IP Library Granted Patent US 10,560,483
Granted Patent B2
US 10,560,483 · App. 15/823,363 · Granted Feb 11, 2020

Rating organization cybersecurity using active and passive external reconnaissance

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX, INC.
H04L63/20G06F16/2477G06F16/951H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,560,483
App. No.
15/823,363
Granted
Feb 11, 2020
Kind
B2
Abstract

A system for cybersecurity rating using active and passive external reconnaissance, that uses a web crawler that sends message prompts to external hosts and receives responses from external hosts, a time-series data store that produces time-series data from the message responses, and a directed computational graph module that analyzes the time-series data to produce a weighted score representing the overall cybersecurity state of an organization.

Claims (34)

1. An advanced cyber decision platform for external network reconnaissance and cybersecurity rating, the platform comprising:

a computing device comprising a memory and a processor;

a time-series data module comprising a first plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the first plurality of programming instructions, when operating on the processor, cause the computing device to:

receive leak information and reconnaissance data about a company from a web crawler; and

produce time-series data based on at least a portion of the leak information and reconnaissance data;

a directed computational graph module comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programming instructions, when operating on the processor, cause the computing device to:

retrieve at least a portion of the stored time series data;

produce a directed computational graph by performing a plurality of transformation operations on at least a portion of the time-series data, wherein:

each transformation operation sends a message output to subsequent transformation operations;

the directed computational graph comprises nodes and edges, the nodes representing the transformation operations and the edges representing message outputs between the nodes; and

one or more of the transformation operations are linearization of non-linear operations that are created when they are ready to be computed; and

produce a weighted score based on at least a portion of the transformation operations, wherein the weighted score represents a risk of external cyber-security threats to the company based on the collected leak information and the reconnaissance data; and

a web crawler comprising at least a processor, a memory, and a plurality of programming instructions stored in the memory and operating on the processor, wherein the programmable instructions, when operating on the processor, cause the processor to:

collect leak information about a company from publicly-available records using domain name system entries and internet protocol addresses associated with the company;

use the collected leak information to obtain reconnaissance data for websites and Internet applications used by, or affecting, the company, the reconnaissance data comprising:

identifying portions each website or application that web crawlers are requested to ignore;

fingerprinting each website or application to identify characteristic patterns or markers that may be used to identify host or application details;

checking each website's administrative pages to determine if any administrative portals are vulnerable to cyber-attacks; and

determining a patching frequency of each website or application; and

provide the collected leak information and the reconnaissance data to the time-series data module.

2. A method for external network reconnaissance and cybersecurity rating, comprising the steps of:

Using a web crawler to:

collect leak information about a company from publicly-available records using domain name system entries and internet protocol addresses associated with the company;

use the collected leak information to obtain reconnaissance data for websites and Internet applications used by, or affecting, the company, the reconnaissance data comprising:

identifying portions each website or application that web crawlers are requested to ignore;

fingerprinting each website or application to identify characteristic patterns or markers that may be used to identify host or application details;

checking each website's administrative pages to determine if any administrative portals are vulnerable to cyber-attacks; and

determining a patching frequency of each website or application; and

producing, using a time-series data module, time-series data based on at least a portion of the leak information and the reconnaissance data;

producing a directed computational graph by performing, using a directed computational graph module, a plurality of transformation operations on at least a portion of the time-series data, wherein:

each transformation operation sends a message output to subsequent transformation operations;

the directed computational graph comprises nodes and edges, the nodes representing the transformation operations and the edges representing message outputs between the nodes; and

one or more of the transformation operations are linearization of non-linear operations that are created when they are ready to be computed; and

producing a weighted score based on at least a portion of the transformation operations, wherein the weighted score represents a risk of external cyber-security threats to the company based on the collected leak information and the reconnaissance data.

Assignments (9)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
CHANGE OF ADDRESS Recorded Dec 29, 2022
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 062251/0629 →
CHANGE OF ADDRESS Recorded Oct 27, 2020
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 054298/0094 →
CHANGE OF ADDRESS Recorded Aug 7, 2019
From: FRACTAL INDUSTRIES, INC.
To: QOMPLX, INC.
Reel/Frame 049996/0683 →
CHANGE OF NAME Recorded Aug 7, 2019
From: FRACTAL INDUSTRIES, INC.
To: QOMPLX, INC.
Reel/Frame 049996/0698 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2017
From: CRABTREE, JASON; SELLERS, ANDREW
To: FRACTAL INDUSTRIES, INC.
Reel/Frame 044265/0534 →
Continuity (12)
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Related Publication 20180219919A1 · Aug 2, 2018
Cited By (1)
US 12,278,834