IP Library Granted Patent US 10,594,714
Granted Patent B2
US 10,594,714 · App. 15/825,350 · Granted Mar 17, 2020

User and entity behavioral analysis using an advanced cyber decision platform

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO); Nhan Tran (Springfield, VA); Sethan Arja (Hendon, VA); Shadrack Antwi (Manassas, VA); Ian MacLeod (Arlington, VA); Penelope Brooks (Augusta, MI); Angad Salaria (Herndon, VA)
Assignee: QOMPLX, INC.
H04L63/1425H04L63/20G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,594,714
App. No.
15/825,350
Filed
Nov 29, 2017
Granted
Mar 17, 2020
Kind
B2
Art Unit
2497
USPC
726/22
Abstract

A cybersecurity system that protects against cyber attacks by performing user and device behavioral analysis using an advanced cyber decision platform which creates a map of users and devices attached to a network, develops a baseline of expected interactions and behaviors for each user and device in the map, and monitors deviations from the expected interactions and behaviors.

Claims (46)

1. A system for user and entity behavioral analysis using an advanced cyber decision platform, comprising:

a computing device comprising a memory and a processor;

a grouping engine comprising a first plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the first plurality of programming instructions, when operating on the processor, cause the computing device to:

create an interaction dataset based at least in part on interactions of users and devices within a network;

process the interaction dataset with at least graph analysis to generate an interaction map;

store the interaction dataset and interaction map; and

create a plurality of groups from the users and devices within the network based at least in part on the interaction map;

a behavioral analysis engine comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programming instructions, when operating on the processor, cause the computing device to:

create a network-usage dataset based at least in part on access logs of the users and devices within the network;

process the network-usage dataset to generate a behavioral baseline for each of the previously created groups; and

store the network-usage dataset and behavioral baseline; and

a monitoring service comprising a third plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the third plurality of programming instructions, when operating on the processor, cause the computing device to:

continuously monitor each group for anomalous network behavior based at least on the behavioral baseline;

periodically create and store a behavioral analysis snapshot of the users and devices within the network;

receive an identified vulnerability and an identified extent to which the network may be compromised from a simulation engine;

improve the security of the network by changing an access privilege of one or more of the users and devices on the network based on the identified vulnerability and identified extent; and

a simulation engine comprising a fourth plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the fourth plurality of programming instructions, when operating on the processor, cause the computing device to:

retrieve the interaction dataset, interaction map, the network-usage dataset, behavioral baseline, and behavioral analysis snapshot from storage;

run a simulation comprising a simulated cyber-attack of a particular type on the network using the interaction dataset, interaction map, the network-usage dataset, behavioral baseline, and behavioral analysis snapshot;

identify a vulnerability of the network to the simulated cyber-attack of a particular type;

identify an extent to which the network may be compromised based on the simulated cyber-attack of a particular type;

send the identified vulnerability and identified extent to the monitoring service.

2. The system of claim 1 , wherein a corrective measure is automatically located and applied in the event of anomalous behavior detection.

3. The system of claim 1 , wherein the grouping engine dynamically adjusts groups based on changing group dynamics.

4. The system of claim 1 , wherein at least a portion of the interaction dataset is based on results of natural language processing of internal communications.

5. The system of claim 1 , wherein the behavioral analysis snapshot is used in forecasting group dynamic.

6. A method for user and entity behavioral analysis using an advanced cyber decision platform, comprising the steps of:

creating an interaction dataset based at least in part on interactions of users and devices within a network using a grouping engine;

processing the interaction dataset with at least graph analysis to generate an interaction map using the grouping engine;

storing the interaction dataset and interaction map;

creating a plurality of groups from the users and devices within the network based at least in part on the interaction map using the grouping engine;

creating a network-usage dataset based at least in part on access logs of the users and devices within the network using a behavioral analysis engine;

processing the network-usage dataset to generate a behavioral baseline for each of the previously created groups using the behavioral analysis engine;

storing the network-usage dataset and behavioral baseline;

continuously monitoring each group for anomalous network behavior based at least on the behavioral baseline using a monitoring service;

periodically creating and storing a behavioral analysis snapshot of the users and devices within the network;

retrieving the interaction dataset, interaction map, the network-usage dataset, behavioral baseline, and behavioral analysis snapshot from storage;

running a simulation comprising a simulated cyber-attack of a particular type on the network using the interaction dataset, interaction map, the network-usage dataset, behavioral baseline, and behavioral analysis snapshot;

identifying a vulnerability of the network to the simulated cyber-attack of a particular type;

identifying an extent to which the network may be compromised based on the simulated cyber-attack of a particular type;

sending the identified vulnerability and identified extent to the monitoring service; and

improving the security of the network by changing an access privilege of one or more of the users and devices based on the identified vulnerability and identified extent.

7. The method of claim 6 , wherein a corrective measure is automatically located and applied in the event of anomalous behavior detection.

8. The method of claim 6 , wherein the grouping engine dynamically adjusts groups based on changing group dynamics.

9. The method of claim 6 , wherein at least a portion of the interaction dataset is based on results of natural language processing of internal communications.

10. The method of claim 6 , wherein the behavioral analysis snapshot is used in forecasting group dynamic.

Assignments (9)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
CHANGE OF ADDRESS Recorded Dec 29, 2022
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 062251/0629 →
CHANGE OF ADDRESS Recorded Oct 27, 2020
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 054298/0094 →
CHANGE OF NAME Recorded Aug 7, 2019
From: FRACTAL INDUSTRIES, INC.
To: QOMPLX, INC.
Reel/Frame 049996/0698 →
CHANGE OF ADDRESS Recorded Aug 7, 2019
From: FRACTAL INDUSTRIES, INC.
To: QOMPLX, INC.
Reel/Frame 049996/0683 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2017
From: CRABTREE, JASON; SELLERS, ANDREW; TRAN, NHAN; ARJA, SETHAN; ANTWI, SHADRACK; MACLEOD, IAN; BROOKS, PENELOPE; SALARIA, ANGAD
To: FRACTAL INDUSTRIES, INC.
Reel/Frame 044291/0294 →
Continuity (12)
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Related Publication 20180219894A1 · Aug 2, 2018
Cited By (7)
US 12,224,985 US 12,316,666 US 12,361,098 US 12,412,094 US 12,445,466 US 12,615,275 US 12,676,885