IP Library Granted Patent US 12,537,855
Granted Patent B2
US 12,537,855 · App. 17/205,853 · Granted Jan 27, 2026

Enhanced cybersecurity using an automated planning service

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/20G06F16/2477G06F16/951H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,537,855
App. No.
17/205,853
Granted
Jan 27, 2026
Kind
B2
Abstract

A system and methods for enhanced cybersecurity using an automated planning service is provided, comprising an automated planning service that receives a network analysis job, constructs a simulation using known network and threat information, assigns individual actions to worker nodes for processing, analyzes the results and records new threat mitigation plans as they are produced to expedite future operations, and produces an action plan as output.

Claims (43)

1 . A system for enhanced cybersecurity using an automated planning service, comprising:

an automated planning service comprising a memory, a processor, and a plurality of programming instructions stored in the memory thereof and operable on the processor thereof, wherein the programmable instructions, when operating on the processor, cause the processor to:

operate a plurality of master computing nodes, each master computing node in turn operating a plurality of worker computing nodes;

receive a network analysis job at a first master computing node;

receive, from a distributed computational graph, a plurality of security parameters and threat definitions, wherein the plurality of security parameters and threat definitions are based, at least in part, on streaming data processed by the distributed computational graph;

identify a security threat based on the network analysis job and the plurality of security parameters and threat definitions;

determine a desired network end state, wherein the desired network end state is based on the network analysis job and the plurality of security parameters and threat definitions;

assign, using the first master computing node, a plurality of actions to a plurality of worker computing nodes, wherein each of the plurality of actions is based on the identified security threat, the network analysis job, and the desired network end state, wherein each of the plurality of worker computing nodes is assigned exactly one of the plurality of actions at any given time during operation;

receive, at the first master computing node, results of the plurality of actions from the plurality of worker computing nodes as the actions are completed;

analyze, using the first master computing node, the received results to determine which of the actions have brought a current network state closer to the desired network end state;

iteratively instruct, using the first master computing node, at least one of the worker computing nodes to perform at least one additional action, wherein the at least one additional action performed by the at least one worker computing node is based on the analysis of the received results;

when the desired network end state is reached, generate a threat mitigation plan for the identified security threat comprising a record of the actions that led to the desired network end state and the order in which said actions were completed; and

provide the analyzed results and the threat mitigation plan as output.

2 . The system of claim 1 , wherein at least a portion of the plurality of security parameters and threat definitions is retrieved from a data storage.

3 . The system of claim 1 , wherein at least a portion of the plurality of security parameters and threat definitions is received via a representational state transfer (RESTful) application programming interface (API).

4 . The system of claim 1 , wherein the streaming data processed by the distributed computational graph originates from a plurality of sensors and electronic infrastructure monitors associated with the system.

5 . The system of claim 1 , wherein the plurality of security parameters and threat definitions are updated in near real-time based on the streaming data.

6 . The system of claim 1 , wherein the network analysis job is updated in near real-time based on the streaming data.

7 . The system of claim 1 , wherein each worker computing node operates independently from each other worker computing node in an asynchronous “eventual agreement” model.

8 . The system of claim 1 , wherein the distributed computational graph comprises a plurality of transformation pipelines arranged as a directed graph of transformation nodes and messages.

9 . The system of claim 8 , wherein the distributed computational graph is configured via representational state transfer (RESTful) application programming interface (API) endpoints to start, stop, and update pipelines without halting other pipelines.

10 . The system of claim 8 , wherein one or more of the plurality of transformation pipelines of the distributed computational graph is updated in near-real-time based on the streaming data.

11 . A method for enhanced cybersecurity using an automated planning service, comprising the steps of:

operating, at an automated planning service, a plurality of master computing nodes, each master computing node in turn operating a plurality of worker computing nodes;

receiving a network analysis job at a first master computing node;

receiving, from a distributed computational graph, a plurality of security parameters and threat definitions, wherein the plurality of security parameters and threat definitions are based, at least in part, on streaming data processed by the distributed computational graph;

identifying a security threat based on the network analysis job and the plurality of security parameters and threat definitions;

determining a desired network end state, wherein the desired network end state is based on the network analysis job and the plurality of security parameters and threat definitions;

assigning, using the first master computing node, a plurality of actions to a plurality of worker computing nodes, wherein each of the plurality of actions is based on the identified security threat, the network analysis job, and the desired network end state, wherein each of the plurality of worker computing nodes is assigned exactly one of the plurality of actions at any given time during operation;

receiving, at the first master computing node, results of the plurality of actions from the plurality of worker computing nodes as the actions are completed;

analyzing, using the first master computing node, the received results to determine which of the actions have brought a current network state closer to the desired network end state;

iteratively instructing, using the first master computing node, at least one of the worker computing nodes to perform at least one additional action, wherein the at least one additional action performed by the at least one worker computing node is based on the analysis of the received results;

when the desired network end state is reached, generating a threat mitigation plan for the identified security threat comprising a record of the actions that led to the desired network end state and the order in which said actions were completed; and

providing the analyzed results and the threat mitigation plan as output.

12 . The method of claim 11 , wherein at least a portion of the plurality of security parameters and threat definitions are is retrieved from a data storage.

13 . The method of claim 11 , wherein at least a portion of the plurality of security parameters and threat definitions is received via a representational state transfer (RESTful) application programming interface (API).

14 . The method of claim 11 , wherein the streaming data processed by the distributed computational graph originates from a plurality of sensors and electronic infrastructure monitors associated with the system.

15 . The method of claim 11 , wherein the plurality of security parameters and threat definitions are updated in near real-time based on the streaming data.

16 . The method of claim 11 , wherein the network analysis job is updated in near real-time based on the streaming data.

17 . The method of claim 11 , wherein each worker computing node operates independently from each other worker computing node in an asynchronous “eventual agreement” model.

18 . The method of claim 11 , wherein the distributed computational graph comprises a plurality of transformation pipelines arranged as a directed graph of transformation nodes and messages.

19 . The method of claim 18 , wherein the distributed computational graph is configured via representational state transfer (RESTful) application programming interface (API) endpoints to start, stop, and update pipelines without halting other pipelines.

20 . The method of claim 18 , wherein one or more of the plurality of transformation pipelines of the distributed computational graph is updated in near-real-time based on the streaming data.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2023
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 064411/0735 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2021
From: SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 056123/0503 →
Continuity (63)
Continuation In Part 17189161 · Mar 1, 2021
Continuation In Part 17061195 · Oct 1, 2020
Continuation In Part 17035029 · Sep 28, 2020
Continuation In Part 17008276 · Aug 31, 2020
Continuation In Part 17000504 · Aug 24, 2020
Continuation In Part 16855724 · Apr 22, 2020
Continuation In Part 16836717 · Mar 31, 2020
Continuation In Part 15887496 · Feb 2, 2018
Continuation In Part 15823285 · Nov 27, 2017
Continuation In Part 15788718 · Oct 19, 2017
Continuation In Part 15788002 · Oct 19, 2017
Continuation In Part 15787601 · Oct 18, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 16412340 · May 14, 2019
Continuation In Part 16267893 · Feb 5, 2019
Continuation In Part 16248133 · Jan 15, 2019
Continuation In Part 15849901 · Dec 21, 2017
Continuation In Part 15835436 · Dec 7, 2017
Continuation In Part 15790457 · Oct 23, 2017
Continuation In Part 15790327 · Oct 23, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15835312 · Dec 7, 2017
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15813097 · Nov 14, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15806697 · Nov 8, 2017
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15343209 · Nov 4, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15229476 · Aug 5, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15673368 · Aug 9, 2017
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 15879801 · Jan 25, 2018
Continuation In Part 15379899 · Dec 15, 2016
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 16709598 · Dec 10, 2019
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62568312 · Oct 4, 2017
Provisional Application 62568305 · Oct 4, 2017
Provisional Application 62568307 · Oct 4, 2017
Provisional Application 62568291 · Oct 4, 2017
Provisional Application 62568298 · Oct 4, 2017
Related Publication 20220006837A1 · Jan 6, 2022
References Cited (36)
US 7818224B2 · Boerner · 2010 [cited by applicant]
US 7818417B2 · Ginis et al. · 2010 [cited by applicant]
US 7840677B2 · Li et al. · 2010 [cited by applicant]
US 8069190B2 · Mccoll et al. · 2011 [cited by applicant]
US 8156029B2 · Szydlo · 2012 [cited by applicant]
US 8352347B2 · Howard et al. · 2013 [cited by applicant]
US 8370192B2 · Deo et al. · 2013 [cited by applicant]
US 9338061B2 · Chen et al. · 2016 [cited by applicant]
US 9461876B2 · Van Dusen et al. · 2016 [cited by applicant]
US 9639575B2 · Leida et al. · 2017 [cited by applicant]
US 9721086B2 · Shear et al. · 2017 [cited by applicant]
US 10168691B2 · Zornio et al. · 2019 [cited by applicant]
US 10740358B2 · Chan et al. · 2020 [cited by applicant]
US 11038926B2 · Sharma · 2021 [cited by examiner]
US 20050209993A1 · Koehler · 2005 [cited by applicant]
US 20050210008A1 · Tran · 2005 [cited by examiner]
US 20070168370A1 · Hardy · 2007 [cited by applicant]
US 20070174233A1 · Ginis et al. · 2007 [cited by applicant]
US 20090171999A1 · Mccoll et al. · 2009 [cited by applicant]
US 20090235251A1 · Li et al. · 2009 [cited by applicant]
US 20130262443A1 · Leida et al. · 2013 [cited by applicant]
US 20130290554A1 · Chen et al. · 2013 [cited by applicant]
US 20150254330A1 · Chan et al. · 2015 [cited by applicant]
US 20160092557A1 · Stojanovic et al. · 2016 [cited by applicant]
US 20160098037A1 · Zorino et al. · 2016 [cited by applicant]
US 20160358102A1 · Bowers · 2016 [cited by applicant]
US 20160373448A1 · Keene · 2016 [cited by examiner]
US 20170006135A1 · Siebel et al. · 2017 [cited by applicant]
US 20170090893A1 · Aditya et al. · 2017 [cited by applicant]
US 20190155646A1 · Bishop et al. · 2019 [cited by applicant]
US 20200293523A1 · Eike · 2020 [cited by examiner]
US 20200351157A1 · Patterson · 2020 [cited by examiner]
US 20210092134A1 · Ludwig · 2021 [cited by examiner]
WO 0163534A2 · 2001 [cited by applicant]
WO 2015094545A1 · 2015 [cited by applicant]
“Conflict-based search for optimal multi-agent pathfinding” Sharon et al., pp. 40-66. (Year: 2014). [cited by examiner]