IP Library Granted Patent US 10,735,456
Granted Patent B2
US 10,735,456 · App. 15/655,113 · Granted Aug 4, 2020

Advanced cybersecurity threat mitigation using behavioral and deep analytics

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,735,456
App. No.
15/655,113
Filed
Jul 20, 2017
Granted
Aug 4, 2020
Kind
B2
Art Unit
2497
USPC
726/25
Abstract

A system for mitigation of cyberattacks employing an advanced cyber decision platform comprising a time series data store, a directed computational graph module, an action outcome simulation module, and observation and state estimation module, wherein the state of a network is monitored and used to produce a cyber-physical graph representing network resources, simulated network events are produced and monitored, and the network events and their effects are analyzed to produce security recommendations.

Claims (27)

1. A system for operating an advanced cyber decision platform for mitigation of cyberattacks, the system comprising:

a computing device comprising a memory and a processor;

a time series data store comprising a first plurality of programming instructions stored in the memory and operating on the processor, wherein the first plurality of programming instructions, when operating on the processor, cause the computing device to:

monitor a plurality of network events;

produce time-series data comprising at least a record of a network event and the time at which the event occurred;

an observation and state estimation module comprising a second plurality of programming instructions stored in the memory and operating on the processor, wherein the second plurality of programming instructions, when operating on the processor, cause the computing device to:

monitor a plurality of connected resources on a network;

produce a cyber-physical graph representing at least a portion of the plurality of connected resources, the cyber-physical graph comprising at least the logical relationships between the portion of the plurality of connected resources on the network and the physical relationships between any connected resources that comprise at least a hardware device;

a directed computational graph module comprising a third plurality of programming instructions stored in the memory and operating on the processor, wherein the third plurality of programming instructions, when operating on the processor, cause the computing device to:

perform a plurality of analysis and transformation operations on at least a portion of the time-series data;

perform a plurality of analysis and transformation operations on at least a portion of the cyber-physical graph; and

an action-outcome simulation module comprising a fourth plurality of programming instructions stored in the memory and operating on the processor, wherein the fourth plurality of programming instructions, when operating on the processor, cause the computing device to:

produce a simulated network event comprising at least a simulated cyberattack;

produce a plurality of security reports based at least in part on the results of analysis performed by the directed computational graph module, wherein the contents of each report are customized to provide a specialized information stream relevant to the operational role of a recipient of the report.

2. The system of claim 1 , wherein the plurality of analysis and transformation operations performed on at least a portion of the cyber-physical graph comprise the calculation of an impact assessment score for each of a portion of the resources in the graph.

3. The system of claim 2 , wherein the plurality of analysis and transformation operations performed on at least a portion of the time-series data comprise the calculation of the overall impact of a cyberattack, wherein the calculation is based at least in part on the impact assessment score for each resource affected by the cyberattack.

4. The system of claim 1 , wherein the plurality of analysis and transformation operations performed on at least a portion of the cyber-physical graph comprise a comparison of relationships between resources against known security vulnerabilities.

5. The system of claim 4 , wherein the recommendations produced by the action-outcome simulation module are based at least in part on the results of the comparison against known security vulnerabilities.

6. The system of claim 1 , wherein the observation and state estimation module is further configured to produce a visualization based at least in part on at least a portion of the time-series data, wherein the visualization illustrates changes to the data over time.

7. A method for mitigation of cyberattacks employing an advanced cyber decision platform comprising the steps of:

a) producing, using an observation and state estimation module, a cyber-physical graph representing at least a portion of the plurality of connected resources, the cyber-physical graph comprising at least the logical relationships between the portion of the plurality of connected resources on the network and the physical relationships between any connected resources that comprise at least a hardware device;

b) performing, using a directed computational graph module, a plurality of analysis and transformation operations on at least a portion of the cyber-physical graph;

c) producing, using an action outcome simulation module, a simulated network event comprising at least a simulated cyberattack;

d) monitoring, using a time series data store, a plurality of network events comprising at least the simulated cyberattack;

e) producing time-series data based at least in part on the network events;

f) performing a plurality of analysis and transformation operations on at least a portion of the time-series data; and

g) producing a plurality of security reports based at least in part on the results of analysis performed by the directed computational graph module, wherein the contents of each report are customized to provide a specialized information stream relevant to the operational role of a recipient of the report.

Assignments (8)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
CHANGE OF ADDRESS Recorded Oct 27, 2020
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 054298/0094 →
CHANGE OF ADDRESS Recorded Aug 7, 2019
From: FRACTAL INDUSTRIES, INC.
To: QOMPLX, INC.
Reel/Frame 049996/0683 →
CHANGE OF NAME Recorded Aug 7, 2019
From: FRACTAL INDUSTRIES, INC.
To: QOMPLX, INC.
Reel/Frame 049996/0698 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2017
From: CRABTREE, JASON; SELLERS, ANDREW
To: FRACTAL INDUSTRIES, INC.
Reel/Frame 043126/0403 →