IP Library Patent Application 17683242
Patent Application
App. No. 17/683,242

SYSTEM AND METHOD FOR DATA COMPLIANCE AND PREVENTION WITH THREAT DETECTION AND RESPONSE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/683,242
Filed
Feb 28, 2022
Art Unit
OPAP
USPC
726/23
Abstract

A system and method to identify and prevent cybersecurity attacks on modern, highly-interconnected networks, to identify attacks before data loss occurs, using a combination of human level, device level, system level, and organizational level monitoring.

Claims (54)

1 . A system for data compliance and protection with threat detection and response, comprising:

a computing device comprising a processor and a memory;

an activity monitoring engine comprising a first plurality of programming instructions stored in the memory and operating on the processor, wherein the first plurality of programming instructions, when operating on the processor, cause the computing device to:

generate expected behavior data of a plurality of connected resources by applying a behavioral model to each node of a cyber-physical graph; and

send the expected behavior data to an action outcome simulation module;

the action outcome simulation module comprising a second plurality of programming instructions stored in the memory and operating on the processor, wherein the second plurality of programming instructions, when operating on the processor, cause the computing device to:

receive expected behavior data from the activity monitoring engine;

determine unexpected actions of a plurality of connected resources via a plurality of simulations using the expected behavior data; and

produce a hypothetical behavior graph representing the unexpected actions to or by the plurality of connected resources, wherein:

the connected resources comprise one or more of people, devices, systems, and organizations within or out of an organization's network;

the hypothetical behavior graph comprises action nodes representing one or more of the connected resources and an action either to or by the connected resource, and wherein all action nodes but the last action node in a sequence has succeeding action node representing one or more of the connected resources and another action made possible by the preceding node's action; and

the hypothetical behavior graph comprises edges representing the logical or physical relationships between the action nodes and weighted by a likelihood and an impact of the preceding action node's action; and

a risk analyzer comprising a third plurality of programming instructions stored in the memory and operating on the processor, wherein the third plurality of programming instructions, when operating on the processor, cause the computing device to:

compare a real-time stream of actions of the connected resources against the hypothetical behavior graph identifying any sequence of action nodes that are unexpected and lead to a potential threat;

determine an impact of each potential threat posed by the identified sequences with respect to a set of data compliance rules; and

initiate a response to any identified sequences that meet the threshold for immediate action based on the impact and likelihood of the potential threat.

2 . The system of claim 1 , further comprising a scoring engine comprising a fourth plurality of programming instructions stored in the memory and operating on the processor, wherein the fourth plurality of programming instructions, when operating on the processor, cause the computing device to generate a risk score for each affected connected resource using the impact and likelihood of the identified sequences.

3 . The system of claim 2 , wherein the scoring engine further causes the computing device to display the risk score in text and graphical form.

4 . The system of claim 1 , wherein the response is a virtual compartmentalization of one or more of the connected resources that is potentially comprised.

5 . The system of claim 1 , further comprising an observation and state estimation module comprising a fifth plurality of programming instructions stored in the memory and operating on the processor, wherein the fifth plurality of programming instructions, when operating on the processor, cause the computing device to:

monitor the plurality of connected resources on the network; and

produce the cyber-physical graph representing the plurality of connected resources, wherein:

the connected resources comprise one or more of people, devices, systems, and organizations within the network;

the cyber-physical graph comprises nodes representing the connected resources, which each node having one or more properties containing descriptive information for the connected resource represented by that node; and

the cyber-physical graph comprises edges representing the logical relationships between the plurality of connected resources and the physical relationships between any connected resources comprising a hardware device.

6 . The system of claim 1 , wherein the activity monitoring engine further causes the computing device to:

store the expected behavior data for a node as the one or more properties of that node in the cyber-physical graph;

stream in real-time the actual behavior data of the connected resources within and out of the network to the risk analyzer;

detect deviations of the actual behavior data from the expected behavior data by comparing the expected behavior data properties of each node with the actual behavior properties of that node; and

when deviations are detected, send information about the deviation to the risk analyzer and the scoring engine.

7 . A method for data compliance and protection with threat detection and response, comprising the steps of:

generating expected behavior data of a plurality of connected resources by applying a behavioral model to each node of a cyber-physical graph;

determining unexpected actions of a plurality of connected resources via a plurality of simulations using the expected behavior data;

producing a hypothetical behavior graph representing the unexpected actions on or of the plurality of connected resources, wherein:

the connected resources comprise one or more of people, devices, systems, and organizations within or out of an organization's network;

the hypothetical behavior graph comprises action nodes representing one or more of the connected resources and an action either to or by the connected resource, and wherein all action nodes but the last action node in a sequence has succeeding action node representing one or more of the connected resources and another action made possible by the preceding node's action; and

the hypothetical behavior graph comprises edges representing the logical or physical relationships between the action nodes and weighted by a likelihood and an impact of the preceding action node's action;

comparing a real-time stream of actions of the connected resources against the hypothetical behavior graph identifying any sequence of action nodes that are unexpected and lead to a potential threat;

determining an impact of each potential threat posed by the identified sequences with respect to a set of data compliance rules; and

initiating a response to any identified sequences that meet the threshold for immediate action based on the impact and likelihood of the potential threat.

8 . The method of claim 7 , further comprising the steps of generating a risk score for each affected connected resource using the impact and likelihood of the identified sequences.

9 . The method of claim 8 , further comprising the steps of displaying the risk score in text and graphical form.

10 . The method of claim 7 , wherein the response is a virtual compartmentalization of one or more of the connected resources that is potentially comprised.

11 . The method of claim 7 , further comprising the steps of:

monitoring the plurality of connected resources on the network; and

producing the cyber-physical graph representing the plurality of connected resources, wherein:

the connected resources comprise one or more of people, devices, systems, and organizations within the network;

the cyber-physical graph comprises nodes representing the connected resources, which each node having one or more properties containing descriptive information for the connected resource represented by that node; and

the cyber-physical graph comprises edges representing the logical relationships between the plurality of connected resources and the physical relationships between any connected resources comprising a hardware device.

12 . The method of claim 7 , further comprising the steps of:

storing the expected behavior data for a node as the one or more properties of that node in the cyber-physical graph;

streaming in real-time the actual behavior data of the connected resources within and out of the network to the risk analyzer;

detecting deviations of the actual behavior data from the expected behavior data by comparing the expected behavior data properties of each node with the actual behavior properties of that node; and

when deviations are detected, sending information about the deviation to the risk analyzer and the scoring engine.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2023
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 062881/0313 →