IP Library Granted Patent US 12,542,811
Granted Patent B2
US 12,542,811 · App. 18/069,206 · Granted Feb 3, 2026

Policy-aware software compliance verification with distributed code auditing

Inventors: Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
H04L63/20G06F16/2477G06F16/951H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,542,811
App. No.
18/069,206
Granted
Feb 3, 2026
Kind
B2
Abstract

A system for continuous contextual policy-aware vulnerability mapping, security posture determination and attack planning and simulation, comprising an indexing service configured to create a dataset by processing and indexing source code of a project by a developer, perform a code audit on the indexed source code, store results from the code audit in the dataset, gather additional information relating to the provided project as intended and as operated, store the additional information in the dataset, and store the dataset into memory; and a monitoring service configured to continuously monitor the project for source code and operational changes and performance and make changes to the dataset as needed.

Claims (61)

1 . A system for policy-aware vulnerability mapping, security posture determination and attack planning and simulation, comprising:

a computing device comprising at least a processor and a memory;

an indexing service comprising a first plurality of programming instructions stored in the memory and operable on the processor of the computing device, wherein the first plurality of programmable instructions, when operating on the processor, cause the processor to:

create a dataset by processing and indexing source code of a project provided by a developer;

perform a code audit using automated analysis using a distributed computational graph comprising at least a plurality of network-addressable processors and memories operating on a plurality of network-connected computing devices, the distributed computational graph collectively maintains maintaining a distributed computational graph and a plurality of interfaces for accessing the functionality of the distributed computational graph across a network, on the indexed source code; and

store results from the code audit in the dataset; and

an enforcement service comprising a second plurality of programming instructions stored in the memory and operable on the processor of the computing device, wherein the second plurality of programmable instructions, when operating on the processor, cause the processor to:

retrieve a software asset from the database for compliance verification, wherein the software asset is a portion of source code;

retrieve a set of rules and obligations relating to the software asset using metadata from a rules database;

automatically perform the compliance verification of the software asset according to the set of rules and obligations from the rules database;

produce a compliance recommendation for any non-complaint part of the software asset;

for any rule or obligation of the set of rules and obligations that cannot be automatically verified during the compliance verification:

forward said rule or obligation to an enforcement queue for a manual recommendation;

receive the manual recommendation and an approval decision for said rule or obligation; and

store the results of the compliance verification.

2 . The system of claim 1 , wherein the enforcement module is further configured to:

retrieve a network asset from a cyber-physical graph of a computer network, wherein the network asset is a hardware device;

retrieve policy configurations relating to the network asset from a policy database;

automatically perform the policy compliance verification of the network asset according to the policy configurations from the policy database;

produce a policy compliance recommendation for any non-complaint part of the network asset;

for any policy configuration that cannot be automatically verified during the policy compliance verification:

forward said policy configuration to the enforcement queue for a manual recommendation;

receive the manual recommendation and an approval decision regarding said policy configuration; and

store the results of the policy compliance verification.

3 . The system of claim 2 , further comprising an attack path engine comprising a third plurality of programming instructions stored in the memory and operable on the processor of the computing device, wherein the third plurality of programmable instructions, when operating on the processor, cause the processor to:

create and store the cyber-physical graph of the computer network;

perform a plurality of queries over time on the cyber-physical graph to identify paths between nodes;

receive results of the plurality of queries;

retrieve the results of the policy compliance verification;

analyze the plurality of results of queries and the results of the policy compliance verification to determine a plurality of risk attributes associated with each of a plurality of nodes in the graph, the risk attributes for each node being based at least in part on a determined value and policy compliance of the node and the node's connectivity to other nodes within any identified paths; and

create and store a policy-aware attack path map comprising a plurality of identified paths that each exceed a plurality of stored risk conditions.

4 . The system of claim 2 , wherein the policy configurations comprise general procedures and protocols applied to each network asset.

5 . A method for policy-aware vulnerability mapping and attack planning, comprising the steps of:

creating a dataset by processing and indexing source code of a project provided by a developer;

performing a code audit using automated analysis using a distributed computational graph comprising at least a plurality of network-addressable processors and memories operating on a plurality of network-connected computing devices, the distributed computational graph collectively maintaining a distributed computational graph and a plurality of interfaces for accessing the functionality of the distributed computational graph across a network, on the indexed source code;

storing results from the code audit in the dataset;

retrieving a software asset from the database for compliance verification, wherein the software asset is a portion of code;

retrieving rules and obligations relating to the software asset using metadata from a rules database;

automatically performing the compliance verification of the software asset according to the set of rules and obligations from the rules database;

producing a compliance recommendation for any non-complaint part of the software asset;

for any rule or obligation of the set of rules and obligations that cannot be automatically verified during the compliance verification:

forwarding said rule or obligation to an enforcement queue for manual recommendation;

receiving the manual recommendation and an approval decision regarding said rule or obligation; and

storing the results of the compliance verification.

6 . The method of claim 5 , further comprising the steps of:

retrieving a network asset from a cyber-physical graph of a computer network, wherein the network asset is a hardware device;

retrieving policy configurations relating to the network asset from a policy database;

automatically performing the policy compliance verification of the network asset according to the policy configurations from the policy database;

producing a policy compliance recommendation for any non-complaint part of the network asset;

for any policy configuration that cannot be automatically verified during the policy compliance verification:

forwarding said policy configuration to the enforcement queue for a manual recommendation;

receiving the manual recommendation and an approval decision regarding said policy configuration; and

storing the results of the policy compliance verification.

7 . The method of claim 6 , further comprising the steps of:

creating and storing the cyber-physical graph of the computer network;

performing a plurality of queries over time on the cyber-physical graph to identify paths between nodes;

receiving results of the plurality of queries;

retrieving the results of the policy compliance verification;

analyzing the plurality of results of queries and the results of the policy compliance verification to determine a plurality of risk attributes associated with each of a plurality of nodes in the graph, the risk attributes for each node being based at least in part on a determined value and policy compliance of the node and the node's connectivity to other nodes within any identified paths; and

creating and storing a policy-aware attack path map comprising a plurality of identified paths that each exceed a plurality of stored risk conditions.

8 . The method of claim 6 , wherein the policy configurations comprise general procedures and protocols applied to each network asset.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE ASSIGNOR'S NAME FROM RICHARD KELLY TO RICHARD KELLEY PREVIOUSLY RECORDED AT REEL: 64412 FRAME: 415. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 22, 2024
From: CRABTREE, JASON; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 067505/0892 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2023
From: CRABTREE, JASON; KELLY, RICHARD
To: QOMPLX, INC.
Reel/Frame 064412/0415 →
Continuity (73)
Continuation In Part 17362590 · Jun 29, 2021
Continuation In Part 17330893 · May 26, 2021
Continuation In Part 17008276 · Aug 31, 2020
Continuation In Part 17000504 · Aug 24, 2020
Continuation In Part 16855724 · Apr 22, 2020
Continuation In Part 16836717 · Mar 31, 2020
Continuation In Part 15887496 · Feb 2, 2018
Continuation In Part 15823285 · Nov 27, 2017
Continuation In Part 15788718 · Oct 19, 2017
Continuation In Part 15788002 · Oct 19, 2017
Continuation In Part 15787601 · Oct 18, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 16412340 · May 14, 2019
Continuation In Part 16267893 · Feb 5, 2019
Continuation In Part 16248133 · Jan 15, 2019
Continuation In Part 15849901 · Dec 21, 2017
Continuation In Part 15835436 · Dec 7, 2017
Continuation In Part 15790457 · Oct 23, 2017
Continuation In Part 15790327 · Oct 23, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15835312 · Dec 7, 2017
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15813097 · Nov 14, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15806697 · Nov 8, 2017
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15343209 · Nov 4, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15229476 · Aug 5, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15673368 · Aug 9, 2017
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 16945743 · Jul 31, 2020
Continuation 15655113 · Jul 20, 2017
Continuation In Part 17336108 · Jun 1, 2021
Continuation In Part 17216754 · Mar 30, 2021
Continuation 16856886 · Apr 23, 2020
Continuation 15823285 · Nov 27, 2017
Continuation In Part 17197697 · Mar 10, 2021
Continuation In Part 17189161 · Mar 1, 2021
Continuation In Part 17061195 · Oct 1, 2020
Continuation In Part 17035029 · Sep 28, 2020
Continuation In Part 17008276 · Aug 31, 2020
Continuation In Part 15879801 · Jan 25, 2018
Continuation In Part 15379899 · Dec 15, 2016
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 16709598 · Dec 10, 2019
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62568312 · Oct 4, 2017
Provisional Application 62568305 · Oct 4, 2017
Provisional Application 62568307 · Oct 4, 2017
Provisional Application 62568291 · Oct 4, 2017
Provisional Application 62568298 · Oct 4, 2017
Related Publication 20230208882A1 · Jun 29, 2023
References Cited (48)
US 5950010A · Hesse et al. · 1999 [cited by applicant]
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 6321204B1 · Kazami et al. · 2001 [cited by applicant]
US 7284274B1 · Walls et al. · 2007 [cited by applicant]
US 7657832B1 · Lin · 2010 [cited by applicant]
US 7739653B2 · Venolia · 2010 [cited by applicant]
US 7860842B2 · Bronnikov et al. · 2010 [cited by applicant]
US 7933926B2 · Ebert · 2011 [cited by applicant]
US 8010494B2 · Chandrasekaran et al. · 2011 [cited by applicant]
US 8380843B2 · Loizeaux et al. · 2013 [cited by applicant]
US 8381305B2 · Jacobson · 2013 [cited by applicant]
US 8607197B2 · Barcia et al. · 2013 [cited by applicant]
US 8731954B2 · Heinze et al. · 2014 [cited by applicant]
US 8799225B2 · Vaitzblit et al. · 2014 [cited by applicant]
US 8954925B2 · Dutta et al. · 2015 [cited by applicant]
US 9135286B2 · Sengupta et al. · 2015 [cited by applicant]
US 9143624B2 · Rossi · 2015 [cited by applicant]
US 9286063B2 · Kriegsman et al. · 2016 [cited by applicant]
US 9292695B1 · Bassett · 2016 [cited by applicant]
US 9916133B2 · Jubran et al. · 2018 [cited by applicant]
US 9946740B2 · Athani et al. · 2018 [cited by applicant]
US 10021138B2 · Gill et al. · 2018 [cited by applicant]
US 10180780B2 · Ainalem · 2019 [cited by applicant]
US 10185833B2 · Hale et al. · 2019 [cited by applicant]
US 10200399B2 · Agarwal · 2019 [cited by applicant]
US 10216938B2 · Reith et al. · 2019 [cited by applicant]
US 10318739B2 · Brucker et al. · 2019 [cited by applicant]
US 10360203B2 · Bhatnagar et al. · 2019 [cited by applicant]
US 10637744B2 · Carroll · 2020 [cited by examiner]
US 20040267756A1 · Bayardo et al. · 2004 [cited by applicant]
US 20050060317A1 · Ott et al. · 2005 [cited by applicant]
US 20050289072A1 · Sabharwal · 2005 [cited by applicant]
US 20060149575A1 · Varadarajan et al. · 2006 [cited by applicant]
US 20060288035A1 · Viavant · 2006 [cited by applicant]
US 20070005665A1 · Vaitzblit et al. · 2007 [cited by applicant]
US 20090049094A1 · Howell et al. · 2009 [cited by applicant]
US 20100228835A1 · Pitts · 2010 [cited by applicant]
US 20100275183A1 · Panicker et al. · 2010 [cited by applicant]
US 20120109806A1 · Willard et al. · 2012 [cited by applicant]
US 20120272220A1 · Calcagno et al. · 2012 [cited by applicant]
US 20130014093A1 · Lee · 2013 [cited by applicant]
US 20150124644A1 · Pani · 2015 [cited by applicant]
US 20160162813A1 · Hoffmann et al. · 2016 [cited by applicant]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20190108001A1 · Hauser · 2019 [cited by examiner]
US 20190250893A1 · Pandit · 2019 [cited by examiner]
US 20210374767A1 · Kurian · 2021 [cited by examiner]
US 20220012340A1 · Rao et al. · 2022 [cited by applicant]