IP Library Granted Patent US 12,701,106
Granted Patent B2
US 12,701,106 · App. 18/789,647 · Granted Aug 4, 2026

Ongoing trigger-based scanning of cyber-physical assets

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/0428G06F16/909G06F16/951G06N7/01H04L9/14H04L9/3236H04L9/3297H04L63/061H04L63/12H04L63/123H04L63/1408H04L63/1433H04L67/52G06N5/01G06N5/045G06N5/046G06N20/00H04L9/50H04L63/0442H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,701,106
App. No.
18/789,647
Filed
Jul 30, 2024
Granted
Aug 4, 2026
Kind
B2
Art Unit
2497
USPC
713/168
Abstract

A system and method for trigger-based scanning of cyber-physical assets, including a distributed operating system, parameter evaluation engine, at least one cyber-physical asset, at least one crypt-ledger, a network, and a scanner that detects trigger conditions and events and performs scans of cyber-physical assets based on the trigger and any relevant stored scan rules before storing scan results as time-series data.

Claims (74)

1 . A computing system for dynamic geospatially-referenced cyber-physical infrastructure inventory and asset management, comprising:

a first computing device comprising a first processor, a first memory, and a first plurality of programming instructions, when operating on the first computing device, cause the first computing device to:

determine a location of an asset;

generate an encrypted message comprising an identifier of the first computing device and the location of the asset; and

transmit the encrypted message to a second computing device;

the second computing device comprising a second processor, a second memory, and a second plurality of programming instructions, when operating on the second computing device, cause the second computing device to:

receive a triggering event from the first computing device, wherein the triggering event comprises the encrypted message from the first computing device;

attach metadata to the triggering event, wherein the metadata comprises a time at which the triggering event occurred;

retrieve rules associated with the triggering event;

perform one or more port scans of the first computing device based on the retrieved rules;

produce scan results of the port scans;

attach time-series metadata to each scan result; and

generate and encrypt a report with the scan results and the time-series metadata attached to each scan result.

2 . The system of claim 1 , further comprising a third computing device comprising a third processor, a third memory, and a third plurality of programming instructions, when operating on the third processor, cause the third computing device to:

receive an encrypted scan report message from the second computing device;

verify the report's authenticity;

update a graph with the scan results and the time-series metadata;

store the graph; and

establish data structures with data received from one or more network sources.

3 . The system of claim 1 , wherein the second computing device periodically rescans the first computing device based on one or more triggers and updates the graph accordingly.

4 . A computer-implemented method for dynamic geospatially-referenced cyber-physical infrastructure inventory and asset management, the computer-implemented method comprising the steps of:

determining, using a first computing device, a location of an asset;

generating, using the first computing device, an encrypted message comprising an identifier of the first computing device and the location of the asset;

transmitting, using the first computing device, the encrypted message to a second computing device;

receiving, at the second computing device, a triggering event from the first computing device, wherein the triggering event comprises the encrypted message from the first computing device;

attaching, using the second computing device, metadata to the triggering event, wherein the metadata comprises a time at which the triggering event occurred;

retrieving, using the second computing device, rules associated with the triggering event;

performing, using the second computing device, one or more port scans of the first computing device based on the retrieved rules;

producing, using the second computing device, scan results of the port scans;

attaching, using the second computing device, time-series metadata to each scan result; and

generating and encrypting, using the second computing device, a report with the scan results and the time-series metadata attached to each scan result.

5 . The computer-implemented method of claim 4 , further comprising the steps of:

receiving an encrypted scan report message from the second computing device;

verifying the report's authenticity;

updating a graph with the scan results and the time-series metadata;

storing the graph; and

establishing data structures with data received from one or more network sources.

6 . The computer-implemented method of claim 4 , wherein the second computing device periodically rescans the first computing device based on one or more triggers and updates the graph accordingly.

7 . A system for dynamic geospatially-referenced cyber-physical infrastructure inventory and asset management, comprising one or more computers with executable instructions that, when executed, cause the system to:

determine a location of an asset;

generate an encrypted message comprising an identifier of a first computing device and the location of the asset; and

transmit the encrypted message to a second computing device;

receive a triggering event from the first computing device, wherein the triggering event comprises the encrypted message from the first computing device;

attach metadata to the triggering event, wherein the metadata comprises a time at which the triggering event occurred;

retrieve rules associated with the triggering event;

perform one or more port scans of the first computing device based on the retrieved rules;

produce scan results of the port scans;

attach time-series metadata to each scan result; and

generate and encrypt a report with the scan results and the time-series metadata attached to each scan result.

8 . The system of claim 7 , wherein the executable instructions further cause the system to:

receive an encrypted scan report message from the second computing device;

verify the report's authenticity;

update a graph with the scan results and the time-series metadata;

store the graph;

establish data structures with data received from one or more network sources.

9 . The system of claim 7 , wherein the second computing device periodically rescans the first computing device based on one or more triggers and updates the graph accordingly.

10 . Non-transitory, computer-readable storage media having computer-executable instructions embodied thereon that, when executed by one or more processors of a computing system employing asset management for dynamic geospatially-referenced cyber-physical infrastructure inventory, cause the computing system to:

determine a location of an asset;

generate an encrypted message comprising an identifier of a first computing device and the location of the asset location;

transmit the encrypted message to a second computing device;

receive a triggering event from the first computing device, wherein the triggering event comprises the encrypted message from the first computing device;

attach metadata to the triggering event, wherein the metadata comprises a time at which the triggering event occurred;

retrieve rules associated with the triggering event;

perform one or more port scans of the first computing device based on the retrieved rules;

produce scan results of the port scans;

attach time-series metadata to each scan result; and

generate and encrypt a report with the scan results and the time-series metadata attached to each scan result.

11 . The non-transitory, computer-readable storage media of claim 10 , wherein the computer-executable instructions further cause the computing system to:

receive an encrypted scan report message from the second computing device;

verify the report's authenticity;

update a graph with the scan results and the time-series metadata;

store the graph;

establish data structures with data received from one or more network sources.

12 . The non-transitory, computer-readable storage media of claim 10 , wherein the second computing device periodically rescans the first computing device based on one or more triggers and updates the graph accordingly.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2024
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 068272/0203 →
Continuity (18)
Continuation 18353898 · Jul 18, 2023
Continuation 17139701 · Dec 31, 2020
Continuation In Part 16910623 · Jun 24, 2020
Continuation In Part 15930063 · May 12, 2020
Continuation 15904006 · Feb 23, 2018
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Related Publication 20240388574A1 · Nov 21, 2024
References Cited (44)
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 8316237B1 · Felsher et al. · 2012 [cited by applicant]
US 8549650B2 · Hanson · 2013 [cited by applicant]
US 8677473B2 · Dennerline et al. · 2014 [cited by applicant]
US 8788254B2 · Peloski · 2014 [cited by applicant]
US 8856936B2 · Datta Ray et al. · 2014 [cited by applicant]
US 9020802B1 · Florissi et al. · 2015 [cited by applicant]
US 9043920B2 · Gula et al. · 2015 [cited by applicant]
US 9122694B1 · Dukes et al. · 2015 [cited by applicant]
US 9299029B1 · Kim · 2016 [cited by applicant]
US 9319430B2 · Bell, Jr. et al. · 2016 [cited by applicant]
US 9350550B2 · Nix · 2016 [cited by applicant]
US 9357381B2 · Cho et al. · 2016 [cited by applicant]
US 9426118B2 · Kim · 2016 [cited by applicant]
US 9451462B2 · Kim et al. · 2016 [cited by applicant]
US 9467464B2 · Gula et al. · 2016 [cited by applicant]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9672355B2 · Titonis et al. · 2017 [cited by applicant]
US 9967334B2 · Ford · 2018 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10200233B2 · Anderson et al. · 2019 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10262321B1 · Ramanathan et al. · 2019 [cited by applicant]
US 10320828B1 · Derbeko · 2019 [cited by examiner]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 10831838B2 · Kraning et al. · 2020 [cited by applicant]
US 20040193943A1 · Angelino · 2004 [cited by examiner]
US 20100125900A1 · Dennerline · 2010 [cited by examiner]
US 20120197911A1 · Banka · 2012 [cited by examiner]
US 20130097706A1 · Titonis · 2013 [cited by examiner]
US 20130104236A1 · Ray · 2013 [cited by examiner]
US 20140013434A1 · Ranum et al. · 2014 [cited by applicant]
US 20140358911A1 · McCarthy et al. · 2014 [cited by applicant]
US 20150071139A1 · Nix · 2015 [cited by examiner]
US 20150350003A1 · Anderson · 2015 [cited by examiner]
US 20150365437A1 · Bell, Jr. · 2015 [cited by examiner]
US 20150371224A1 · Lingappa · 2015 [cited by applicant]
US 20150379072A1 · Dirac et al. · 2015 [cited by applicant]
US 20160099960A1 · Gerritz · 2016 [cited by examiner]
US 20160119284A1 · Kim · 2016 [cited by examiner]
US 20160203448A1 · Metnick et al. · 2016 [cited by applicant]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]