IP Library Granted Patent US 12,500,938
Granted Patent B2
US 12,500,938 · App. 18/339,214 · Granted Dec 16, 2025

Dynamic cybersecurity scoring and operational risk reduction assessment

Inventors: Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
H04L63/20G06F16/2477G06F16/951H04L63/1408H04L63/1425H04L63/1441H04L63/0807H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,938
App. No.
18/339,214
Granted
Dec 16, 2025
Kind
B2
Abstract

A system and method for operational and cyber risk assessment that utilizes a data-driven approach to evaluate the current security posture and identify areas for improvement based on the user's desired target profile. This process involves estimating the costs and benefits associated with various security program enhancements, increased, hiring, and control uplifts. The system and method then quantify these benefits in terms of reduction in tail value at risk, expected losses, cyber insurance premiums, and the amount of risk capital set aside. The system simulates attack paths associated with various risk scenarios and uses a risk scenario model to compute losses associated with each attack path for each risk scenario. The results of the simulation may be used to determine one or more business outcomes associated with the costs and benefits of implementing security enhancements.

Claims (60)

1 . A system for operational and cyber risk assessment, comprising:

a hardware processor of a first computing device configured to execute a first plurality of programming instructions stored in a hardware memory of the first computing device, wherein the first plurality of programming instructions, when executed on the hardware processor, cause the first computing device to:

receive a risk scenario of interest;

receive security control data, wherein the security control data is associated with the risk scenario of interest;

use a directed computational graph to retrieve network topology data of a network from at least a subset of a cyber-physical graph comprising nodes and edges, wherein:

the nodes represent hardware, software, and entities in the network, and

the edges represent relationships between the nodes, wherein the relationships are associated with:

business processes that rely on the hardware, software, or entities in the network, and

financial flows that rely on the business processes;

update the risk scenario of interest based on the retrieved network topology data and reconnaissance data obtained from external network scanning;

simulate a plurality of attack paths against the network based on the security control data, the updated risk scenario interest, and the network topology data to determine a key control;

compare predicted vulnerability scores from the simulated plurality of attack paths against actual vulnerability scores to generate a confidence score;

update the risk scenario of interest based on the confidence score; and

generate one or more predicted business outcomes based at least on the key control and the confidence score.

2 . The system of claim 1 , wherein the directed computational graph comprises a second plurality of programming instructions stored in the hardware memory of and operating on the hardware processor of the first computing device, wherein the second plurality of programming instructions, when executed on the hardware processor, cause the first computing device to:

produce a first weighted cybersecurity score based on at least a portion of transformation operations, wherein the first weighted cybersecurity score represents a predicted risk scenario of interest;

simulate a cybersecurity attack against the network based on the weighted cybersecurity score;

produce a second weighted cybersecurity score based on an outcome of the simulated cybersecurity attack, wherein the second weighted cybersecurity score represents an actual vulnerability to a cybersecurity attack of a type that was simulated;

compare the first weighted cybersecurity score against the second weighted cybersecurity score to produce a confidence score, wherein the confidence score represents an accuracy of the predicted risk scenario of interest based on the outcome of the simulated cybersecurity attack; and

update the risk scenario of interest based on the confidence score.

3 . The system of claim 1 , wherein the risk scenario of interest comprises a scenario name, a relative likelihood of occurrence, an expected loss derived based on a severity of a risk event associated with the scenario, and a cause linked to a set of entities, threat actor capabilities, and business systems.

4 . The system of claim 1 , wherein updating the risk scenario of interest comprises computing a total tail value at risk.

5 . The system of claim 1 , wherein the one or more predicted business outcomes is a return on investment.

6 . The system of claim 1 , wherein the one or more predicted business outcomes is an amount of capital that should be set aside to cover expected losses associated with the risk scenario of interest.

7 . The system of claim 1 , wherein the first plurality of programming instructions, when executed on the hardware processor, further cause the first computing device to:

receive a list of real or representative threat actors and associated tactics, techniques, and procedures that are consistent with operational capabilities associated with the threat actors;

update the risk scenario of interest based on the received list;

simulate a plurality of attack paths against the network based on the security control data, a threat actor of interest, the updated risk scenario of interest, and the network topology data to determine the key control; and

generate one or more predicted business outcomes based at least on the key control.

8 . The system of claim 1 , wherein the key control comprises a suggested modification or addition.

9 . The system of claim 1 , wherein the one or more business outcomes is associated with an insurance-linked security.

10 . A method for operational and cyber risk assessment, comprising the steps of:

receiving a risk scenario of interest;

receiving security control data, wherein the security control data is associated with the risk scenario of interest;

using a directed computational graph to retrieve network topology data of a network from at least a subset of a cyber-physical graph comprising nodes and edges, wherein:

the nodes represent hardware, software, and entities in the network, and

the edges represent relationships between the nodes, wherein the relationships are associated with:

business processes that rely on the hardware, software, or entities in the network, and

financial flows that rely on said business processes;

updating the risk scenario of interest based on the retrieved network topology data and reconnaissance data obtained from external network scanning;

simulating a plurality of attack paths against the network based on the security control data, the updated risk scenario of interest, and the network topology data to determine a key control;

comparing predicted vulnerability scores from the simulated plurality of attack paths against actual vulnerability scores to generate a confidence score; and

generating one or more predicted business outcomes based at least on the key control and the confidence score.

11 . The method of claim 10 , further comprising the steps of:

producing a first weighted cybersecurity score based on at least a portion of transformation operations, wherein the first weighted cybersecurity score represents a predicted risk scenario of interest;

simulating a cybersecurity attack against the network based on the weighted cybersecurity score;

producing a second weighted cybersecurity score based on an outcome of the simulated cybersecurity attack, wherein the second weighted cybersecurity score represents an actual vulnerability to a cybersecurity attack of a type that was simulated;

comparing the first weighted cybersecurity score against the second weighted cybersecurity score to produce a confidence score, wherein the confidence score represents an accuracy of the predicted risk scenario of interest based on the outcome of the simulated cybersecurity attack; and

updating the risk scenario of interest based on the confidence score.

12 . The method of claim 10 , wherein the risk scenario of interest comprises a scenario name, a relative likelihood of occurrence, an expected loss derived based on a severity of a risk event associated with the scenario, and a cause linked to a set of entities, threat actor capabilities, and business systems.

13 . The method of claim 10 , wherein updating the risk scenario of interest comprises computing a total tail value at risk.

14 . The method of claim 10 , wherein the one or more predicted business outcomes is a return on investment.

15 . The method of claim 10 , wherein the one or more predicted business outcomes is an amount of capital that should be set aside to cover expected losses associated with the risk scenario of interest.

16 . The method of claim 10 , further comprising the steps of:

receiving a list of real or representative threat actors and associated tactics, techniques, and procedures that are consistent with operational capabilities associated with the threat actors;

updating the risk scenario of interest based on the received list;

simulating a plurality of attack paths against the network based on the security control data, a threat actor of interest, the updated risk scenario of interest, and the network topology data to determine the key control; and

generating one or more predicted business outcomes based at least on the key control.

17 . The method of claim 10 , wherein the key control comprises a suggested modification or addition.

18 . The method of claim 10 , wherein the one or more business outcomes is associated with an insurance-linked security.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY DATA NAME: RICHARD KELLEY PREVIOUSLY RECORDED AT REEL: 064412 FRAME: 0681. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 18, 2024
From: CRABTREE, JASON; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 066343/0792 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2023
From: CRABTREE, JASON; KELLY, RICHARD
To: QOMPLX, INC.
Reel/Frame 064412/0681 →
Continuity (53)
Continuation In Part 18171328 · Feb 18, 2023
Continuation In Part 17162683 · Jan 29, 2021
Continuation 16720383 · Dec 19, 2019
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 17986850 · Nov 14, 2022
Continuation In Part 17567060 · Dec 31, 2021
Continuation In Part 17389863 · Jul 30, 2021
Continuation 16792754 · Feb 17, 2020
Continuation In Part 16779801 · Feb 3, 2020
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation In Part 17170288 · Feb 8, 2021
Continuation In Part 17169924 · Feb 8, 2021
Continuation In Part 15837845 · Dec 11, 2017
Continuation In Part 15825350 · Nov 29, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 17102561 · Nov 24, 2020
Continuation 15790457 · Oct 23, 2017
Continuation In Part 15790327 · Oct 23, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 17105025 · Nov 25, 2020
Continuation 16836717 · Mar 31, 2020
Continuation In Part 15887496 · Feb 2, 2018
Continuation In Part 15823285 · Nov 27, 2017
Continuation In Part 15788718 · Oct 19, 2017
Continuation In Part 15788002 · Oct 19, 2017
Continuation In Part 15787601 · Oct 18, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 16837551 · Apr 1, 2020
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 15818733 · Nov 20, 2017
Provisional Application 62596105 · Dec 7, 2017
Provisional Application 62568291 · Oct 4, 2017
Provisional Application 62568298 · Oct 4, 2017
Provisional Application 62568312 · Oct 4, 2017
Provisional Application 62568305 · Oct 4, 2017
Provisional Application 62568307 · Oct 4, 2017
Related Publication 20230362200A1 · Nov 9, 2023
References Cited (97)
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 6976053B1 · Tripp et al. · 2005 [cited by applicant]
US 7530105B2 · Gilbert et al. · 2009 [cited by applicant]
US 7660815B1 · Scofield et al. · 2010 [cited by applicant]
US 7739653B2 · Venolia · 2010 [cited by applicant]
US 7774335B1 · Scofield et al. · 2010 [cited by applicant]
US 8006303B1 · Dennerline et al. · 2011 [cited by applicant]
US 8281121B2 · Nath et al. · 2012 [cited by applicant]
US 8386519B2 · Kenedy et al. · 2013 [cited by applicant]
US 8539582B1 · Aziz et al. · 2013 [cited by applicant]
US 8583639B2 · Chitnis et al. · 2013 [cited by applicant]
US 8595240B1 · Otey et al. · 2013 [cited by applicant]
US 8615800B2 · Baddour et al. · 2013 [cited by applicant]
US 8677473B2 · Dennerline et al. · 2014 [cited by applicant]
US 8725597B2 · Mauseth et al. · 2014 [cited by applicant]
US 8726393B2 · Macy et al. · 2014 [cited by applicant]
US 8793758B2 · Raleigh et al. · 2014 [cited by applicant]
US 8806361B1 · Noel et al. · 2014 [cited by applicant]
US 8826426B1 · Dubey · 2014 [cited by applicant]
US 8914878B2 · Burns et al. · 2014 [cited by applicant]
US 9031870B2 · Kenedy et al. · 2015 [cited by applicant]
US 9141360B1 · Chen et al. · 2015 [cited by applicant]
US 9210185B1 · Wood et al. · 2015 [cited by applicant]
US 9231962B1 · Yen et al. · 2016 [cited by applicant]
US 9235732B2 · Eynon et al. · 2016 [cited by applicant]
US 9256735B2 · Stute · 2016 [cited by applicant]
US 9319430B2 · Bell, Jr. et al. · 2016 [cited by applicant]
US 9560065B2 · Neil et al. · 2017 [cited by applicant]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9654495B2 · Hubbard et al. · 2017 [cited by applicant]
US 9672355B2 · Titonis et al. · 2017 [cited by applicant]
US 9674211B2 · Curcic et al. · 2017 [cited by applicant]
US 9686308B1 · Srivastava · 2017 [cited by applicant]
US 9712553B2 · Nguyen et al. · 2017 [cited by applicant]
US 9762443B2 · Dickey · 2017 [cited by applicant]
US 9887933B2 · Lawrence, III · 2018 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10320828B1 · Derbeko et al. · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 10642995B2 · Shih et al. · 2020 [cited by applicant]
US 11140196B1 · Bilge et al. · 2021 [cited by applicant]
US 11176251B1 · Plantenga et al. · 2021 [cited by applicant]
US 20050289072A1 · Sabharwal · 2005 [cited by applicant]
US 20070226796A1 · Gilbert et al. · 2007 [cited by applicant]
US 20080010683A1 · Baddour et al. · 2008 [cited by applicant]
US 20080126408A1 · Middleton · 2008 [cited by applicant]
US 20080133540A1 · Hubbard et al. · 2008 [cited by applicant]
US 20080270203A1 · Holmes et al. · 2008 [cited by applicant]
US 20090293128A1 · Lippmann et al. · 2009 [cited by applicant]
US 20100125900A1 · Dennerline et al. · 2010 [cited by applicant]
US 20100281539A1 · Burns et al. · 2010 [cited by applicant]
US 20110313956A1 · Abe et al. · 2011 [cited by applicant]
US 20120197911A1 · Banka et al. · 2012 [cited by applicant]
US 20130097706A1 · Titonis et al. · 2013 [cited by applicant]
US 20130103657A1 · Ikawa et al. · 2013 [cited by applicant]
US 20130191416A1 · Lee et al. · 2013 [cited by applicant]
US 20130212638A1 · Wilson · 2013 [cited by applicant]
US 20130304623A1 · Kumar et al. · 2013 [cited by applicant]
US 20140074850A1 · Noel et al. · 2014 [cited by applicant]
US 20140082730A1 · Vashist et al. · 2014 [cited by applicant]
US 20140101763A1 · Harlacher et al. · 2014 [cited by applicant]
US 20140230060A1 · Higbee · 2014 [cited by examiner]
US 20140244612A1 · Bhasin et al. · 2014 [cited by applicant]
US 20150020199A1 · Neil et al. · 2015 [cited by applicant]
US 20150033341A1 · Schmidtler et al. · 2015 [cited by applicant]
US 20150180891A1 · Seward et al. · 2015 [cited by applicant]
US 20150213631A1 · Broek · 2015 [cited by applicant]
US 20150215332A1 · Curcic et al. · 2015 [cited by applicant]
US 20150236935A1 · Bassett · 2015 [cited by applicant]
US 20150295766A1 · Dickey · 2015 [cited by applicant]
US 20150295775A1 · Dickey · 2015 [cited by applicant]
US 20150310195A1 · Bailor et al. · 2015 [cited by applicant]
US 20150347414A1 · Xiao et al. · 2015 [cited by applicant]
US 20150347523A1 · Patel et al. · 2015 [cited by applicant]
US 20150363840A1 · Gupta et al. · 2015 [cited by applicant]
US 20150365437A1 · Bell, Jr. et al. · 2015 [cited by applicant]
US 20150381649A1 · Schultz · 2015 [cited by examiner]
US 20160004858A1 · Chen et al. · 2016 [cited by applicant]
US 20160012235A1 · Lee · 2016 [cited by examiner]
US 20160044057A1 · Chenette · 2016 [cited by examiner]
US 20160099960A1 · Gerritz et al. · 2016 [cited by applicant]
US 20160105454A1 · Li et al. · 2016 [cited by applicant]
US 20160127262A1 · Lawrence, III · 2016 [cited by applicant]
US 20160140519A1 · Trepca et al. · 2016 [cited by applicant]
US 20160162543A1 · Gustafson et al. · 2016 [cited by applicant]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20160301709A1 · Hassanzadeh · 2016 [cited by examiner]
US 20160306806A1 · Fackler et al. · 2016 [cited by applicant]
US 20160350442A1 · Crosby · 2016 [cited by applicant]
US 20170063896A1 · Muddu et al. · 2017 [cited by applicant]
US 20170134418A1 · Minoli et al. · 2017 [cited by applicant]
US 20180197128A1 · Carstens et al. · 2018 [cited by applicant]
US 20210297452A1 · Crabtree et al. · 2021 [cited by applicant]
US 20220006830A1 · Wescoe · 2022 [cited by applicant]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]