IP Library Granted Patent US 12,542,816
Granted Patent B2
US 12,542,816 · App. 18/600,727 · Granted Feb 3, 2026

Complex IT process annotation, tracing, analysis, and simulation

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/20G06F9/5038G06F16/2477G06F16/951H04L63/1425H04L63/1441G06F9/4881G06F9/54
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,542,816
App. No.
18/600,727
Filed
Mar 10, 2024
Granted
Feb 3, 2026
Kind
B2
Examiner
KORSAK, OLEG
Art Unit
2492
USPC
726/22
Abstract

A system and method for complex IT process annotation and tracing, analysis, and simulation, comprising at least a generative simulation platform, optimization engine, and metric engine, which is able to model and simulate a variety of simulations and develop adaptive models, and can be used more specifically for IT/OT infrastructure and technology enabled process simulation to manage performance and risk in a network enabled business infrastructure, perform load-testing and quality control tests, and determine the overall health to known attacks and potential interruptions as a system or network or process topography changes and updates.

Claims (45)

1 . A computing system for complex IT process annotation and tracing, analysis, and simulation employing a generative simulation platform, the computing system comprising:

one or more hardware processors configured for:

receiving time series data associated with a computer network, the time series data comprising system logs from one or more devices on the computer network;

storing the time series data as a first dataset in a multidimensional time series database;

retrieving the first dataset from the multidimensional time series database;

constructing a knowledge graph from the first dataset by assigning devices, users, user groups, or system properties to nodes and by assigning edges between the nodes representing relationships among the nodes, wherein the knowledge graph is a model of the computer network and its users, and comprises nodes representing devices, users, user groups, or system properties, and vertices representing relationships among the nodes;

selecting a user or user group represented as a node in the directed computational graph;

generating a simulated attack on the model of the computer network by simulating a compromised password of the user or user group;

storing a simulation result, the simulation result comprising a list of nodes accessible using the compromised password;

determining a blast radius comprising an extent to which the computer network would be compromised based on the list of nodes and their relationships to one another;

identifying a plurality of paths between nodes within the blast radius; and

calculating and reporting a resilience metric for the computer network, the resilience metric being based on a Monte-Carlo simulation within the blast radius to determine the worst-scoring relationships in the blast radius.

2 . A computer-implemented method executed on a generative simulation platform for complex IT process annotation and tracing, analysis, and simulation, the computer-implemented method comprising:

receiving time series data associated with a computer network, the time series data comprising system logs from one or more devices on the computer network;

storing the time series data as a first dataset in a multidimensional time series database;

retrieving the first dataset from the multidimensional time series database;

constructing a directed computational graph from the first dataset by assigning devices, users, user groups, or system properties to nodes and by assigning edges between the nodes representing relationships among the nodes, wherein the directed computational graph is a model of the computer network and its users, and comprises nodes representing devices, users, user groups, or system properties, and vertices representing relationships among the nodes;

selecting a user or user group represented as a node in the directed computational graph;

generating a simulated attack on the model of the computer network by simulating a compromised password of the user or user group;

storing a simulation result the simulation result comprising a list of nodes accessible using the compromised password;

determining a blast radius comprising an extent to which the computer network would be compromised based on the list of nodes and their relationships to one another;

identifying a plurality of paths between nodes within the blast radius; and

calculating and reporting a resilience metric for the computer network, the resilience metric being based on a Monte-Carlo simulation within the blast radius to determine the worst-scoring relationships in the blast radius.

3 . A system for complex IT process annotation and tracing, analysis, and simulation employing a generative simulation platform, comprising one or more computers with executable instructions that, when executed, cause the system to:

receive time series data associated with a computer network, the time series data comprising system logs from one or more devices on the computer network;

store the time series data as a first dataset in a multidimensional time series;

retrieve the first dataset from the multidimensional time series database;

construct a directed computational graph from the first dataset by assigning devices, users, user groups, or system properties to nodes and by assigning edges between the nodes representing relationships among the nodes, wherein the directed computational graph coordinates the ongoing curation of a model of the computer network and its users, comprised of nodes representing devices, users, user groups, or system properties, and vertices representing relationships among the nodes;

select a user or user group represented as a node in the graph;

generate a simulated attack on the model of the computer network by simulating a compromised password of the user or user group;

store a simulation result the simulation result comprising a list of nodes accessible using the compromised password;

determine a blast radius comprising an extent to which the computer network would be compromised based on the list of nodes and their relationships to one another;

identify a plurality of paths between nodes within the blast radius; and

calculate and report a resilience metric for the computer network, the resilience metric being based on a Monte-Carlo simulation within the blast radius to determine the worst-scoring relationships in the blast radius.

4 . Non-transitory, computer-readable storage media having computer-executable instructions embodied thereon that, when executed by one or more processors of a computing system employing a generative simulation platform for complex IT process annotation and tracing, analysis, and simulation, cause the computing system to:

receive time series data associated with a computer network, the time series data comprising system logs from one or more devices on the computer network;

store the time series data as a first dataset in a multidimensional time series;

retrieve the first dataset from the multidimensional time series database;

construct a directed computational graph from the first dataset by assigning devices, users, user groups, or system properties to nodes and by assigning edges between the nodes representing relationships among the nodes, wherein the directed computational graph is a model of the computer network and its users, and comprises nodes representing devices, users, user groups, or system properties, and vertices representing relationships among the nodes;

select a user or user group represented as a node in the directed computational graph;

generate a simulated attack on the model of the computer network by simulating a compromised password of the user or user group;

store a simulation result the simulation result comprising a list of nodes accessible using the compromised password;

determine a blast radius comprising an extent to which the computer network would be compromised based on the list of nodes and their relationships to one another;

identify a plurality of paths between nodes within the blast radius; and

calculate and report a resilience metric for the computer network, the resilience metric being based on a Monte-Carlo simulation within the blast radius to determine the worst-scoring relationships in the blast radius.