IP Library Patent Application 17585637
Patent Application
App. No. 17/585,637

SYSTEM AND METHOD FOR CYBERSECURITY ANALYSIS AND SCORE GENERATION FOR INSURANCE PURPOSES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/585,637
Abstract

A system for comprehensive cybersecurity analysis and rating based on heterogeneous data and reconnaissance is provided, comprising a multidimensional time-series data server configured to create a dataset with at least time-series data gathered from passive network reconnaissance of a client; and a cybersecurity scoring engine configured to retrieve the dataset from the multidimensional time-series data server, process the dataset using at least computational graph analysis, and generate an aggregated cybersecurity score based at least on results of processing the dataset.

Claims (41)

1 . A system for comprehensive cybersecurity analysis and rating based on heterogeneous data and reconnaissance, comprising:

a computing device comprising a hardware memory, a hardware processor, and a network interface device; and

an automated planning service module comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programming instructions, when operating on the processor, causes the computing device to:

establish a scope of cybersecurity analysis by:

defining a target network by identifying internet protocol addresses and subdomains of the target network;

identifying web applications used by the target network; and

gathering version and update information for hardware and software systems within the boundary of the target network; and

perform reconnaissance of the target network according to the established scope by:

verifying domain name system information for each internet protocol address and subdomain of the target network and assigning an Internet reconnaissance score;

collecting domain name system leak and assigning a domain name system leak information score;

analyzing web applications used by the target network to identify vulnerabilities in the web applications and assigning a web application security score based on the identified vulnerabilities; and

checking version and update information for the hardware and software systems within the boundary of the target network, and assigning a patching frequency score.

2 . The system of claim 1 , further comprising a cybersecurity scoring engine comprising a third plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the third plurality of programming instructions, when operating on the processor, cause the computing device to:

generate a weighted cybersecurity rating by:

assigning a weight to each of the Internet reconnaissance score, the domain name system leak information score, the web application security score, the patching frequency score;

aggregating the weighted scores into the weighted cybersecurity rating; and

reporting the weighted cybersecurity rating.

3 . The system of claim 1 , further comprising a task scheduling engine comprising a fourth plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the fourth plurality of programming instructions, when operating on the processor, cause the computing device to schedule computer tasks and programs to run at certain intervals.

4 . The system of claim 1 , wherein the domain name system information for each internet protocol address and subdomain of the target network is verified to confirm ownership and extent of the target network.

5 . The system of claim 4 , wherein assigning the Internet reconnaissance score is based on the confirmation.

6 . The system of claim 1 , wherein the domain name system leak information is collected by identifying improper network configurations in the internet protocol addresses and subdomains of the target network.

7 . The system of claim 1 , wherein the identified vulnerabilities could allow unauthorized access to the target network.

8 . A method for comprehensive cybersecurity analysis and rating based on heterogeneous data and reconnaissance, comprising the following steps:

establishing a scope of cybersecurity analysis using an automated planning service module, the establishment of the scope of cybersecurity analysis comprising the following steps:

defining a target network by identifying internet protocol addresses and subdomains of the target network;

identifying web applications used by the target network; and

gathering version and update information for hardware and software systems within the boundary of the target network; and

performing reconnaissance of the target network according to the established scope using the automated planning service module, the reconnaissance comprising the following steps:

verifying domain name system information for each internet protocol address and subdomain of the target network and assigning an Internet reconnaissance score based on the confirmation;

collecting domain name system leak information and assigning a domain name system leak information score;

analyzing web applications used by the target network to identify vulnerabilities in the web applications and assigning a web application security score; and

checking version and update information for the hardware and software systems within the boundary of the target network, and assigning a patching frequency score.

9 . The method of claim 8 , further comprising generating a weighted cybersecurity rating using a cybersecurity scoring engine, the generation of the weighted cybersecurity rating comprising the following steps:

assigning a weight to each of the Internet reconnaissance score, the domain name system leak information score, the web application security score, the patching frequency score;

aggregating the weighted scores into the weighted cybersecurity rating; and

reporting the weighted cybersecurity rating.

10 . The method of claim 8 , further comprising the step of scheduling computer tasks and programs to run at certain intervals.

11 . The method of claim 8 , wherein the domain name system information for each internet protocol address and subdomain of the target network is verified to confirm ownership and extent of the target network.

12 . The method of claim 11 , wherein assigning the Internet reconnaissance score is based on the confirmation.

13 . The method of claim 8 , wherein the domain name system leak information is collected by identifying improper network configurations in the internet protocol addresses and subdomains of the target network.

14 . The method of claim 8 , wherein the identified vulnerabilities could allow unauthorized access to the target network.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2023
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 064427/0599 →
CHANGE OF ADDRESS Recorded Dec 29, 2022
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 062251/0629 →