IP Library Granted Patent US 11,218,510
Granted Patent B2
US 11,218,510 · App. 16/855,724 · Granted Jan 4, 2022

Advanced cybersecurity threat mitigation using software supply chain analysis

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX, Inc.
H04L63/20G06F16/2477G06F16/951H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,218,510
App. No.
16/855,724
Granted
Jan 4, 2022
Kind
B2
Abstract

A system and method for comprehensive cybersecurity threat assessment of software applications based on the totality of vulnerabilities from all levels of the software supply chain. The system and method comprising analyzing the code and/or operation of a software application to determine components comprising the software, identifying the source of such components, determining vulnerabilities associated with those components, compiling a list of such components, creating a directed graph of relationships between the components and their sources, and evaluating the overall threat associated with the software application based its software supply chain vulnerabilities.

Claims (43)

1. A system for analyzing the cybersecurity threat of software applications from the software supply chain, comprising:

a computing device comprising a memory and a processor;

a software analyzer comprising a first plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the first plurality of programming instructions, when operating on the processor, cause the computing device to:

receive a software application for analysis;

identify one or more software components comprising the software application; and

send a component identifier for each software component identified to a reconnaissance engine;

a reconnaissance engine comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programming instructions, when operating on the processor, cause the computing device to:

receive the component identifier for the one or more software components;

search one or more databases to identify a source of each software component;

search one or more databases to identify a vulnerability of each software component;

send the component identifier, source, and vulnerability for each of the one or more software components to a cyber-physical graph engine;

a cyber-physical graph engine comprising a third plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the third plurality of programming instructions, when operating on the processor, cause the computing device to:

receive the component identifier, source, and vulnerability for each of the one or more software components; and

construct a cyber-physical graph of a software supply chain for the software application, the cyber-physical graph comprising nodes representing the source and vulnerability of each software component of the software application and edges representing the relationships between the nodes; and

a scoring engine comprising a third plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the third plurality of programming instructions, when operating on the processor, cause the computing device to:

run one or more graph-processing algorithms on the cyber-physical graph to determine one or more paths of vulnerability in the software supply chain and a probability of occurrence for each path; and

generate a cybersecurity score for the software application based on the vulnerabilities in the software supply chain.

2. The system of claim 1 , wherein one of the databases used to identify a source of each software component is a vulnerability information database containing structured information.

3. The system of claim 1 , wherein one of the databases used to identify a vulnerability of each software component is a vulnerability information database containing structured information.

4. The system of claim 1 , further comprising a natural language processing engine comprising a fourth plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the fourth plurality of programming instructions, when operating on the processor, cause the computing device to:

retrieve structured data from a source of vulnerability information;

retrieve unstructured data from a different source of vulnerability information;

extract identifiable information regarding vulnerabilities from the structured data;

search, identify, and tag the unstructured data using the identifiable information from the structured data, thereby converting the unstructured data to newly structured data; and

storing a database comprising the newly structured data;

wherein one of the databases used to identify a vulnerability of each software component is the database comprising the newly structured data, or one of the databases used to identify a source of each software component is the database comprising the newly structured data, or both.

5. A method for analyzing the cybersecurity threat of software applications from the software supply chain, comprising the steps of:

receiving a software application for analysis;

identifying one or more software components comprising the software application;

searching one or more databases to identify a source of each software component;

searching one or more databases to identify a vulnerability of each software component;

constructing a cyber-physical graph of a software supply chain for the software application, the cyber-physical graph comprising nodes representing the source and vulnerability of each software component of the software application and edges representing the relationships between the nodes;

running one or more graph-processing algorithms on the cyber-physical graph to determine one or more paths of vulnerability in the software supply chain and a probability of occurrence for each path; and

generating a cybersecurity score for the software application based on the vulnerabilities in the software supply chain.

6. The method of claim 5 , wherein one of the databases used to identify a source of each software component is a vulnerability information database containing structured information.

7. The method of claim 5 , wherein one of the databases used to identify a vulnerability of each software component is a vulnerability information database containing structured information.

8. The method of claim 5 , further comprising the steps of:

retrieving structured data from a source of vulnerability information;

retrieving unstructured data from a different source of vulnerability information;

extracting identifiable information regarding vulnerabilities from the structured data;

searching, identifying, and tagging the unstructured data using the identifiable information from the structured data, thereby converting the unstructured data to newly structured data;

storing a database comprising the newly structured data; and

using the database comprising the newly structured data to identify a vulnerability of each software component, or to identify a source of each software component, or both.

Assignments (7)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
CHANGE OF ADDRESS Recorded Dec 29, 2022
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 062251/0629 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2022
From: SELLERS, ANDREW; CRABTREE, JASON
To: QOMPLX, INC.
Reel/Frame 060611/0505 →
CHANGE OF ADDRESS Recorded Oct 27, 2020
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 054298/0094 →
Continuity (28)
Continuation In Part 16836717 · Mar 31, 2020
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation In Part 15887496 · Feb 2, 2018
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15823285 · Nov 27, 2017
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15788718 · Oct 19, 2017
Continuation In Part 15788002 · Oct 19, 2017
Continuation In Part 15787601 · Oct 18, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62568307 · Oct 4, 2017
Provisional Application 62568312 · Oct 4, 2017
Provisional Application 62568305 · Oct 4, 2017
Related Publication 20210021644A1 · Jan 21, 2021
Cited By (3)
US 12,273,258 US 12,278,835 US 12,574,394