IP Library Granted Patent US 11,750,631
Granted Patent B2
US 11,750,631 · App. 17/589,811 · Granted Sep 5, 2023

System and method for comprehensive data loss prevention and compliance management

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX, INC.
H04L63/1425H04L43/045H04L43/08H04L63/1433G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,750,631
App. No.
17/589,811
Granted
Sep 5, 2023
Kind
B2
Abstract

A system and method to identify and prevent cybersecurity attacks on modern, highly-interconnected networks, to identify attacks before data loss occurs, using a combination of human level, device level, system level, and organizational level monitoring.

Claims (43)

1. A system for comprehensive data loss prevention and compliance management, comprising:

a computing device comprising a processor and a memory;

an observation and state estimation module comprising a first plurality of programming instructions stored in the memory and operating on the processor, wherein the first plurality of programming instructions, when operating on the processor, cause the computing device to:

monitor a plurality of connected resources on a network; and

produce a cyber-physical graph representing the plurality of connected resources, wherein:

the connected resources comprise one or more of people, devices, systems, and organizations within the network;

the cyber-physical graph comprises nodes representing the connected resources, which each node having one or more properties containing descriptive information for the connected resource represented by that node; and

the cyber-physical graph comprises edges representing the logical relationships between the plurality of connected resources and the physical relationships between any connected resources comprising a hardware device;

an activity monitoring engine comprising a second plurality of programming instructions stored in the memory and operating on the processor, wherein the second plurality of programming instructions, when operating on the processor, cause the computing device to:

generate expected behavior data of the connected resources within the network by applying a behavioral model to each node of the cyber-physical graph;

generate actual behavior data of the connected resources within the network from time-series data comprising a record of network events and the respective times at which each network event occurred;

detect deviations of the actual behavior data from the expected behavior data by comparing the expected behavior data properties of each node with the actual behavior properties of that node; and

when deviations are detected, send information about the deviation to a risk analysis and scoring engine; and

the risk analysis and scoring engine comprising a third plurality of programming instructions stored in the memory and operating on the processor, wherein the third plurality of programming instructions, when operating on the processor, cause the computing device to:

receive deviation information from the activity monitoring engine;

analyze the severity of a threat posed by the deviation using at least one analysis algorithm; and

generate a risk score based on a plurality of factors which indicate the severity of the threat.

2. The system of claim 1 , wherein the risk analysis and scoring engine further generates an impact assessment score for each affected connected resource by determining an impact on the network using the cyber-physical graph.

3. The system of claim 2 , wherein the impact assessment score further comprises the calculation of the overall impact of a cyberattack, wherein the calculation is based at least in part on the impact assessment score for each connected resource affected by the cyberattack.

4. The system of claim 1 , wherein the detection of deviations is based in part on a comparison of relationships between the connected resources against known security vulnerabilities.

5. The system of claim 4 , wherein the risk score is based at least in part on the results of the comparison against known security vulnerabilities.

6. The system of claim 1 , wherein the observation and state estimation module is further configured to produce a visualization based at least in part on at least a portion of the time-series data, wherein the visualization illustrates changes to the data over time.

7. A method for comprehensive data loss prevention and compliance management, comprising the steps of:

monitoring a plurality of connected resources on the network;

producing a cyber-physical graph representing the plurality of connected resources, wherein:

the connected resources comprise one or more of people, devices, systems, and organizations within the network;

the cyber-physical graph comprises nodes representing the connected resources, which each node having one or more properties containing descriptive information for the connected resource represented by that node; and

the cyber-physical graph comprises edges representing the logical relationships between the plurality of connected resources and the physical relationships between any connected resources comprising a hardware device;

generating expected behavior data of the connected resources-within the network by applying a behavioral model to each node of the cyber-physical graph;

generating actual behavior data of the connected resources within the network from time-series data comprising a record of network events and the respective times at which each network event occurred;

detecting deviations of the actual behavior data from the expected behavior data by comparing the expected behavior data properties of each node with the actual behavior properties of that node; and

when deviations are detected:

analyzing the severity of the threat posed by the deviation using at least one analysis algorithm;

generating a risk score based on a plurality of factors which indicate the severity of the threat; and

displaying the risk score in text and graphical form.

8. The method of claim 7 , wherein the risk analysis and scoring engine further generates an impact assessment score for each affected connected resource by determining an impact on the network using the cyber-physical graph.

9. The method of claim 8 , wherein the impact assessment score further comprises the calculation of the overall impact of a cyberattack, wherein the calculation is based at least in part on the impact assessment score for each connected resource affected by the cyberattack.

10. The method of claim 7 , wherein the detection of deviations is based in part on a comparison of relationships between the connected resources against known security vulnerabilities.

11. The method of claim 10 , wherein the risk score is based at least in part on the results of the comparison against known security vulnerabilities.

12. The method of claim 7 , wherein the observation and state estimation module is further configured to produce a visualization based at least in part on at least a portion of the time-series data, wherein the visualization illustrates changes to the data over time.

13. The system of claim 1 , further comprising a time series database module comprising a fourth plurality of programming instructions stored in the memory and operating on the processor, wherein the fourth plurality of programming instructions, when operating on the processor, cause the computing device to:

monitor a plurality of network events on a network; and

produce time-series data comprising a record of a network event and the time at which the event occurred.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2023
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 062797/0178 →
Continuity (14)
Continuation 16896764 · Jun 9, 2020
Continuation 16191054 · Nov 14, 2018
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Related Publication 20220263845A1 · Aug 18, 2022