IP Library Granted Patent US 12,015,596
Granted Patent B2
US 12,015,596 · App. 17/140,092 · Granted Jun 18, 2024

Risk analysis using port scanning for multi-factor authentication

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/0428G06F16/951G06N7/01H04L9/14H04L9/3236H04L9/3297H04L63/061H04L63/08H04L63/1408H04L63/1433G06N5/01G06N5/045G06N5/046G06N20/00H04L9/50H04L63/0442H04L63/123H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,015,596
App. No.
17/140,092
Granted
Jun 18, 2024
Kind
B2
Abstract

A system for risk analysis using port scanning for multi-factor authentication having a multi-dimensional time series data server configured to monitor and record a network's traffic data and to serve the traffic data to other modules and a directed computational graph module configured to scan open ports on connection destinations, analyze the scan results, and determine a verification score needed before granting access based at least in part on the analysis of the received responses. A plurality of verification methods build up a user's verification score to required level to gain access.

Claims (32)

1. A system for risk analysis using port scanning for multi-factor authentication, comprising:

a multi-dimensional time series data server comprising a memory, a processor, and a plurality of programming instructions stored in the memory thereof and operable on the processor thereof, wherein the programmable instructions, when operating on the processor, cause the processor to:

monitor and store a network's traffic data; and

serve traffic data to other modules; and

a directed computational graph module comprising a memory, a processor, and a plurality of programming instructions stored in the memory thereof and operable on the processor thereof, wherein the programmable instructions, when operating on the processor, cause the processor to:

receive traffic data from the multi-dimensional time series data server;

identify a connection attempt from a user device to a destination device with unknown risk potential;

scan a plurality of network ports at the destination device;

analyze the scan results to determine at least a plurality of open ports at the destination device and a plurality of closed ports at the destination device; and

determine a required verification score for granting access to a network resource based at least in part on the open and closed ports on the destination device;

wherein a plurality of verification methods is used to build up a user's verification score to the required verification score in order for the user to gain access to the destination device.

2. The system of claim 1 , wherein the verification score is based at least in part on stored knowledge of the user.

3. The system of claim 2 , wherein the stored knowledge of the user comprises at least knowledge of user access privileges to resources on the local network.

4. The system of claim 1 , wherein at least a portion of the verification methods verifies visual media pertaining to the user.

5. The system of claim 1 , wherein at least a portion of the verification methods checks and verifies biometric features of the user.

6. The system of claim 1 , wherein at least a portion of the verification methods used are based on information obtained from untrusted parties.

7. The system of claim 1 , wherein at least a portion of the verification methods used are based on information pertaining to the user device.

8. A method for risk analysis using port scanning for multi-factor authentication, comprising the steps of:

(a) using a computing device with a processor and a memory, monitoring and recording a network's traffic data for the purpose of providing a stateful, evolving baseline of authentication patterns, with a multi-dimensional time series data server;

(b) serving the traffic data to other modules, with the multi-dimensional time series data server;

(c) receiving the traffic data from the multi-dimensional time series data server, at a directed computation graph module;

(d) identifying a connection attempt from a user device to a destination device with unknown risk potential;

(e) scanning a plurality of network ports at the destination device;

(f) analyzing the scan results to determine at least a plurality of open ports at the destination device and a plurality of closed ports at the destination device; and

(g) determining a required verification score for granting access to a network resource based at least in part on the open and closed ports on the destination device; and

(h) requiring user of the user device to use a plurality of verification methods to earn enough verification score in order to gain access to the destination device.

9. The method of claim 8 , wherein the verification score is based at least in part on stored knowledge of the user.

10. The method of claim 9 , wherein the stored knowledge of the user comprises at least knowledge of user access privileges to resources on the local network.

11. The method of claim 8 , wherein at least a portion of the verification methods verifies visual media pertaining to the user.

12. The method of claim 8 , wherein at least a portion of the verification methods checks and verifies biometric features of the user.

13. The method of claim 8 , wherein at least a portion of the verification methods used are based on information obtained from untrusted parties.

14. The method of claim 8 , wherein at least a portion of the verification methods used are based on information pertaining to the user device.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2021
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 054820/0081 →
Continuity (22)
Continuation In Part 16910623 · Jun 24, 2020
Continuation In Part 15930063 · May 12, 2020
Continuation 15904006 · Feb 23, 2018
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 13, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 17138202 · Dec 30, 2020
Continuation In Part 16856827 · Apr 23, 2020
Continuation 15790860 · Oct 23, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Provisional Application 62574708 · Oct 19, 2017
Related Publication 20210226928A1 · Jul 22, 2021