IP Library Granted Patent US 12,052,228
Granted Patent B2
US 12,052,228 · App. 18/353,898 · Granted Jul 30, 2024

System and method for ongoing trigger-based scanning of cyber-physical assets

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/0428G06F16/909G06F16/951G06N7/01H04L9/14H04L9/3236H04L9/3297H04L63/061H04L63/12H04L63/123H04L63/1408H04L63/1433G06N5/01G06N5/045G06N5/046G06N20/00H04L9/50H04L63/0442H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,052,228
App. No.
18/353,898
Granted
Jul 30, 2024
Kind
B2
Abstract

A system and method for trigger-based scanning of cyber-physical assets, including a distributed operating system, parameter evaluation engine, at least one cyber-physical asset, at least one crypt-ledger, a network, and a scanner that detects trigger conditions and events and performs scans of cyber-physical assets based on the trigger and any relevant stored scan rules before storing scan results as time-series data.

Claims (38)

1. A system for dynamic geospatially-referenced cyber-physical infrastructure inventory and asset management, comprising:

a first computing device coupled to a physical asset and comprising a first processor, a first memory, and a first plurality of programming instructions stored in the memory and operating on the processor, wherein the first plurality of programmable instructions, when operating on the first processor, cause the computing device to perform the following actions:

periodically determine a geographical location of the physical asset;

generate an encrypted asset status update message, the encrypted asset status update message comprising a device identifier of the first computing device and the geographical location of the physical asset; and

transmit the encrypted asset status update message via a network to a second computing device; and

the second computing device comprising a second processor, a second memory, and a second plurality of programming instructions stored in the second memory and operating on the second processor, wherein the second programmable instructions, when operating on the second processor, cause the second computing device to:

receive a triggering event from the first computing device, the triggering event comprising a plurality of packets received over a network satisfying a preconfigured condition;

attach time-series metadata to the triggering event comprising a time at which the triggering event occurred;

retrieve a plurality of stored scan rules associated with the triggering event from the second memory or a database;

perform a plurality of scans of one or more ports of the first computing device using the plurality of scan rules;

produce a plurality of scan results comprising a list of network vulnerabilities;

for each scan, attach time-series metadata to the corresponding scan result comprising a time at which the respective scan was initiated; and

generate and encrypt a scan report message comprising the plurality of scan results and attached time-series metadata.

2. The system of claim 1 , further comprising a third computing device comprising a third processor, a third memory, and a third plurality of programming instructions stored in the third memory and operating on the third processor, wherein the third programmable instructions, when operating on the third processor, cause the third computing device to:

receive an encrypted scan report message from the second computing device;

verify the authenticity of the encrypted scan report;

modify a cyber-physical graph to include the list of network vulnerabilities and the plurality of scan results and associated time-series metadata based upon the contents of the verified encrypted asset and scan status encrypted scan report message;

store the cyber-physical graph in a multidimensional time-series database;

establishing graph-series data structures with the received data.

3. The system of claim 1 , wherein the second computing device periodically rescans the first computing device based on one or more triggers and updates the cyber-physical graph accordingly.

4. A method for dynamic geospatially-referenced cyber-physical infrastructure inventory and asset management, comprising the steps of:

periodically determining a geographical location of the physical asset coupled to a first computing device;

generating an encrypted asset status update message, the encrypted asset status update message comprising a device identifier of the first computing device and the geographical location of the physical asset;

transmitting the encrypted asset status update message via a network to a second computing device;

receiving, at the second computing device, a triggering event from the first computing device, the triggering event comprising a plurality of packets received over a network satisfying a preconfigured condition;

attaching time-series metadata to the triggering event comprising a time at which the triggering event occurred;

retrieving a plurality of stored scan rules associated with the triggering event;

performing a plurality of scans of one or more ports of the first computing device using the plurality of scan rules;

producing a plurality of scan results comprising a list of network vulnerabilities;

for each scan, attaching time-series metadata to the corresponding scan result comprising a time at which the respective scan was initiated; and

generating and encrypting a scan report message comprising the plurality of scan results and attached time-series metadata.

5. The method of claim 4 , further comprising the steps of:

receiving, at a third computing device, an encrypted scan report message from the second computing device;

verifying the authenticity of the encrypted scan report;

modifying a cyber-physical graph to include the list of network vulnerabilities and the plurality of scan results and associated time-series metadata based upon the contents of the verified encrypted asset and scan status encrypted scan report message;

storing the cyber-physical graph in a multidimensional time-series database; and

establishing graph-series data structures with the received data.

6. The method of claim 4 , wherein the second computing device periodically rescans the first computing device based on one or more triggers and updates the cyber-physical graph accordingly.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2023
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 064427/0912 →