IP Library Granted Patent US 12,058,177
Granted Patent B2
US 12,058,177 · App. 17/220,150 · Granted Aug 6, 2024

Cybersecurity risk analysis and anomaly detection using active and passive external reconnaissance

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
H04L63/20G06F16/2477G06F16/951H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,058,177
App. No.
17/220,150
Granted
Aug 6, 2024
Kind
B2
Abstract

A system and method for cybersecurity risk analysis and anomaly detection using active and passive external reconnaissance, that identifies critical network entities within a cyber-physical graph, identifies anomalous events within the network, determines the risk of identified anomalies based on the value of the entities involved, and determines an effectiveness score for the network based on the identified risks.

Claims (27)

1. A system for cybersecurity profiling and rating using internal and external reconnaissance, comprising:

a cyber-physical graph module comprising a first plurality of programming instructions stored in a memory of, and operating on a processor of, a computing device, wherein the first plurality of programming instructions, when operating on the processor, cause the computing device to create a cyber-physical graph of an organization using information about the organization, the cyber-physical graph comprising nodes representing entities associated with the organization and edges representing relationships between entities associated with the organization;

a reconnaissance engine comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programming instructions, when operating on the processor, cause the computing device to:

perform a reconnaissance search using the cyber-physical graph; and

apply a plurality of results of the reconnaissance search to the cyber-physical graph to create a cybersecurity profile of the organization; and

a scoring engine comprising a third plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the third plurality of programming instructions, when operating on the processor, cause the computing device to:

receive the cybersecurity profile and the reconnaissance search results;

using the cyber-physical graph and the reconnaissance search results:

assign a criticality score to each of a plurality of nodes within the cyber-physical graph, the criticality score indicating a measure of importance of the respective entity represented by a node;

identify a plurality of cybersecurity risks associated with each of the nodes to which a relative value was assigned;

identify an anomalous event based on analysis of cyber-physical graph and the reconnaissance search results;

assign a risk value to the identified anomalous event, the risk value being determined based on the assigned criticality score for a node associated with the anomalous event; and

determine an effectiveness score for the network based on the cyber-physical graph and the risk value.

2. The system of claim 1 , wherein the information about the organization further comprises information about business processes within the organization.

3. The system of claim 1 , wherein the information about the organization further comprises prior loss information for the organization.

4. A method for cybersecurity profiling and rating using internal and external reconnaissance, comprising the steps of:

creating a cyber-physical graph of an organization using entities associated with the organization and relationships between the entities associated with the organization, the cyber-physical graph comprising nodes representing the entities associated with the organization and edges representing the relationships between entities associated with the organization;

performing a reconnaissance search using the cyber-physical graph;

applying some or all of the results of the reconnaissance search to the cyber-physical graph to create a cybersecurity profile of the organization; and

using the cyber-physical graph and the reconnaissance search results:

assigning a criticality score to each of a plurality of nodes within the cyber-physical graph, the criticality score indicating a measure of importance of the respective entity represented by a node;

identifying a plurality of cybersecurity risks associated with each of the nodes to which a relative value was assigned;

identifying an anomalous event based on analysis of cyber-physical graph and the reconnaissance search results;

assigning a risk value to the identified anomalous event, the risk value being determined based on the assigned criticality score for a node associated with the anomalous event; and

determining an effectiveness score for the network based on the cyber-physical graph and the risk value.

5. The method of claim 4 wherein the information about the organization further comprises information about business processes within the organization.

6. The method of claim 4 wherein the information about the organization further comprises prior loss information for the organization.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2022
From: CRABTREE, JASON; SELLERS, ANDREW; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 059740/0461 →