IP Library Granted Patent US 10,320,827
Granted Patent B2
US 10,320,827 · App. 15/791,058 · Granted Jun 11, 2019

Automated cyber physical threat campaign analysis and attribution

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO); Ian MacLeod (Arlington, VA)
Assignee: Fractal Industries, Inc.
H04L63/1425G06F16/9024G06F21/577H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,320,827
App. No.
15/791,058
Granted
Jun 11, 2019
Kind
B2
Abstract

A system for automated cyber physical threat campaign analysis and attribution, comprising a multi-dimensional time series and graph hybrid data server, an automated planning service module, and a directed computation graph module. A dataset is gathered from a monitored network and aggregated into a cyber-physical systems graph. Cyberattack simulations on the monitored network are made using exogenously collected data as input. Metrics are generated based on the cyber-physical systems graph and results from the cyberattack simulations, and the generated metrics are used to develop a threat profile.

Claims (40)

1. A system for automated cyber physical threat campaign analysis and attribution, comprising:

a multi-dimensional time series and graph hybrid data server comprising a memory, a processor, and a plurality of programming instructions stored in the memory thereof and operable on the processor thereof, wherein the programmable instructions, when operating on the processor, cause the processor to:

create a dataset based at least in part by data gathered from a monitored network and exogenous data collected from published threat intelligence feeds and extracted from public-facing websites; and

aggregate the dataset into a cyber-physical systems graph;

an automated planning service module comprising a memory, a processor, and a plurality of programming instructions stored in the memory thereof and operable on the processor thereof, wherein the programmable instructions, when operating on the processor, cause the processor to:

receive the dataset from the multi-dimensional time series data server; and

conduct a plurality of cyberattack simulations on the monitored network with the dataset as input data, wherein the plurality of cyberattack simulations comprises cyberattacks from substantially all points of the monitored network; and

a directed computation graph module comprising a memory, a processor, and a plurality of programming instructions stored in the memory thereof and operable on the processor thereof, wherein the programmable instructions, when operating on the processor, cause the processor to:

receive the cyber-physical systems graph from the multi-dimensional time series and graph hybrid data server;

generate a plurality of metrics based at least in part by the cyber-physical systems graph;

continuously monitor the plurality of metrics for changes, anomalies, or specific critical thresholds; and

analyze results from the cyberattack simulations and the generated metrics to develop a threat profile and to identify at least one threat actor or one threat campaign; and

send an alert to an external system or organization based on the analysis.

2. The system of claim 1 , wherein a threat actor is identified using the threat profile.

3. The system of claim 1 , wherein a threat campaign is identified using the threat profile.

4. The system of claim 1 , wherein a current attack phase is determined using the threat profile.

5. The system of claim 1 , wherein the threat profile is further developed through additional analysis iterations.

6. The system of claim 1 , wherein at least a portion of the dataset is based on network telemetry.

7. The system of claim 1 , wherein at least a portion of the dataset is based on endpoint data.

8. The system of claim 1 , wherein at least a portion of the data is based on security system information.

9. The system of claim 1 , wherein at least a portion of the data is based application and performance data.

10. A method for automated cyber physical threat campaign analysis and attribution, comprising the steps of:

(a) creating a dataset based at least in part by data gathered from a monitored network and exogenous sources, using a multi-dimensional time series and graph hybrid data server;

(b) aggregating the dataset into a cyber-physical systems graph, using the multi-dimensional time series data server;

(c) receiving the dataset from the multi-dimensional time series data server, using an automated planning service module;

(d) conducting a plurality of cyberattack simulations on the monitored network with the dataset as input data, using the automated planning service module, wherein the plurality of cyberattack simulations comprises cyberattacks from substantially all points of the monitored network;

(e) receiving the cyber-physical systems graph from the multi-dimensional time series data server, using a directed computation graph module;

(f) generating a plurality of metrics based at least in part by the cyber-physical systems graph; and

(g) analyzing results from the cyberattack simulations, and the generated metrics to develop a threat profile;

(h) continuously monitoring the plurality of metrics for changes, anomalies, or specific critical thresholds;

(i) identifying at least one threat actor or one threat campaign; and

(j) sending an alert to an external system or organization based on the analysis of step (g).

11. The method of claim 10 , wherein a threat actor is identified using the threat profile.

12. The method of claim 10 , wherein a threat campaign is identified using the threat profile.

13. The method of claim 10 , wherein a current attack phase is determined using the threat profile.

14. The method of claim 10 , wherein the threat profile is further developed through additional analysis iterations.

15. The method of claim 10 , wherein at least a portion of the dataset is based on network telemetry.

16. The method of claim 10 , wherein at least a portion of the dataset is based on endpoint data.

17. The method of claim 10 , wherein at least a portion of the data is based on security system information.

18. The method of claim 10 , wherein at least a portion of the data is based application and performance data.

Assignments (9)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
CHANGE OF ADDRESS Recorded Dec 29, 2022
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 062251/0629 →
CHANGE OF ADDRESS Recorded Oct 27, 2020
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 054298/0094 →
CHANGE OF NAME Recorded Aug 7, 2019
From: FRACTAL INDUSTRIES, INC.
To: QOMPLX, INC.
Reel/Frame 049996/0698 →
CHANGE OF ADDRESS Recorded Aug 7, 2019
From: FRACTAL INDUSTRIES, INC.
To: QOMPLX, INC.
Reel/Frame 049996/0683 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2017
From: CRABTREE, JASON; SELLERS, ANDREW; MACLEOD, IAN
To: FRACTAL INDUSTRIES, INC.
Reel/Frame 043998/0470 →
Continuity (13)
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15791058
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62574713 · Oct 19, 2017
Related Publication 20180159881A1 · Jun 7, 2018
Cited By (1)
US 12,368,730