IP Library Granted Patent US 12,284,177
Granted Patent B2
US 12,284,177 · App. 17/567,069 · Granted Apr 22, 2025

Event-triggered reauthentication of at-risk and compromised systems and accounts

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/0861H04L43/04H04L63/083H04L63/0876H04L63/105H04L63/1433H04L63/1408H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,284,177
App. No.
17/567,069
Granted
Apr 22, 2025
Kind
B2
Abstract

A system and method that detects and mitigates zero-day exploits and other vulnerabilities by analyzing event logs and external databases, forcing reauthentication of at-risk and comprised systems and accounts during an identified threat or potential security risk.

Claims (40)

1. A system for event-triggered reauthentication, comprising:

a first computing system comprising a memory and a processor connected to a computer network

wherein the first computing system is configured to:

receive a plurality of system logs from a second computing system connected to the computer network;

generate a baseline usage profile of the second computing system based on the received system logs, wherein the baseline usage profile is updated based on receipt of the received system logs from the second computing system;

receive a request from the second computing system to authenticate access to a service;

in response to the received request to authenticate access to the service, determine, based on the baseline usage profile of the second computing system, whether to require additional verification from the second computing system;

retrieve a dataset of known exploit information from a plurality of databases;

identify a cybersecurity threat related to the second computing system by comparing the baseline usage profile and events within the system logs against the dataset of known exploit information; and

in response to identifying the cybersecurity threat, trigger a forced reauthentication to allow the second computing system to maintain continued access to the service.

2. The system of claim 1 , wherein the forced reauthentication is triggered regardless of the determination whether to require additional verification from the second computing system.

3. The system of claim 1 , wherein the first computing system is implemented as a cloud-based service that monitors a remote computing device using a software agent and enforces authentication over the computer network.

4. The system of claim 1 , wherein the first computing system is implemented as a server on an enterprise network that monitors all computing devices on the enterprise network and enforces authentication over the computer network.

5. The system of claim 1 , wherein the service is an operating system service.

6. The system of claim 1 , wherein the service is a cloud-based service.

7. The system of claim 1 , wherein the forced reauthentication uses two-factor authentication.

8. The system of claim 1 , wherein the forced reauthentication is selected from a plurality of verification methods, wherein:

each verification method is associated with a number of points;

the successful completion of a verification method awards the number of points associated with that verification method;

the total number of points available for successful completion of the plurality of verification methods is equal to or greater than the verification score; and

at least one of the verification methods is a non-automated verification method requiring a manual input.

9. A method for event-triggered reauthentication, comprising the steps of:

receiving a plurality of system logs from a computing system connected to a computer network;

generating a baseline usage profile of the computing system based on the received system logs, wherein the baseline usage profile is updated based on receipt of the received system logs from the computing system;

receiving a request from the computing system to authenticate access to a service;

in response to the received request to authenticate access to the service, determining, based on the baseline usage profile of the computing system, whether to require additional verification from the computing system;

retrieving a dataset of known exploit information from a plurality of databases;

identifying a cybersecurity threat related to the computing system by comparing the baseline usage profile and events within the system logs against the dataset of known exploit information; and

in response to identifying the cybersecurity threat, triggering a forced reauthentication to allow the computing system to maintain continued access to the service.

10. The method of claim 9 , wherein the forced reauthentication is triggered regardless of the determination whether to require additional verification from the second computing system.

11. The method of claim 9 , wherein the method is implemented as a cloud-based service that monitors a remote computing device using a software agent and enforces authentication over the computer network.

12. The method of claim 9 , wherein the method is implemented on a server on an enterprise network that monitors all computing devices on the enterprise network and enforces authentication over the computer network.

13. The method of claim 9 , wherein the service is an operating system service.

14. The method of claim 9 , wherein the service is a cloud-based service.

15. The method of claim 9 , wherein the forced reauthentication uses two-factor authentication.

16. The method of claim 9 , wherein the forced reauthentication is selected from a plurality of verification methods, wherein:

each verification method is associated with a number of points;

the successful completion of a verification method awards the number of points associated with that verification method;

the total number of points available for successful completion of the plurality of verification methods is equal to or greater than the verification score; and

at least one of the verification methods is a non-automated verification method requiring a manual input.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2022
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 059864/0746 →
Continuity (14)
Continuation In Part 16856827 · Apr 23, 2020
Continuation 15790860 · Oct 23, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62574708 · Oct 19, 2017
Related Publication 20220255926A1 · Aug 11, 2022
References Cited (19)
US 6256544B1 · Weissinger · 2001 [cited by examiner]
US 6857073B2 · French · 2005 [cited by examiner]
US 7171515B2 · Ohta · 2007 [cited by examiner]
US 7530105B2 · Gilbert · 2009 [cited by examiner]
US 8832840B2 · Zhu · 2014 [cited by examiner]
US 9256735B2 · Stute · 2016 [cited by examiner]
US 9558220B2 · Nixon · 2017 [cited by examiner]
US 9560065B2 · Neil · 2017 [cited by examiner]
US 10212034B1 · Carranza Giotto · 2019 [cited by examiner]
US 10216485B2 · Misra · 2019 [cited by examiner]
US 20050000165A1 · Dischinat · 2005 [cited by examiner]
US 20070226796A1 · Gilbert · 2007 [cited by examiner]
US 20130111592A1 · Zhu · 2013 [cited by examiner]
US 20130117852A1 · Stute · 2013 [cited by examiner]
US 20140359552A1 · Misra · 2014 [cited by examiner]
US 20150020199A1 · Neil · 2015 [cited by examiner]
US 20160006629A1 · Ianakiev · 2016 [cited by examiner]
US 20160275123A1 · Lin · 2016 [cited by examiner]
US 20170244762A1 · Kinder · 2017 [cited by examiner]