IP Library Granted Patent US 12,003,544
Granted Patent B2
US 12,003,544 · App. 17/392,250 · Granted Jun 4, 2024

System and methods for automatically assessing and improving a cybersecurity risk score

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/20G06F16/2477G06F16/951H04L63/1425H04L63/1441H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,003,544
App. No.
17/392,250
Granted
Jun 4, 2024
Kind
B2
Abstract

A system and method for automatically assessing and improving a cybersecurity risk score, wherein a cybersecurity risk score and cyber-physical graph for a network are retrieved and analyzed to identify potential improvements that can be made to network topography and device configurations, changes are applied automatically and an updated cyber-physical graph reflecting the applied changes is produced, and the updated cyber-physical graph is reassessed to determine the effect of the changes that were applied.

Claims (25)

1. A system for automatically assessing and improving a cybersecurity risk score, comprising:

a computing system comprising a memory, a processor, and a network interface;

a cybersecurity scoring subsystem comprising a first plurality of programming instructions that, when operating on the processor, cause the computing system to:

retrieve a cyber-physical graph for a network;

retrieve a cybersecurity profile for the network based on external reconnaissance of the network by a reconnaissance subsystem;

determine a cybersecurity risk score for the network based on the cybersecurity profile and the cyber-physical graph of the network;

provide the cybersecurity risk score and the cyber-physical graph to a directed computational graph subsystem;

upon changes occurring at one or more of a plurality of target devices, determine a new cybersecurity risk score and provide it to the directed computation graph subsystem;

the directed computational graph subsystem comprising a second plurality of programming instructions that, cause the computing device system to:

analyze the cyber-physical graph and the cybersecurity risk score; and

when the cybersecurity risk score falls below a threshold:

identify a plurality of changes that can be applied to each of the plurality of target devices within the network, the identified plurality of changes being based on results of the analysis;

transmit instructions to the plurality of target devices, wherein upon receipt of the instructions each of the plurality of target devices automatically applies at least one of the identified plurality of changes; and

update the cyber-physical graph based on the applied changes.

2. A method for automatically assessing and improving a cybersecurity risk score, comprising the steps of:

retrieving a cyber-physical graph for the network;

retrieving a cybersecurity profile for the network based on external reconnaissance of the network by a reconnaissance subsystem;

determining a cybersecurity risk score for the network based on the cybersecurity profile and the cyber-physical graph of the network;

providing the cybersecurity risk score and the cyber-physical graph to a directed computational graph subsystem of a computing system;

upon changes occurring at one or more of a plurality of target devices, determining a new cybersecurity risk score;

analyzing, using the directed computational graph subsystem, the cyber-physical graph and the cybersecurity risk score; and

when the cybersecurity risk score falls below a threshold:

identifying a plurality of changes that can be applied to each of the plurality of target devices within the network, the identified plurality of changes being based on results of the analysis;

transmitting instructions to the plurality of target devices, wherein upon receipt of the instructions each of the plurality of target devices automatically applies at least one of the identified plurality of changes; and

updating the cyber-physical graph based on the applied changes.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2022
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 059886/0920 →
Cited By (1)
US 12,341,803