Asset context

Combine inventory and exposure evidence without turning uncertain links into facts.

Illustrative reference architecture 3 min read

Reference diagram

Keep asset observations separate from conclusions about them

Evidence and identity

  1. Source observationsInventory, endpoint, and exposure reports
    Preserve provenance and observation time
  2. Temporal matchingScoped IDs, effective intervals, ambiguous candidates
    Version accepted mappings and qualified links
  3. Evidence graphTyped edges with sources and uncertainty

Analyst investigation

  1. Scoped questionAuthorized analyst, asset, and time interval
    Bound the requested traversal
  2. Permitted pivotAllowed nodes, edges, conflicts, and coverage
    Attach selected evidence for review
  3. Case evidenceObservation references and mapping versions

Connections between paths

  • Permitted pivot→Evidence graph

    Request a bounded traversal under current access policy

  • Evidence graph→Permitted pivot

    Return permitted evidence and explicit relationship uncertainty

A graph connection is qualified evidence, not a finding of ownership or compromise. An absent or stale observation must remain distinguishable from confirmed asset retirement.

Begin with observations from several sources

This reference design combines inventory records, endpoint observations, and permitted external exposure feeds for an analyst. Sources differ in what they can see and how often they update. The application presents evidence and qualified relationships; it does not declare an asset owned, vulnerable, or compromised merely because a scan found it.

Assume tenant-scoped access, changing infrastructure, and source-specific identifiers. Record which source supports each fact. A successful import establishes receipt of that source's report, not its completeness or correctness.

Keep the observation and its time

Preserve the source record identifier, observed time or interval, collection time, and import time. A service banner observed last week describes that observation; it does not establish the service's current state. Keep the source's confidence separately from confidence assigned by local matching rules.

Retain permitted evidence references and contradictory observations. STIX observed-data records provide a useful distinction between observed content and the assertions built from it. Repeated reports copied from one original feed should not count as independent corroboration.

Resolve identity within a time interval

Match using scoped source identifiers and dated relationships. Keep an asset instance distinct from the address, hostname, or account associated with it. Addresses can be shared or reassigned; a replacement machine can inherit a familiar name.

NIST's asset-identification model separates identifier representation from the matching logic that consumes it. This design records the matching rule, evidence, and effective interval. Ambiguous candidates remain separate. Corrections create a new mapping version and preserve the earlier interpretation so historical investigations can be reconstructed.

Explain every relationship in the graph

A graph edge needs a type, direction, time range, and supporting source. “Reported as assigned to” differs from “observed communicating with” or “possibly related through a shared certificate.” Mark inferred relationships and the rule that produced them.

Shared hosting or a discovery link does not establish common ownership. Public external inventory documentation distinguishes confirmed inventory, dependencies, and candidates requiring review. Keep comparable distinctions here. A chain of individually plausible links is not automatically a verified ownership or attack path.

Give analysts a bounded pivot

The interface starts from an asset and interval, then shows permitted observations, relationship evidence, conflicts, and missing coverage. Apply authorization before returning nodes, edges, counts, or exports. Limit graph depth, time range, result size, and execution time; offer an explicit next pivot instead of expanding everything.

Attach the selected evidence and mapping versions to a case. Ownership confirmation, vulnerability validation, and incident conclusions need their own evidence. Following a relationship in the interface grants no authority to scan, change, or contain its target.

Treat disappearance as something to explain

A missing observation can mean retirement, permission loss, an expired feed, or a collection gap. Track source coverage and last observation separately from an asset's confirmed lifecycle state. End outdated relationships without erasing evidence needed for earlier intervals.

Monitor stale sources, unresolved matches, disputed links, and review backlog. A graph adds identity maintenance and careful access control. When the question is simple, a source-linked inventory table may be easier to use and validate.

References

Search the site

Search experience, studies, articles, projects, and contributions.

Try a topic