IP Library Granted Patent US 11,025,674
Granted Patent B2
US 11,025,674 · App. 16/777,270 · Granted Jun 1, 2021

Cybersecurity profiling and rating using active and passive external reconnaissance

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX, INC.
H04L63/20G06F16/2477G06F16/951H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,025,674
App. No.
16/777,270
Granted
Jun 1, 2021
Kind
B2
Abstract

A system and method for generating comprehensive security profiles and ratings for organizations that takes into account the organization's infrastructure and operations in generating the profile, and the context and purpose of the rating to be generated related to the profile. The system and method may further comprise gathering data about the totality of the organization's infrastructure and operations, generating a cybersecurity profile using active and passive internal and external reconnaissance of the organization to determine cybersecurity vulnerabilities and potential impacts to the business in light of the information gathered about the organization's infrastructure and operations, and generating cybersecurity scores and ratings that take into account all of the above information, plus the context and purpose of the score or rating to be generated based on the cybersecurity profile.

Claims (61)

1. A system for cybersecurity profiling and rating using internal and external reconnaissance, comprising:

a cyber-physical graph module comprising a first plurality of programming instructions stored in a memory of, and operating on a processor of, a computing device, wherein the first plurality of programming instructions, when operating on the processor, cause the computing device to:

receive information about an organization, the information comprising entities associated with the organization and relationships between entities associated with the organization;

create a cyber-physical graph of the organization using the information, the cyber-physical graph comprising nodes representing the entities associated with the organization and edges representing the relationships between entities associated with the organization;

a reconnaissance engine comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programming instructions, when operating on the processor, cause the computing device to:

determine a reconnaissance search to be performed using the cyber-physical graph;

identify a search tool to perform the reconnaissance search;

instantiate a search task using the search tool;

receive search data from the search task;

apply some or all of the search data to the cyber-physical graph to create a cybersecurity profile of the organization; and

send the cybersecurity profile and search data to a scoring engine; and

a scoring engine comprising a third plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the third plurality of programming instructions, when operating on the processor, cause the computing device to:

receive the cybersecurity profile and search data;

using the cyber-physical graph and the search data:

estimate a frequency and severity of cyber-attacks on the organization;

identify a plurality of cybersecurity risks associated with the organization;

determine a business impact for each cybersecurity risk identified;

assign a network resilience rating to the organization;

receive a context for scoring; and

assign a functional cybersecurity score by adjusting the network resilience rating based on the context.

2. The system of claim 1 , further comprising a data to rule mapper comprising a fourth plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the fourth plurality of programming instructions, when operating on the processor, cause the computing device to:

receive a plurality of rules;

retrieve the search data;

map a rule to each data point in the search data;

assign a possible consequence for each data point based on the rule mapped to the data point; and

send the possible consequence for each data point to the scoring engine as additional data for consideration in scoring.

3. The system of claim 1 , wherein the information about the organization further comprises information about business processes within the organization.

4. The system of claim 1 , wherein the information about the organization further comprises prior loss information for the organization.

5. The system of claim 1 , wherein the search tool is a third party search tool available on the Internet.

6. The system of claim 1 , wherein the search tool comprises a fifth plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the fifth plurality of programming instructions, when operating on the processor, cause the computing device to perform a search task as directed by the reconnaissance engine.

7. The system of claim 1 , further comprising a directed computational graph, comprising nodes representing data transformations and edges representing communications between the nodes;

wherein a plurality of nodes represents a data transformation pipeline; and

wherein the directed computational graph is used to direct a workflow in the system.

8. A method for cybersecurity profiling and rating using internal and external reconnaissance, comprising the steps of:

receiving information about an organization, the information comprising entities associated with the organization and relationships between entities associated with the organization;

creating a cyber-physical graph of the organization using the information, the cyber-physical graph comprising nodes representing the entities associated with the organization and edges representing the relationships between entities associated with the organization;

determining a reconnaissance search to be performed using the cyber-physical graph;

identifying a search tool to perform the reconnaissance search;

instantiating a search task using the search tool;

receiving search data from the search task;

applying some or all of the search data to the cyber-physical graph to create a cybersecurity profile of the organization; and

using the cyber-physical graph and the search data:

estimating a frequency and severity of cyber-attacks on the organization;

identifying a plurality of cybersecurity risks associated with the organization;

determining a business impact for each cybersecurity risk identified;

assigning a network resilience rating to the organization;

receiving a context for scoring; and

assigning a functional cybersecurity score by adjusting the network resilience rating based on the context.

9. The method of claim 8 further comprising the steps of:

receiving a plurality of rules;

retrieving the search data;

mapping a rule to each data point in the search data;

assigning a possible consequence for each data point based on the rule mapped to the data point; and

using the possible consequence for each data point as additional data for consideration in scoring.

10. The method of claim 8 wherein the information about the organization further comprises information about business processes within the organization.

11. The method of claim 8 wherein the information about the organization further comprises prior loss information for the organization.

12. The method of claim 8 wherein the search tool is a third party search tool available on the Internet.

13. The method of claim 8 wherein the search tool comprises a fifth plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the fifth plurality of programming instructions, when operating on the processor, cause the computing device to perform a search task.

14. The method of claim 8 further comprising a directed computational graph, comprising nodes representing data transformations and edges representing communications between the nodes;

wherein a plurality of nodes represents a data transformation pipeline; and

wherein the directed computational graph is used to direct a workflow in the system.

Assignments (7)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
CHANGE OF ADDRESS Recorded Dec 29, 2022
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 062251/0629 →
CHANGE OF ADDRESS Recorded Oct 27, 2020
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 054298/0094 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2020
From: CRABTREE, JASON; SELLERS, ANDREW; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 051708/0098 →
Continuity (20)
Continuation In Part 16720383 · Dec 19, 2019
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 16777270
Continuation In Part 16720383 · Dec 19, 2019
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Related Publication 20200296137A1 · Sep 17, 2020
Cited By (1)
US 12,603,911