IP Library Patent Application 17589797
Patent Application
App. No. 17/589,797

SYSTEM AND METHOD FOR CYBERSECURITY ANALYSIS AND SCORE GENERATION FOR INSURANCE PURPOSES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/589,797
Abstract

A system for comprehensive cybersecurity analysis and rating based on heterogeneous data and reconnaissance is provided, comprising a multidimensional time-series data server configured to create a dataset with at least time-series data gathered from passive or active network reconnaissance of a client or target; and a cybersecurity scoring engine configured to retrieve the dataset from the multidimensional time-series data server, process the dataset using at least computational graph analysis, and generate an aggregated cybersecurity score based at least on results of processing the dataset.

Claims (37)

1 . A system for comprehensive cybersecurity analysis and rating based on heterogeneous data and reconnaissance, comprising:

a computing device comprising a hardware memory, a hardware processor, and a network interface device; and

a high-volume web crawler comprising a first plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the first plurality of programming instructions, when operating on the processor, causes the computing device to obtain information from the Internet as directed by an automated planning service module;

an automated planning service module, comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programming instructions, when operating on the processor, causes the computing device to:

establish a scope of cybersecurity analysis by:

defining a target network by identifying internet protocol addresses and subdomains of the target network;

identifying web applications used by the target network; and

gathering version and update information for hardware and software systems within the boundary of the target network; and

perform reconnaissance of the target network according to the established scope by:

verifying domain name system information for each internet protocol address and subdomain of the target network to confirm ownership and extent of the target network;

identifying additional domains and entities related to the target network using the domain name system information and accessing each additional domain and entity for malicious activity and cybersecurity vulnerabilities;

assigning an Internet reconnaissance score based on the confirmation and the malicious activity and cybersecurity vulnerabilities of any identified related domain and entity;

collecting domain name system leak information by identifying improper network configurations in the internet protocol addresses and subdomains of the target network, and assigning a domain name system leak information score;

analyzing web applications used by the target network to identify vulnerabilities in the web applications that could allow unauthorized access to the target network, and assigning a web application security score based on the identified vulnerabilities; and

checking version and update information for the hardware and software systems within the boundary of the target network, and assigning a patching frequency score; and

a cybersecurity scoring engine comprising a third plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the third plurality of programming instructions, when operating on the processor, cause the computing device to:

generate a weighted cybersecurity rating by:

assigning a weight to each of the Internet reconnaissance score, the domain name system leak information score, the web application security score, the patching frequency score;

aggregating the weighted scores into the weighted cybersecurity rating; and

reporting the weighted cybersecurity rating.

2 . The system of claim 1 , further comprising a task scheduling engine comprising a fourth plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the fourth plurality of programming instructions, when operating on the processor, cause the computing device to schedule computer tasks and programs to run at certain intervals.

3 . A method for comprehensive cybersecurity analysis and rating based on heterogeneous data and reconnaissance, comprising the steps of:

establishing a scope of cybersecurity analysis by:

defining a target network by identifying internet protocol addresses and subdomains of the target network;

identifying web applications used by the target network; and

gathering version and update information for hardware and software systems within the boundary of the target network;

performing reconnaissance of the target network according to the established scope by:

verifying domain name system information for each internet protocol address and subdomain of the target network to confirm ownership and extent of the target network;

identifying additional domains and entities related to the target network using the domain name system information and accessing each additional domain and entity for malicious activity and cybersecurity vulnerabilities;

assigning an Internet reconnaissance score based on the confirmation and the malicious activity and cybersecurity vulnerabilities of any identified related domain and entity;

collecting domain name system leak information by identifying improper network configurations in the internet protocol addresses and subdomains of the target network, and assigning a domain name system leak information score;

analyzing web applications used by the target network to identify vulnerabilities in the web applications that could allow unauthorized access to the target network, and assigning a web application security score based on the identified vulnerabilities; and

checking version and update information for the hardware and software systems within the boundary of the target network, and assigning a patching frequency score; and

generating a weighted cybersecurity rating by:

assigning a weight to each of the Internet reconnaissance score, the domain name system leak information score, the web application security score, the patching frequency score;

aggregating the weighted scores into the weighted cybersecurity rating; and

reporting the weighted cybersecurity rating.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2022
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 060077/0662 →