IP Library Granted Patent US 12,500,920
Granted Patent B2
US 12,500,920 · App. 18/358,005 · Granted Dec 16, 2025

Computer-implemented system and method for cybersecurity threat analysis using federated machine learning and hierarchical task networks

Inventors: Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
H04L63/1433H04L63/102H04L63/1416H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,920
App. No.
18/358,005
Granted
Dec 16, 2025
Kind
B2
Abstract

A system and method for cyber exploitation path analysis and response using federated networks to minimize network exposure and maximize network resilience, with the ability to simulate complex and large scale network traffic through the use of federated training networks, by gathering network entity information, establishing baseline behaviors for each entity, and monitoring each entity for behavioral anomalies that might indicate cybersecurity concerns. Further, the system and method involve incorporating network topology information into the analysis by generating a model of the network, annotating the model with risk and criticality information for each entity in the model and with a vulnerability level between entities, and using the model to evaluate cybersecurity risks to the network. Lastly, network attack path analysis and automated task planning for minimizing network exposure and maximizing resiliency is performed with machine learning, generative adversarial networks, hierarchical task networks, and Monte Carlo search trees.

Claims (40)

1 . A system for cyber exploitation path analysis and response using federated networks, comprising:

a computing device comprising a memory and a processor;

a directed graph stored in the memory of the computing device, the directed graph comprising a representation of a computer network wherein:

nodes of the directed graph represent entities comprising the computer network; and

edges of the directed graph represent relationships between the entities of the computer network;

a machine learning engine comprising a plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the machine learning engine comprises multiple distributed generator instances operating as separate federated processes with independent neural network parameters and communicating through high level architecture (HLA) protocols, wherein the plurality of programming instructions, when operating on the processor, cause the computing device to:

receive information about a topology and setup of a network of entities, from the directed graph;

simulate fake computer network traffic through coordinated operation of the multiple distributed generator instances using runtime infrastructure (RTI) for inter-federated communication;

use machine learning techniques including neural networks to attempt to classify computer network traffic either as legitimate or as simulated fake computer network traffic; and

a hierarchical task network engine comprising a plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the plurality of programming instructions, when operating on the processor, cause the computing device to:

receive information about the topology and setup of the network of entities, from the directed graph;

receive information about simulated fake computer network traffic from a machine learning engine comprising the multiple distributed generator instances with independent neural network parameters; and

create an automated task plan for minimizing network exposure and maximizing network resilience against simulated fake network traffic generated by the coordinated multiple distributed generator instances operating through the HLA protocols and the RTI infrastructure.

2 . The system of claim 1 , further comprising a generative adversarial network engine, wherein the generative adversarial network engine is used to optimize the automated task plan created by a hierarchical task network engine.

3 . The system of claim 2 , wherein the generative adversarial network engine:

has multiple generators distributed across multiple software instances, called federates; and

wherein each federate may have different neural network structures or hyperparameters.

4 . A method for cyber exploitation path analysis and response using federated networks, comprising the steps of:

storing a directed graph in the memory of a computing device, the directed graph comprising a representation of a computer network wherein:

nodes of the directed graph represent entities comprising the computer network; and

edges of the directed graph represent relationships between the entities of the computer network;

receiving information about a topology and setup of a network of entities, from the directed graph, using a machine learning engine comprising multiple distributed generator instances operating as separate federated processes with independent neural network parameters and communicating through high level architecture (HLA) protocols;

simulating fake computer network traffic, using a machine learning engine through coordinated operation of the multiple distributed generator instances using runtime infrastructure (RTI) for inter-federated communication;

using machine learning techniques including neural networks to attempt to classify computer network traffic either as legitimate or as simulated fake computer network traffic, using a machine learning engine;

receiving information about the topology and setup of the network of entities, from the directed graph, using a hierarchical task network engine;

receiving information about simulated fake computer network traffic from a machine learning engine comprising the multiple distributed generator instances with independent neural network parameters, using a hierarchical task network engine; and

creating an automated task plan for minimizing network exposure and maximizing network resilience against simulated fake network traffic generated by the coordinated multiple distributed generator instances operating through the HLA protocols and the RTI infrastructure, using a hierarchical task network engine.

5 . The method of claim 4 , further comprising the step of optimizing the automated task plan created by a hierarchical task network engine, using a generative adversarial network engine.

6 . The method of claim 5 , wherein the generative adversarial network engine:

has multiple generators distributed across multiple software instances, called federates; and

wherein each federate may have different neural network structures or hyperparameters.

7 . The system of claim 1 , wherein each of the multiple distributed generators operates as a separate federate process with independent neural network parameters.

8 . The system of claim 1 , wherein the multiple distributed generators communicate through high level architecture (HLA) protocols.

9 . The system of claim 2 , wherein the generative adversarial network engine coordinates the multiple generators through a runtime infrastructure (RTI) to simulate coordinated multi-vector network attacks.

10 . A method for cyber exploitation path analysis and response using federated networks, comprising:

receiving network topology information from a directed graph representation;

deploying multiple distributed generator federates for simulating fake network traffic;

coordinating the multiple generator federates to generate diverse attack scenarios;

classifying network traffic using machine learning; and

generating automated task plans for network defense.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE SECOND INVENTOR'S NAME PREVIOUSLY RECORDED AT REEL: 64412 FRAME: 731. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 22, 2024
From: CRABTREE, JASON; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 067504/0093 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2023
From: CRABTREE, JASON; KELLY, RICHARD
To: QOMPLX, INC.
Reel/Frame 064412/0731 →
Continuity (18)
Continuation In Part 18354651 · Jul 19, 2023
Continuation In Part 18186117 · Mar 17, 2023
Continuation 17363222 · Jun 30, 2021
Continuation 16807007 · Mar 2, 2020
Continuation In Part 15825350 · Nov 29, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Related Publication 20230370491A1 · Nov 16, 2023
References Cited (113)
US 5669000A · Jessen et al. · 1997 [cited by applicant]
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 6477572B1 · Elderton et al. · 2002 [cited by applicant]
US 7072863B1 · Phillips et al. · 2006 [cited by applicant]
US 7657406B2 · Tolone et al. · 2010 [cited by applicant]
US 7698213B2 · Lancaster · 2010 [cited by applicant]
US 7739653B2 · Venolia · 2010 [cited by applicant]
US 8065257B2 · Kuecuekyan · 2011 [cited by applicant]
US 8145761B2 · Liu et al. · 2012 [cited by applicant]
US 8281121B2 · Nath et al. · 2012 [cited by applicant]
US 8615800B2 · Baddour et al. · 2013 [cited by applicant]
US 8788306B2 · Delurgio et al. · 2014 [cited by applicant]
US 8793758B2 · Raleigh et al. · 2014 [cited by applicant]
US 8881288B1 · Levy et al. · 2014 [cited by applicant]
US 8914878B2 · Burns et al. · 2014 [cited by applicant]
US 8997233B2 · Green et al. · 2015 [cited by applicant]
US 9134966B2 · Brock et al. · 2015 [cited by applicant]
US 9141360B1 · Chen et al. · 2015 [cited by applicant]
US 9231962B1 · Yen et al. · 2016 [cited by applicant]
US 9294497B1 · Ben-Or et al. · 2016 [cited by applicant]
US 9306965B1 · Grossman et al. · 2016 [cited by applicant]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9654495B2 · Hubbard et al. · 2017 [cited by applicant]
US 9672355B2 · Titonis et al. · 2017 [cited by applicant]
US 9686308B1 · Srivastava · 2017 [cited by applicant]
US 9762443B2 · Dickey · 2017 [cited by applicant]
US 9887933B2 · Lawrence, III · 2018 [cited by applicant]
US 9946517B2 · Talby et al. · 2018 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10102480B2 · Dirac et al. · 2018 [cited by applicant]
US 10210246B2 · Stojanovic et al. · 2019 [cited by applicant]
US 10210255B2 · Crabtree et al. · 2019 [cited by applicant]
US 10242406B2 · Kumar et al. · 2019 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10318882B2 · Brueckner et al. · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 10511498B1 · Narayan et al. · 2019 [cited by applicant]
US 11228616B2 · Khan et al. · 2022 [cited by applicant]
US 20030041254A1 · Challener et al. · 2003 [cited by applicant]
US 20030145225A1 · Bruton et al. · 2003 [cited by applicant]
US 20040098610A1 · Hrastar · 2004 [cited by applicant]
US 20050289072A1 · Sabharwal · 2005 [cited by applicant]
US 20060149575A1 · Varadarajan et al. · 2006 [cited by applicant]
US 20070150744A1 · Cheng et al. · 2007 [cited by applicant]
US 20090012760A1 · Schunemann · 2009 [cited by applicant]
US 20090064088A1 · Barcia et al. · 2009 [cited by applicant]
US 20090089227A1 · Sturrock et al. · 2009 [cited by applicant]
US 20090182672A1 · Doyle · 2009 [cited by applicant]
US 20090222562A1 · Liu et al. · 2009 [cited by applicant]
US 20090293128A1 · Lippmann et al. · 2009 [cited by applicant]
US 20110060821A1 · Loizeaux et al. · 2011 [cited by applicant]
US 20110087888A1 · Rennie · 2011 [cited by applicant]
US 20110154341A1 · Pueyo et al. · 2011 [cited by applicant]
US 20120266244A1 · Green et al. · 2012 [cited by applicant]
US 20130073062A1 · Smith et al. · 2013 [cited by applicant]
US 20130132149A1 · Wei et al. · 2013 [cited by applicant]
US 20130191416A1 · Lee et al. · 2013 [cited by applicant]
US 20130246996A1 · Duggal et al. · 2013 [cited by applicant]
US 20130304623A1 · Kumar et al. · 2013 [cited by applicant]
US 20140156806A1 · Karpistsenko et al. · 2014 [cited by applicant]
US 20140244612A1 · Bhasin et al. · 2014 [cited by applicant]
US 20140279762A1 · Xaypanya et al. · 2014 [cited by applicant]
US 20150149979A1 · Talby et al. · 2015 [cited by applicant]
US 20150163242A1 · Laidlaw et al. · 2015 [cited by applicant]
US 20150169294A1 · Brock et al. · 2015 [cited by applicant]
US 20150195192A1 · Vasseur et al. · 2015 [cited by applicant]
US 20150236935A1 · Bassett · 2015 [cited by applicant]
US 20150281225A1 · Schoen et al. · 2015 [cited by applicant]
US 20150317481A1 · Gardner et al. · 2015 [cited by applicant]
US 20150339263A1 · Ata et al. · 2015 [cited by applicant]
US 20150347414A1 · Xiao et al. · 2015 [cited by applicant]
US 20150379424A1 · Dirac et al. · 2015 [cited by applicant]
US 20160004858A1 · Chen et al. · 2016 [cited by applicant]
US 20160028758A1 · Ellis et al. · 2016 [cited by applicant]
US 20160044054A1 · Stiansen · 2016 [cited by examiner]
US 20160072845A1 · Chiviendacz et al. · 2016 [cited by applicant]
US 20160078361A1 · Brueckner et al. · 2016 [cited by applicant]
US 20160099960A1 · Gerritz et al. · 2016 [cited by applicant]
US 20160105454A1 · Li et al. · 2016 [cited by applicant]
US 20160140519A1 · Trepca et al. · 2016 [cited by applicant]
US 20160171415A1 · Yampolskiy et al. · 2016 [cited by applicant]
US 20160212171A1 · Senanayake et al. · 2016 [cited by applicant]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20160285732A1 · Brech et al. · 2016 [cited by applicant]
US 20160342606A1 · Mouel et al. · 2016 [cited by applicant]
US 20160350442A1 · Crosby · 2016 [cited by applicant]
US 20160364307A1 · Garg et al. · 2016 [cited by applicant]
US 20170019678A1 · Kim et al. · 2017 [cited by applicant]
US 20170063896A1 · Muddu et al. · 2017 [cited by applicant]
US 20170083380A1 · Bishop et al. · 2017 [cited by applicant]
US 20170126712A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170139763A1 · Ellwein · 2017 [cited by applicant]
US 20170149802A1 · Huang et al. · 2017 [cited by applicant]
US 20170193110A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170206360A1 · Brucker et al. · 2017 [cited by applicant]
US 20170322959A1 · Tidwell et al. · 2017 [cited by applicant]
US 20170323089A1 · Duggal et al. · 2017 [cited by applicant]
US 20180197128A1 · Carstens et al. · 2018 [cited by applicant]
US 20180300930A1 · Kennedy et al. · 2018 [cited by applicant]
US 20190082305A1 · Proctor · 2019 [cited by applicant]
US 20190095533A1 · Levine et al. · 2019 [cited by applicant]
US 20210256115A1 · Shashanka et al. · 2021 [cited by applicant]
US 20220374515A1 · Bridges et al. · 2022 [cited by applicant]
EP 3655878A1 · 2020 [cited by applicant]
EP 3985576 · 2022 [cited by applicant]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]
WO 2022047415A1 · 2022 [cited by applicant]
WO WO2022165143A1 · 2022 [cited by examiner]
WO 2023091753A1 · 2023 [cited by applicant]
WO WO2024092323A1 · 2024 [cited by examiner]
Rodriguez, Eva et al., “A Survey of Deep Learning Techniques for Cybersecurity in Mobile Networks”, Third Quarter 2021, IEEE Communications Surveys & Tutorials; vol. 23, Issue 3, pp. 1920-1955, ISSN: 1553-877X CD: 2373-… [cited by applicant]
Shaukat, Kamran et al., “A Survey on Machine Learning Techniques for Cyber Security in the Last Decade”, Dec. 2, 2020, IEEE Access vol. 8, pp. 222310-222354. [cited by applicant]
Cited By (1)
US 12,688,277