IP Library Patent Application 17567064
Patent Application
App. No. 17/567,064

ADVANCED CYBERSECURITY THREAT MITIGATION USING SOFTWARE SUPPLY CHAIN ANALYSIS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/567,064
Abstract

A system and method for determining privilege escalation attack pathways by performing a comprehensive cybersecurity threat assessment of software applications based on the totality of vulnerabilities from all levels of the software supply chain to determine attack paths for a privilege escalation attack. The system and method comprising analyzing the code and/or operation of a software application to determine components comprising the software, identifying the source of such components, determining vulnerabilities associated with those components, compiling a list of such components, creating a directed graph of relationships between the components, their sources, and new exploitation pathways, and evaluating the overall threat associated with the software application based its software vulnerabilities.

Claims (33)

1 . A system for determining privilege escalation attack pathways, comprising:

a computing device comprising a memory and a processor;

a cyber-physical graph engine comprising a first plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the first plurality of programming instructions, when operating on the processor, cause the computing device to:

search one or more databases to identify information about one or more vulnerabilities of each software application residing on the computing device;

wherein the information comprises the level of privilege needed to execute the one or more vulnerabilities, and new vulnerabilities and privilege levels made possible by the successful execution of the one or more vulnerabilities; and

construct a cyber-physical graph of privilege escalation attack pathways, the cyber-physical graph comprising nodes representing each software application and its vulnerability information, and edges representing the relationships between the nodes; and

a scoring engine comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programming instructions, when operating on the processor, cause the computing device to:

run one or more graph-processing algorithms on the cyber-physical graph to identify one or more privilege escalation attack pathways and a probability of occurrence for each path; and

generate a cybersecurity score for each privilege escalation attack pathway based on the probability of occurrence for each path.

2 . The system of claim 1 , wherein privilege levels are access levels of a network.

3 . The system of claim 1 , wherein privilege levels are access levels of an operating system.

4 . The system of claim 1 , wherein privilege levels are access levels of a processor architecture.

5 . The system of claim 1 , wherein privilege levels are access levels in a domain.

6 . The system of claim 1 , wherein the edges are weighted, directional, length contracted, or some combination thereof to represent aspects of the vulnerability information.

7 . The system of claim 1 , wherein the cybersecurity score accounts for financial risk associated with each privilege escalation attack pathway.

8 . The system of claim 1 , wherein the cybersecurity score accounts for directory services configurations.

9 . The system of claim 1 , wherein the cybersecurity score accounts for cybersecurity scores of other network-connected computing devices.

10 . The system of claim 1 , wherein a network-wide cyber-physical graph is created from a plurality of individual computing device cyber-physical graphs.

11 . A method for determining privilege escalation attack pathways, comprising the steps of:

searching one or more databases to identify information about one or more vulnerabilities of each software application residing on a computing device;

wherein the information comprises the level of privilege needed to execute the one or more vulnerabilities, and new vulnerabilities and privilege levels made possible by the successful execution of the one or more vulnerabilities;

constructing a cyber-physical graph of privilege escalation attack pathways, the cyber-physical graph comprising nodes representing each software application and its vulnerability information, and edges representing the relationships between the nodes;

running one or more graph-processing algorithms on the cyber-physical graph to identify one or more privilege escalation attack pathways and a probability of occurrence for each path; and

generating a cybersecurity score for each privilege escalation attack pathway based on the probability of occurrence for each path.

12 . The method of claim 11 , wherein privilege levels are access levels of a network.

13 . The method of claim 11 , wherein privilege levels are access levels of an operating system.

14 . The method of claim 11 , wherein privilege levels are access levels of a processor architecture.

15 . The method of claim 11 , wherein privilege levels are access levels in a domain.

16 . The method of claim 11 , wherein the edges are weighted, directional, length contracted, or some combination thereof to represent aspects of the vulnerability information.

17 . The method of claim 11 , wherein the cybersecurity score accounts for financial risk associated with each privilege escalation attack pathway.

18 . The method of claim 11 , wherein the cybersecurity score accounts for directory services configurations.

19 . The method of claim 11 , wherein the cybersecurity score accounts for cybersecurity scores of other network-connected computing devices.

20 . The method of claim 11 , wherein a network-wide cyber-physical graph is created from a plurality of individual computing device cyber-physical graphs.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2022
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 059864/0743 →