IP Library Granted Patent US 12,244,629
Granted Patent B2
US 12,244,629 · App. 17/816,009 · Granted Mar 4, 2025

Systems and methods for applying reinforcement learning to cybersecurity graphs

Inventors: James Korge (Brooklyn, NY); Damion Irving (Brooklyn, NY); Jeffrey L. Thomas (Columbus, OH); Donald Bathurst (Denver, CO)
Assignee: Reveald Holdings, Inc.
H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,629
App. No.
17/816,009
Granted
Mar 4, 2025
Kind
B2
Abstract

Methods, systems and computer program products are provided for integrating risk and threat intelligence from various sources, to provide real-time awareness of potential threats to a computer network, which are now described herein in terms of an example enterprise system.

Claims (56)

1. A cybersecurity method for determining exploits, comprising the steps of:

receiving a graph representing a digital network of a plurality of nodes forming a federated learning network, the graph including at least one vulnerability for each of the plurality of nodes;

receiving, for the plurality of nodes, a plurality of embeddings based on the graph, wherein the plurality of embeddings include a vector of real numbers representing the plurality of notes in the graph;

assigning an agent an initial node from the plurality of nodes;

querying the graph to obtain a plurality of accessible nodes and at least one vulnerability for the accessible nodes;

determining a transition for the agent to take from the initial node to a next accessible node from the plurality of accessible nodes;

computing using a neural network, a reward for moving to the next accessible node;

assigning the agent a new state corresponding to the next accessible node;

collecting, by a collected experience database, a history of node assignments of the agent, a plurality of connections taken by the agent, and a plurality of rewards the agent received for transitioning across the plurality of connections;

updating a plurality of parameters of a neural network using the data collected by the collected experience database, wherein the information collected by each of a plurality of agents is used to further update the plurality of parameters of the neural network while not sharing graph data contributed by a plurality of graphs; and

determining, by the agent, what action from a plurality of available actions to take next using the neural network.

2. The method according to claim 1 , wherein determining the transition for the agent to take is based on the embeddings of a plurality of connections between the initial node and the plurality of accessible nodes.

3. The method according to claim 1 , further comprising the step of:

determining from the plurality of nodes on the graph at least one node having a vulnerability score relatively higher than a plurality of vulnerability scores of other nodes in the graph.

4. The method according to claim 1 , further comprising the step of:

detecting an exploit associated with a node in the graph representing the digital network; and

preventing the agent from traversing the node in the digital network that is associated with the exploit and represented in the graph, thereby inhibiting the exploit.

5. The method according to claim 1 , further comprising the step of:

determining a starting point in the graph that can be exploited to gain access to another node in the graph.

6. A non-transitory computer-readable medium having stored thereon sequences of instructions, the sequences of instructions including instructions which when executed by a computer system causes the computer system to perform determining exploits by:

receiving a graph representing a digital network of a plurality of nodes forming a federated learning network, the graph including at least one vulnerability for each of the plurality of nodes;

receiving for the plurality of nodes, a plurality of embeddings based on the graph;

assigning an agent an initial node from the plurality of nodes;

querying the graph to obtain a plurality of accessible nodes and at least one vulnerability for the accessible nodes, wherein the plurality of embeddings include a vector of real numbers representing the plurality of nodes in the graph;

determining a transition for the agent to take from the initial node to a next accessible node from the plurality of accessible nodes;

computing a reward for moving to the next accessible node;

assigning the agent a new state corresponding to the next accessible node;

collecting a history of node assignments of the agent, a plurality of connections taken by the agent, and a plurality of rewards the agent received for transitioning across the plurality of connections;

updating a plurality of parameters of a neural network using the data collected by the collected experience database, wherein the information collected by each of a plurality of agents is used to further update the plurality of parameters of the neural network while not sharing graph data contributed by a plurality of graphs; and

determining, by the agent, what action from a plurality of available actions to take next using the neural network.

7. The non-transitory computer-readable medium according to claim 6 , wherein determining the transition for the agent to take is based on the embeddings of a plurality of connections between the initial node and the plurality of accessible nodes.

8. The non-transitory computer-readable medium of claim 6 , further having stored thereon a sequence of instructions for causing the one or more processors to perform:

determining from the plurality of nodes on the graph at least one node having a vulnerability score relatively higher than a plurality of vulnerability scores of other nodes in the graph.

9. The non-transitory computer-readable medium of claim 6 , further having stored thereon a sequence of instructions for causing the one or more processors to perform:

detecting an exploit associated with a node in the graph representing the digital network; and

preventing the agent from traversing the node in the digital network that is associated with the exploit and represented in the graph, thereby inhibiting the exploit.

10. The non-transitory computer-readable medium of claim 6 , further having stored thereon a sequence of instructions for causing the one or more processors to perform:

determining a starting point in the graph that can be exploited to gain access to another node in the graph.

11. A cybersecurity system for determining exploits, comprising:

one or more processors configured to:

generate, for a plurality of nodes, a plurality of embeddings based on a graph representing a digital network of the plurality of nodes forming a federated learning network, the graph including at least one vulnerability for each of the plurality of nodes, wherein the plurality of embeddings include a vector of real numbers representing the plurality of nodes in the graph;

assign an agent an initial node from the plurality of nodes;

query the graph to obtain a plurality of accessible nodes and at least one vulnerability for two or more accessible nodes;

determine a transition for the agent to take from the initial node to a next accessible node from the plurality of accessible nodes;

compute, using a neural network, a reward for moving to the next accessible node;

assign the agent a new state corresponding to the next accessible node;

a collected experience database configured to collect a history of node assignments of the agent, a plurality of connections taken by the agent, and a plurality of rewards the agent received for transitioning across the plurality of connections;

the one or more processors further configured to update a plurality of parameters of a neural network, wherein the information collected by each of a plurality of agents is used to that further update the plurality of parameters of the neural network while not sharing graph data contributed by a plurality of graphs; and

the agent further configured to determine what action from a plurality of available actions to take next using the neural network.

12. The cybersecurity system according to claim 11 , wherein determining the transition for the agent to take is based on the embeddings of a plurality of connections between the initial node and the plurality of accessible nodes.

13. The cybersecurity system according to claim 11 , wherein the one or more processors are further configured to determine, from the plurality of nodes on the graph, at least one node having a vulnerability score relatively higher than a plurality of vulnerability scores of other nodes in the graph.

14. The cybersecurity system according to claim 11 , wherein the one or more processors are further configured to:

detect an exploit associated with a node in the graph representing the digital network; and

prevent the agent from traversing the node in the digital network that is associated with the exploit and represented in the graph, thereby inhibiting the exploit.

15. The cybersecurity system according to claim 11 , wherein the one or more processors are further configured to:

determine a starting point in the graph that can be exploited to gain access to another node in the graph.

Assignments (3)
CHANGE OF NAME Recorded Nov 13, 2023
From: EPIPHANY SYSTEMS, INC.
To: REVEALD HOLDINGS, INC.
Reel/Frame 065550/0427 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2023
From: DIGITALWARE, INC.
To: EPIPHANY SYSTEMS, INC.
Reel/Frame 062281/0047 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: KORGE, JAMES; IRVING, DAMION; THOMAS, JEFFREY L.; BATHURST, DONALD
To: DIGITALWARE, INC.
Reel/Frame 060668/0959 →
Continuity (2)
Provisional Application 63227963 · Jul 30, 2021
Related Publication 20230034303A1 · Feb 2, 2023
References Cited (41)
US 8881288B1 · Levy et al. · 2014 [cited by applicant]
US 10033754B2 · Pinney Wood et al. · 2018 [cited by applicant]
US 10084822B2 · Papamartzivanos et al. · 2018 [cited by applicant]
US 10425429B2 · Bassett · 2019 [cited by applicant]
US 10476896B2 · DiValentin et al. · 2019 [cited by applicant]
US 10630716B1 · Ghosh et al. · 2020 [cited by applicant]
US 10657461B2 · McMahan et al. · 2020 [cited by applicant]
US 10848515B1 · Pokhrel et al. · 2020 [cited by applicant]
US 20150193695A1 · Cruz Mota et al. · 2015 [cited by applicant]
US 20180159890A1 · Warnick · 2018 [cited by examiner]
US 20190005195A1 · Peterson · 2019 [cited by examiner]
US 20190061147A1 · Luciw · 2019 [cited by examiner]
US 20190222593A1 · Craig · 2019 [cited by examiner]
US 20190385051A1 · Wabgaonkar · 2019 [cited by examiner]
US 20200145441A1 · Patterson · 2020 [cited by examiner]
US 20200412767A1 · Crabtree · 2020 [cited by applicant]
US 20210019325A1 · Edge · 2021 [cited by examiner]
US 20210021629A1 · Dani · 2021 [cited by applicant]
US 20210042471A1 · Ponomarev · 2021 [cited by examiner]
US 20210234882A1 · Lee · 2021 [cited by applicant]
US 20220014561A1 · Caceres · 2022 [cited by examiner]
US 20220201014A1 · Saha · 2022 [cited by applicant]
US 20220407879A1 · Dong · 2022 [cited by examiner]
US 20230032249A1 · Irving · 2023 [cited by applicant]
US 20230056706A1 · Irving · 2023 [cited by applicant]
US 20230208882A1 · Crabtree · 2023 [cited by examiner]
US 20230328094A1 · Brown · 2023 [cited by examiner]
WO 2020219157 · 2020 [cited by applicant]
WO 2021080577 · 2021 [cited by applicant]
A Markov Game Theoritic Approach for Power Grid Security. Gael Kamdem , Charles Kamhoua, Yue Lu, Sachin Shetty. 2017 IEEE 37th International Conference on Distributed Computing Systems Workshops. pp. 139-144. [cited by examiner]
PCT International Search Report and Written Opinion in Application PCT/US2022/038829, mailed Nov. 28, 2022, 18 pages. [cited by applicant]
Zhang, Lei et al., “Discover the Hidden Attack Path in Multi-Domain Cyberspace Based on Reinforcement Learning”, arXiv:2104.07195v1 [cs.CR], Apr. 15, 2021, 12 pages. [cited by applicant]
Alavizadeh, Hooman et al., “A Markov Game Model for Al-Based Cyber Security Attack Mitigation”, arxiv.org, Cornell University Library, Jul. 20, 2021, 11 pages. [cited by applicant]
He, Chaoyang et al., “FedGraphNN: A Federated Learning System and Benchmark for Graph Neural Networks”, arxiv.org, Cornell University Library, Apr. 14, 2021, 19 pages. [cited by applicant]
McMahen, H. Brendan et al., “Communication-Efficient Learning of Deep Networks from Decentralized Data”, Feb. 28, 2017, https://arxiv.org/pdf/1602.05629.pdf, retrieved on Jan. 7, 2019, 11 pages. [cited by applicant]
PCT International Search Report and Written Opinion in Application PCT/US2022/038845, mailed Oct. 25, 2022, 19 pages. [cited by applicant]
PCT International Search Report and Written Opinion in Application PCT/US2022/038863, mailed Oct. 27, 2022, 18 pages. [cited by applicant]
Yang, Qiang et al., “Federated Learning”, IEEE, Dec. 31, 2020, https://ieeexplore.ieee.org/abstract/document/8940936, retrieved on Dec. 31, 2020, 202 pages. [cited by applicant]
PCT International Preliminary Report on Patentability in Application PCT/US2022/038829, mailed Feb. 8, 2024, 10 pages. [cited by applicant]
PCT International Preliminary Report on Patentability in Application PCT/US2022/038845, mailed Feb. 8, 2024, 12 pages. [cited by applicant]
PCT International Preliminary Report on Patentability in Application PCT/US2022/038863, mailed Feb. 29, 2024, 10 pages. [cited by applicant]
Cited By (1)
US 12,739,272