IP Library Granted Patent US 11,184,401
Granted Patent B2
US 11,184,401 · App. 16/792,754 · Granted Nov 23, 2021

AI-driven defensive cybersecurity strategy analysis and recommendation system

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX, Inc.
H04L63/20G06F16/2477G06F16/951H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,184,401
App. No.
16/792,754
Granted
Nov 23, 2021
Kind
B2
Abstract

A system and method for automated cybersecurity defensive strategy analysis that predicts the evolution of new cybersecurity attack strategies and makes recommendations for cybersecurity improvements to networked systems based on a cost/benefit analysis. The system and method use machine learning algorithms to run simulated attack and defense strategies against a model of the networked system created using a directed graph. Recommendations are generated based on an analysis of the simulation results against a variety of cost/benefit indicators.

Claims (39)

1. A system for automated cybersecurity defensive strategy analysis and recommendations, comprising:

an attack implementation engine comprising a first plurality of programming instructions stored in a memory of, and operating on a processor of, a computing device, wherein the first plurality of programming instructions, when operating on the processor, cause the computing device to:

receive test initiation instructions;

implement a cyberattack on a network under test; and

gather system information about the operation of the network under test during the cyberattack, the system information comprising information about the sequence of events and response of affected devices during the cyberattack;

a machine learning simulator comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programming instructions, when operating on the processor, cause the computing device to:

receive the system information;

use the system information to initiate an iterative simulation of a cyberattack strategy sequence, each iteration comprising a simulated attack on a model of the network under test and a simulated defense against the simulated attack, each simulated attack being generated by a first machine learning algorithm;

obtain a simulation result comprising the cyberattack strategy sequence and a probability of success of the attack and the defense in each iteration;

a recommendation engine comprising a third plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the third plurality of programming instructions, when operating on the processor, cause the computing device to:

receive the simulation result;

receive one or more cost factors;

receive one or more benefit factors;

compare the simulation result against the cost factors and the benefit factors; and

determine a cybersecurity improvement recommendation for the network under test based on the comparison.

2. The system of claim 1 , wherein the system information further comprises system logs of one or more of the affected devices.

3. The system of claim 1 , wherein the first machine learning algorithm is a reinforcement learning algorithm.

4. The system of claim 1 , further comprising a second machine learning algorithm, wherein each simulated defense is generated by the second machine learning algorithm, such that the first and second machine learning algorithms compete against each other in the simulation.

5. The system of claim 4 , wherein the second machine learning algorithm is an evolutionary algorithm.

6. The system of claim 5 , wherein the machine learning simulation is an online simulation and the evolutionary algorithm is a continual online evolutionary planning algorithm.

7. The system of claim 6 , wherein the system is run iteratively, with each iteration resulting in a new cybersecurity improvement recommendation, which is implemented on the network under test prior to the next iteration.

8. The system of claim 1 , wherein the cybersecurity improvement recommendation is implemented on the network under test.

9. A method for automated cybersecurity defensive strategy analysis and recommendations, comprising the steps of:

receiving test initiation instructions;

implementing a cyberattack on a network under test;

gathering system information about the operation of the network under test during the cyberattack, the system information comprising information about the sequence of events and response of affected devices during the cyberattack;

using the system information to initiate an iterative simulation of a cyberattack strategy sequence, each iteration comprising a simulated attack on a model of the network under test and a simulated defense against the simulated attack, each simulated attack being generated by a first machine learning algorithm;

obtaining a simulation result comprising the cyberattack strategy sequence and a probability of success of the attack and the defense in each iteration;

receiving one or more cost factors;

receiving one or more benefit factors;

comparing the simulation result against the cost factors and the benefit factors; and

determining a cybersecurity improvement recommendation for the network under test based on the comparison.

10. The method of claim 9 , wherein the system information further comprises system logs of one or more of the affected devices.

11. The method of claim 9 , wherein the first machine learning algorithm is a reinforcement learning algorithm.

12. The method of claim 9 , further comprising a second machine learning algorithm, wherein each simulated defense is generated by the second machine learning algorithm, such that the first and second machine learning algorithms compete against each other in the simulation.

13. The method of claim 12 , wherein the second machine learning algorithm is an evolutionary algorithm.

14. The method of claim 13 , wherein the machine learning simulation is an online simulation and the evolutionary algorithm is a continual online evolutionary planning algorithm.

15. The method of claim 9 , wherein the cybersecurity improvement recommendation is implemented on the network under test.

16. The method of claim 15 , wherein the method is run iteratively, with each iteration resulting in a new cybersecurity improvement recommendation, which is implemented on the network under test prior to the next iteration.

Assignments (7)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
CHANGE OF ADDRESS Recorded Dec 29, 2022
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 062251/0629 →
CHANGE OF ADDRESS Recorded Oct 27, 2020
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 054298/0094 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 17, 2020
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 053246/0767 →
Continuity (17)
Continuation In Part 16779801 · Feb 3, 2020
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974
Related Publication 20210168175A1 · Jun 3, 2021
Cited By (6)
US 12,223,062 US 12,452,082 US 12,556,587 US 12,563,451 US 12,615,235 US 12,682,072