IP Library Granted Patent US 12,634,345
Granted Patent B2
US 12,634,345 · App. 17/986,850 · Granted May 19, 2026

Holistic external network cybersecurity evaluation and scoring

Inventors: Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
H04L63/20G06F16/2477G06F16/951G06F21/577H04L63/1425H04L63/1433H04L63/1441G06F2221/033G06F2221/034H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,345
App. No.
17/986,850
Granted
May 19, 2026
Kind
B2
Abstract

A system and method for holistic network cybersecurity evaluation and risk rating that takes into account the operation of the entire target network environment comprising hardware, software, operating systems, and network connections. Not only are the hardware, software, operating system, and network evaluated separately for cybersecurity concerns, their interaction and operation as a whole are also evaluated and scored. The results of such analyses may be used, for example, by underwriters of cybersecurity insurance policies to determine policy terms and rates.

Claims (61)

1 . A system for holistic network cybersecurity evaluation and rating, comprising:

a first computing device comprising a memory and a processor;

a reconnaissance engine comprising a first plurality of programming instructions stored in the memory of, and operating on the processor of, the first computing device, wherein the first plurality of programming instructions, when operating on the processor, cause the first computing device to:

capture system information and characteristics about a target network comprising a plurality of computing devices; and

use the captured system information and characteristics to create a network definition of the target network, the network definition being in the form of a graph representation of the target network, wherein nodes of the graph represent hardware or computing devices, and edges between nodes represent physical and logical connections between and among the hardware or computing devices;

a hardware emulator comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the first computing device, wherein the second plurality of programming instructions, when operating on the processor, cause the first computing device to:

emulate functioning of the target network on the first computing device by:

executing a set of functions that emulate the operation of the target network as defined by hardware definitions and the network definition;

installing operating systems on emulated computing devices of the target network;

installing applications on emulated computing devices of the target network; and

executing the applications on the emulated computing device using the operating systems; and

analyze the functioning of the target network by executing an attack on the emulated target network associated with a known hardware exploit to:

determine whether the emulated target network is susceptible to the known hardware exploit;

update a network cybersecurity score using the determination; and

send the updated network cybersecurity score to a scoring engine; and

the scoring engine comprising a third plurality of programming instructions stored in the memory of, and operating on the processor of, the first computing device, wherein the third plurality of programming instructions, when operating on the processor, cause the first computing device to:

generate a cybersecurity score for the target network based on a combination of a software cybersecurity score, the hardware cybersecurity score, an operating system cybersecurity score, and the network cybersecurity score; and

update the cybersecurity score for the target network with the updated network cybersecurity score.

2 . The system of claim 1 , further comprising a system analyzer that receives a software definition comprising source code for an application, wherein the software definition is accompanied by source code for the application, and wherein the software cybersecurity score further comprises an analysis of coding complexity of the source code.

3 . The system of claim 1 , further comprising a system analyzer comprising a fourth plurality of programming instructions stored in the memory of, and operating on the processor of, the first computing device, wherein the fourth plurality of programming instructions, when operating on the processor, causes the first computing device to:

receive a system definition comprising:

a software definition comprising executable binary code for the application; and

an operating system definition for the target network, the operating system definition comprising executable binary code for the operating system;

identify a software function defined by the software definition and compare the software function to a database of software functions to establish the software cybersecurity score;

identify a hardware component defined by the hardware definition and compare the component to a database of components to establish the hardware cybersecurity score; and

identify an operating system function defined by the operating system definition and compare the operating system function to a database of operating system functions to establish the operating system cybersecurity score.

4 . The system of claim 1 , wherein the hardware definition comprises at least one or more memory maps, wherein the one or more memory maps associate hardware components of a physical hardware system and memory locations of the emulated computing devices of the target network.

5 . The system of claim 1 , wherein the first computing device is a cloud-based computing device external to the target network.

6 . The system of claim 1 , wherein a set of clones of the emulated computing devices of the target network are created and tools are injected in each clone for testing.

7 . The system of claim 1 , wherein the scoring engine is further configured to:

correlate cybersecurity signals received from multiple tools across a unified security platform including endpoint protection, identity management, data loss prevention, and threat analytics tools; and

adjust the cybersecurity score for the target network based on aggregated signal intelligence and risk profiles derived from over a threshold quantity of daily threat indicators.

8 . A method for holistic network cybersecurity evaluation and rating, comprising the steps of:

capturing system information and characteristics about a target network comprising a plurality of computing devices;

using the captured system information and characteristics to create a network definition of the target network, the network definition being in the form of a graph representation of the target network, wherein nodes of the graph represent hardware or computing devices, and edges between nodes represent physical and logical connections between and among the hardware or computing devices:

emulating functioning of the target network on a first computing device by:

executing a set of functions that emulate the operation of the target network as defined by a hardware definition and the network definition;

installing operating systems on the emulated computing devices of the target network;

installing applications on the emulated computing devices of the target network; and

executing the applications on the emulated computing devices using the operating systems; and

analyzing the functioning of the target network by executing an attack on the emulated target network associated with a known hardware exploit to:

determine whether the emulated target network is susceptible to the known hardware exploit; and

update a network cybersecurity score using the determination;

generating a cybersecurity score for the target network based on a combination of a software cybersecurity score, a hardware cybersecurity score, an operating system cybersecurity score, and a network cybersecurity score; and

updating the cybersecurity score for the target network using the updated network cybersecurity score.

9 . The method of claim 8 , wherein the software definition is accompanied by source code for the application, and wherein the software cybersecurity score further comprises an analysis of the coding complexity of the source code.

10 . The method of claim 8 , further comprising the steps of:

receiving a system definition comprising:

a software definition comprising executable binary code for the application;

the hardware definition comprising a specification for the target network; and

an operating system definition for the target network, the operating system definition comprising executable binary code for the operating system;

identifying a software function defined by the software definition and comparing the function to a database of software functions to establish the software cybersecurity score;

identifying a hardware component defined by the hardware definition and comparing the component to a database of components to establish the hardware cybersecurity score; and

identifying an operating system function defined by the operating system definition and comparing the function to a database of operating system functions to establish the operating system cybersecurity score.

11 . The method of claim 8 , wherein the hardware definition comprises at least one or more memory maps, wherein the one or more memory maps associate hardware components of a physical hardware system and memory locations of the emulated computing devices of the target network.

12 . The method of claim 8 , wherein the first computing device is a cloud-based computing device external to the target network.

13 . The method of claim 8 , wherein a set of clones of the emulated computing devices of the target network are created and tools are injected in each clone for testing.

14 . The method of claim 8 , further comprising the steps of:

receiving a plurality of cybersecurity threat signals from identity management systems, endpoint monitoring tools, and data protection systems;

generating a composite risk signal from the plurality of cybersecurity threat signals; and

adjusting the cybersecurity score of the target network based on the composite risk signal.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY DATA NAME: RICHARD KELLY PREVIOUSLY RECORDED AT REEL: 064412 FRAME: 0292. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: CRABTREE, JASON; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 066342/0698 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2023
From: CRABTREE, JASON; KELLY, RICHARD
To: QOMPLX, INC.
Reel/Frame 064412/0292 →
Continuity (46)
Continuation In Part 17567060 · Dec 31, 2021
Continuation In Part 17389863 · Jul 30, 2021
Continuation 16792754 · Feb 17, 2020
Continuation In Part 16779801 · Feb 3, 2020
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 17170288 · Feb 8, 2021
Continuation In Part 17169924 · Feb 8, 2021
Continuation In Part 15837845 · Dec 11, 2017
Continuation In Part 15825350 · Nov 29, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 17102561 · Nov 24, 2020
Continuation 15790457 · Oct 23, 2017
Continuation In Part 15790327 · Oct 23, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 17105025 · Nov 25, 2020
Continuation 16836717 · Mar 31, 2020
Continuation In Part 15887496 · Feb 2, 2018
Continuation In Part 15823285 · Nov 27, 2017
Continuation In Part 15788718 · Oct 19, 2017
Continuation In Part 15788002 · Oct 19, 2017
Continuation In Part 15787601 · Oct 18, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15725274 · Oct 4, 2017
Provisional Application 62596105 · Dec 7, 2017
Provisional Application 62568291 · Oct 4, 2017
Provisional Application 62568298 · Oct 4, 2017
Provisional Application 62568312 · Oct 4, 2017
Provisional Application 62568305 · Oct 4, 2017
Provisional Application 62568307 · Oct 4, 2017
Related Publication 20230171292A1 · Jun 1, 2023
References Cited (47)
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 7739653B2 · Venolia · 2010 [cited by applicant]
US 8006303B1 · Dennerline · 2011 [cited by examiner]
US 8583639B2 · Chitnis et al. · 2013 [cited by applicant]
US 8595240B1 · Otey · 2013 [cited by examiner]
US 8677473B2 · Dennerline et al. · 2014 [cited by applicant]
US 8725597B2 · Mauseth et al. · 2014 [cited by applicant]
US 8726393B2 · Macy et al. · 2014 [cited by applicant]
US 9141360B1 · Chen et al. · 2015 [cited by applicant]
US 9210185B1 · Pinney Wood · 2015 [cited by examiner]
US 9288223B2 · Sharabani · 2016 [cited by examiner]
US 9319430B2 · Bell, Jr. et al. · 2016 [cited by applicant]
US 9426169B2 · Zandani · 2016 [cited by examiner]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9672355B2 · Titonis et al. · 2017 [cited by applicant]
US 9712553B2 · Nguyen et al. · 2017 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10320828B1 · Derbeko · 2019 [cited by examiner]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 20050289072A1 · Sabharwal · 2005 [cited by applicant]
US 20080270203A1 · Holmes · 2008 [cited by examiner]
US 20080270209A1 · Mauseth · 2008 [cited by examiner]
US 20090210419A1 · Chitnis · 2009 [cited by examiner]
US 20090320137A1 · White · 2009 [cited by examiner]
US 20100125900A1 · Dennerline · 2010 [cited by examiner]
US 20110004566A1 · Berkowitz · 2011 [cited by examiner]
US 20130019314A1 · Ji · 2013 [cited by examiner]
US 20130097706A1 · Titonis et al. · 2013 [cited by applicant]
US 20130227697A1 · Zandani · 2013 [cited by examiner]
US 20130283336A1 · Macy · 2013 [cited by examiner]
US 20130318614A1 · Archer · 2013 [cited by examiner]
US 20140173738A1 · Condry · 2014 [cited by examiner]
US 20150106889A1 · Sharabani · 2015 [cited by examiner]
US 20150237068A1 · Sandke · 2015 [cited by examiner]
US 20150365437A1 · Bell, Jr. · 2015 [cited by examiner]
US 20160004858A1 · Chen et al. · 2016 [cited by applicant]
US 20160057166A1 · Chesla · 2016 [cited by examiner]
US 20160099960A1 · Gerritz et al. · 2016 [cited by applicant]
US 20160117498A1 · Saxena · 2016 [cited by examiner]
US 20160149930A1 · Casaburi · 2016 [cited by examiner]
US 20160196368A1 · Momot · 2016 [cited by examiner]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20160285907A1 · Nguyen · 2016 [cited by examiner]
US 20170235961A1 · August · 2017 [cited by examiner]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]