber-physical graph is stored in a multidimensional time-series database, used to receive data asynchronously from multiple sources over a period of time, and establishing graph-series data structures with the received data.

2. The system of claim 1 , wherein the attached time-series metadata comprises the time at which each scan was completed.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2021
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 054820/0014 →