IP Library Granted Patent US 11,503,066
Granted Patent B2
US 11,503,066 · App. 17/105,025 · Granted Nov 15, 2022

Holistic computer system cybersecurity evaluation and scoring

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX, INC.
H04L63/1433G06F16/2379G06F16/24578
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,503,066
App. No.
17/105,025
Granted
Nov 15, 2022
Kind
B2
Abstract

A system and method for holistic computer system cybersecurity evaluation and risk rating that takes into account the operation of the entire computer system environment comprising hardware, software, and the operating system. Not only are the hardware, software, and operating system evaluated separately for cybersecurity concerns, their interaction and operation as a whole are also evaluated and scored. The results of such analyses may be used, for example, by underwriters of cybersecurity insurance policies to determine policy terms and rates.

Claims (69)

1. A system for holistic computer system cybersecurity evaluation and rating, comprising:

a first computing device comprising a memory and a processor;

a system analyzer comprising a first plurality of programming instructions stored in the memory of, and operating on the processor of, the first computing device, wherein the first plurality of programming instructions, when operating on the processor, causes the first computing device to:

receive a system definition comprising:

a software definition comprising executable binary code for an application;

a hardware definition comprising a specification for a second computing device; and

an operating system definition for the second computing device, the operating system definition comprising executable binary code for an operating system;

identify a software function defined by the software definition and compare the function to a database of software functions to establish a software cybersecurity score;

identify a hardware component defined by the hardware definition and compare the component to a database of components to establish a hardware cybersecurity score; and

identify an operating system function defined by the operating system definition and compare the function to a database of operating system functions to establish an operating system cybersecurity score;

a scoring engine comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the first computing device, wherein the second plurality of programming instructions, when operating on the processor, cause the first computing device to:

generate a cybersecurity score for the second computing device based on a combination of the software cybersecurity score, the hardware cybersecurity score, and the operating system cybersecurity score; and

update the cybersecurity score with an updated hardware cybersecurity score from a hardware emulator; and

the hardware emulator comprising a third plurality of programming instructions stored in the memory of, and operating on the processor of, the first computing device, wherein the third plurality of programming instructions, when operating on the processor, cause the first computing device to:

emulate functioning of the second computing device on the first computing device by:

executing a set of functions that emulate the operation of the second computing device as defined by the hardware definition;

receiving and installing the operating system on the emulated second computing device;

receiving and installing the application on the emulated second computing device; and

executing the application on the emulated second computing device using the operating system; and

analyze the functioning of the second computing device by executing an attack on the emulated second computing device associated with a known hardware exploit to:

determine whether the emulated second computing device is susceptible to the known hardware exploit;

update the hardware cybersecurity score using the determination; and

send the updated hardware cybersecurity score to the scoring engine.

2. The system of claim 1 , wherein the software definition is accompanied by source code for the application and the software cybersecurity score further comprises an analysis of the coding complexity of the source code.

3. The system of claim 1 , wherein the cybersecurity score is adjusted to reflect a domain in which the computer system will be used.

4. The system of claim 1 , wherein the cybersecurity score is adjusted to reflect a use to which the computer system will be put.

5. The system of claim 1 , wherein the cybersecurity score is adjusted to reflect a criticality of the computer system to overall operations of a business or larger network of computers.

6. The system of claim 1 , wherein the cybersecurity score is adjusted to reflect a magnitude of losses that would occur if the system was compromised.

7. A method for holistic computer system cybersecurity evaluation and rating, comprising the steps of:

receiving a system definition comprising:

a software definition comprising executable binary code for an application;

a hardware definition comprising a specification for a second computing device; and

an operating system definition for the second computing device, the operating system definition comprising executable binary code for an operating system;

identifying a software function defined by the software definition and compare the function to a database of software functions to establish a software cybersecurity score;

identifying a hardware component defined by the hardware definition and compare the component to a database of components to establish a hardware cybersecurity score;

identifying an operating system function defined by the operating system definition and compare the function to a database of operating system functions to establish an operating system cybersecurity score; and

generating a cybersecurity score for the second computing device based on a combination of the software cybersecurity score, the hardware cybersecurity score, and the operating system cybersecurity score;

emulating functioning of the second computing device on a first computing device by:

executing a set of functions that emulate the operation of the second computing device as defined by the hardware definition;

receiving and installing the operating system on the emulated second computing device;

receiving and installing the application on the emulated second computing device; and

executing the application on the emulated second computing device using the operating system; and

analyzing the functioning of the second computing device by executing an attack on the emulated second computing device associated with a known hardware exploit to:

determine whether the emulated second computing device is susceptible to the exploit;

update the hardware cybersecurity score using the determination; and

update the cybersecurity score using the updated hardware cybersecurity score.

8. The method of claim 7 , wherein the software definition is accompanied by source code for the application and the software cybersecurity score further comprises an analysis of the coding complexity of the source code.

9. The method of claim 7 , further comprising the step of adjusting the cybersecurity score to reflect a domain in which the computer system will be used.

10. The method of claim 7 , further comprising the step of adjusting the cybersecurity score to reflect a use to which the computer system will be put.

11. The method of claim 7 , further comprising the step of adjusting the cybersecurity score to reflect a criticality of the computer system to overall operations of a business or larger network of computers.

12. The method of claim 7 , further comprising the step of adjusting the cybersecurity to reflect a magnitude of losses that would occur if the system was compromised.

13. A method for holistic computer system cybersecurity rating, comprising the steps of:

generating a cybersecurity score for a computing device by combining separate analyses of:

a software function of a software component comprising executable binary code for an application;

a hardware component comprising a specification for a second computing device; and

an operating system function of an operating system component of a computer system comprising executable binary code for an operating system;

emulating functioning of the second computing device on a first computing device by:

executing a set of functions that emulate the operation of the second computing device as defined by the hardware definition;

receiving and installing the operating system on the emulated second computing device;

receiving and installing the application on the emulated second computing device; and

executing the application on the emulated second computing device using the operating system;

analyzing the functioning of the second computing device by executing an attack on the emulated second computing device associated with a known hardware exploit to:

determine whether the emulated second computing device is susceptible to the exploit; and

update the hardware cybersecurity score using the determination; and

update the cybersecurity score using the updated hardware cybersecurity score;

adjusting the cybersecurity score to reflect a domain in which the computer system will be used;

adjusting the cybersecurity score to reflect a use to which the computer system will be put;

adjusting the cybersecurity score to reflect a criticality of the computer system to overall operations of a business or larger network of computers; and

adjusting the cybersecurity score to reflect a magnitude of losses that would occur if the system was compromised.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
CHANGE OF ADDRESS Recorded Dec 29, 2022
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 062251/0629 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2022
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 061174/0174 →
Continuity (22)
Continuation 16836717 · Mar 31, 2020
Continuation In Part 15887496 · Feb 2, 2018
Continuation In Part 15823285 · Nov 27, 2017
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15788718 · Oct 19, 2017
Continuation In Part 15788002 · Oct 19, 2017
Continuation In Part 15787601 · Oct 18, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62568307 · Oct 4, 2017
Provisional Application 62568312 · Oct 4, 2017
Provisional Application 62568305 · Oct 4, 2017
Related Publication 20210281598A1 · Sep 9, 2021