IP Library Granted Patent US 11,323,471
Granted Patent B2
US 11,323,471 · App. 16/945,743 · Granted May 3, 2022

Advanced cybersecurity threat mitigation using cyberphysical graphs with state changes

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX, INC.
H04L63/1441H04L63/1408H04L63/1433G06F11/362
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,323,471
App. No.
16/945,743
Granted
May 3, 2022
Kind
B2
Abstract

A system for mitigation of cyberattacks employing an advanced cyber decision platform comprising a time series data store, a directed computational graph module, an action outcome simulation module, and observation and state estimation module, wherein the state of a network is monitored and used to produce a cyber-physical graph representing network resources, simulated network events are produced and monitored, and the network events and their effects are analyzed to produce security recommendations.

Claims (38)

1. A system for cybersecurity threat mitigation using cyberphysical graphs and state changes, the system comprising:

a computing device comprising a memory and a processor;

a time series data store comprising a first plurality of programming instructions stored in the memory and operating on the processor, wherein the first plurality of programming instructions, when operating on the processor, cause the computing device to:

monitor a plurality of network events on a network;

produce time-series data comprising at least a record of a network event and the time at which the network event occurred;

an observation and state estimation module comprising a second plurality of programming instructions stored in the memory and operating on the processor, wherein the second plurality of programming instructions, when operating on the processor, cause the computing device to:

monitor a plurality of connected resources on the network;

periodically store state changes in the plurality of connected changes on the network and store the state changes in the time-series data store;

produce a cyber-physical graph from the time-series data, the cyber-physical graph comprising nodes representing the plurality of connected resources and edges between the nodes representing the physical and logical relationships between the nodes, whereby the cyber-physical graph represents the physical and logical structure of the portion of the network represented by the connected resources, wherein the cyber-physical graph is periodically updated to reflect a state of the network based on the state changes stored in the time-series data store and each state of the network is stored;

operate the cyber-physical graph as a simulated network using the time-series data as a first series of simulated network events on the cyber-physical graph;

monitor the simulated network during the occurrence of a plurality of simulated cyberattacks generated by an action-outcome simulation module to identify a response of the simulated network to each of the simulated cyberattacks, each response comprising a second series of simulated network events;

where a given response to an occurrence of the plurality of simulated cyberattacks identifies a network vulnerability, send the identified network vulnerability to the action-outcome simulation module; and

the action-outcome simulation module comprising a third plurality of programming instructions stored in the memory and operating on the processor, wherein the third plurality of programming instructions, when operating on the processor, cause the computing device to:

produce a simulated cyberattack on the simulated network, the simulated cyberattack comprising a third series of simulated network events;

receive the identified network vulnerability;

compare the current state of the network with a previously stored state of the network to identify a change in the network that led to the network vulnerability; and

produce a security report which includes the identified network vulnerability and the change in the network that led to the identified network vulnerability.

2. The system of claim 1 , wherein the action-outcome simulation module further causes the computing device to calculate an impact assessment score for a connected resource represented by a node in the cyber-physical graph.

3. The system of claim 2 , wherein the action-outcome simulation module further causes the computing device to calculate an overall impact of a cyberattack, wherein the calculation is based on the impact assessment score for each connected resource affected by the simulated cyberattack.

4. The system of claim 1 , wherein the action-outcome simulation module further causes the computing device to compare relationships between connected resources against known security vulnerabilities.

5. The system of claim 4 , wherein action-outcome simulation module further causes the computing device to produce recommended security mitigations based on the comparison against known security vulnerabilities.

6. The system of claim 1 , wherein the observation and state estimation module is further configured to produce a visualization of the operation of the cyber-physical graph as a simulated network over time.

7. A method for cybersecurity threat mitigation using cyberphysical graphs and state changes, comprising the steps of:

monitoring a plurality of network events on a network;

producing time-series data comprising at least a record of a network event and the time at which the network event occurred;

monitoring a plurality of connected resources on the network;

periodically storing state changes in the plurality of connected changes on the network and store the state changes in the time-series data store;

producing a cyber-physical graph from the time-series data, the cyber-physical graph comprising nodes representing the plurality of connected resources and edges between the nodes representing the physical and logical relationships between the nodes, whereby the cyber-physical graph represents the physical and logical structure of the portion of the network represented by the connected resources, wherein the cyber-physical graph is periodically updated to reflect a state of the network based on the state changes stored in the time-series data store and each state of the network is stored;

operating the cyber-physical graph on a computing device as a simulated network using the time-series data as a first series of simulated network events on the cyber-physical graph;

producing a simulated cyberattack on the simulated network, the simulated cyberattack comprising a second series of simulated network events;

monitoring the simulated network during the occurrence of a plurality of the simulated cyberattacks to identify a response of the simulated network to each of the simulated cyberattacks, each response comprising a third series of simulated network events;

where a given response to an occurrence of the plurality of simulated cyberattacks identifies a network vulnerability, comparing the current state of the network with a previously stored state of the network to identify a change in the network that led to the network vulnerability; and

producing of security report which includes the identified network vulnerability and the change in the network that led to the identified network vulnerability.

8. The method of claim 7 , further comprising the step of calculating an impact assessment score for a connected resource represented by a node in the cyber-physical graph.

9. The method of claim 8 , further comprising the step of calculating an overall impact of a cyberattack, wherein the calculation is based on the impact assessment score for each connected resource affected by the simulated cyberattack.

10. The method of claim 7 , further comprising the step of comparing relationships between connected resources against known security vulnerabilities.

11. The method of claim 10 , further comprising the step of producing recommended security mitigations based on the comparison against known security vulnerabilities.

12. The method of claim 7 , further comprising the step of producing a visualization of the operation of the cyber-physical graph as a simulated network over time.

Assignments (9)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TITLE IN THE ASSIGNMENT DOCUMENT PREVIOUSLY RECORDED AT REEL: 053428 FRAME: 0558. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Jul 28, 2023
From: CRABTREE, JASON; SELLERS, ANDREW
To: FRACTAL INDUSTRIES, INC.
Reel/Frame 064427/0833 →
CHANGE OF ADDRESS Recorded Dec 29, 2022
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 062251/0629 →
CHANGE OF ADDRESS Recorded Oct 27, 2020
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 054298/0094 →
CHANGE OF NAME Recorded Aug 23, 2020
From: FRACTAL INDUSTRIES, INC.
To: QOMPLX, INC.
Reel/Frame 053569/0516 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2020
From: CRABTREE, JASON; SELLERS, ANDREW
To: FRACTAL INDUSTRIES, INC.
Reel/Frame 053428/0558 →
Continuity (12)
Continuation 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Related Publication 20210092150A1 · Mar 25, 2021
Cited By (1)
US 12,412,141