IP Library Granted Patent US 12,041,091
Granted Patent B2
US 12,041,091 · App. 17/245,964 · Granted Jul 16, 2024

System and methods for automated internet- scale web application vulnerability scanning and enhanced security profiling

Inventors: Alejandro Caceres (Davie, FL); Tomas Fornara (Berlin, DE); Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/20G06F16/2477G06F16/951H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,041,091
App. No.
17/245,964
Granted
Jul 16, 2024
Kind
B2
Abstract

A system and methods for automated Internet-scale vulnerability scanning and enhanced security profiling. The system utilizes a scheduler that directs web crawlers to scan domains retrieved from a database, interact with the contents of any retrieved web pages using fuzz testing, index and store the results of the scan, and provide the indexed results via an API for inclusion in cybersecurity scoring.

Claims (41)

1. A system for automated Internet-scale vulnerability scanning and enhanced security profiling, comprising:

a cyber-physical graph module comprising a first plurality of programming instructions stored in a memory of, and operating on a processor of, a computing device, wherein the first plurality of programming instructions, when operating on the processor, cause the computing device to create a cyber-physical graph of an organization using information, the cyber-physical graph comprising nodes representing entities associated with the organization and edges representing relationships between the entities associated with the organization;

a reconnaissance engine comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programming instructions, when operating on the processor, cause the computing device to:

perform a reconnaissance search using the cyber-physical graph; and

apply some or all of the results of the reconnaissance search to the cyber-physical graph to create a cybersecurity profile of the organization; and

a scheduler comprising a third plurality of programming instructions stored in a memory of, and operating on a processor of, a computing device, wherein the third plurality of programming instructions, when operating on the processor, cause the computing device to:

store and maintain a schedule; and

operate a plurality of web crawlers based on the stored schedule, wherein a web crawler:

retrieves a plurality of domains from a database, the plurality of domains being associated with the organization;

requests a web page associated with at least one of the retrieved domains;

receives a response to the request from a web server;

provides input to an interactive element of the web page;

receives a result from the web server, the result being based on the provided input;

indexes the result; and

store the indexed results from the plurality of web crawlers; and

a scoring engine comprising a fourth plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the fourth plurality of programming instructions, when operating on the processor, cause the computing device to:

receive the cybersecurity profile and the reconnaissance search results;

retrieve the indexed results;

using the cyber-physical graph and the indexed results:

identify a plurality of cybersecurity risks associated with the organization, the cybersecurity risks being based on the indexed results;

determine a business impact for each cybersecurity risk identified;

assign a network resilience rating to the organization; and

determine a functional cybersecurity score for the organization based at least on the network resilience rating.

2. The system of claim 1 , wherein the input is generated by a fuzzer.

3. A method for automated Internet-scale vulnerability scanning and enhanced security profiling, comprising the steps of:

creating a cyber-physical graph of an organization using entities associated with the organization and relationships between the entities associated with the organization, the cyber-physical graph comprising nodes representing the entities associated with the organization and edges representing the relationships between the entities associated with the organization;

performing a reconnaissance search using the cyber-physical graph;

applying some or all of the results of the reconnaissance search to the cyber-physical graph to create a cybersecurity profile of the organization;

storing and maintaining a schedule; and

operating a plurality of web crawlers based on the stored schedule, wherein a web crawler:

retrieves a plurality of domains from a database, the plurality of domains being associated with the organization;

requests a web page associated with at least one of the retrieved domains;

receives a response to the request from a web server; provides input to an interactive element of the web page;

receives a result from the web server, the result being based on the provided input; indexes the result; and

storing the indexed results from the plurality of web crawlers; and

using the cyber-physical graph and the indexed results:

identify a plurality of cybersecurity risks associated with the organization, the cybersecurity risks being based on the indexed results;

determine a business impact for each cybersecurity risk identified;

assign a network resilience rating to the organization; and

determine a functional cybersecurity score for the organization based at least on the network resilience rating.

4. The method of claim 3 , wherein the input is generated by a fuzzer.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: CACERES, ALEJANDRO; FORNARA, TOMAS; CRABTREE, JASON; KELLEY, RICHARD; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 064120/0200 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2021
From: SELLERS, ANDREW; CRABTREE, JASON; CACERES, ALEJANDRO; FORNARA, TOMAS; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 057355/0837 →
Continuity (17)
Continuation In Part 17216939 · Mar 30, 2021
Continuation 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Related Publication 20220014561A1 · Jan 13, 2022
Cited By (1)
US 12,348,535