IP Library Granted Patent US 12,506,754
Granted Patent B2
US 12,506,754 · App. 18/361,829 · Granted Dec 23, 2025

System and methods for cybersecurity analysis using UEBA and network topology data and trigger-based network remediation

Inventors: Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,754
App. No.
18/361,829
Granted
Dec 23, 2025
Kind
B2
Abstract

A system and method for network cybersecurity analysis that uses user and entity behavioral analysis combined with network topology information and trigger-based network remediation to provide improved cybersecurity. The system and method involve gathering network entity information, establishing baseline behaviors for each entity, and monitoring each entity for behavioral anomalies that might indicate cybersecurity concerns. Further, the system and method involve incorporating network topology information into the analysis by generating a model of the network, annotating the model with risk and criticality information for each entity in the model and with a vulnerability level between entities, and using the model to evaluate cybersecurity risks to the network. Triggers may be based on risks or anomalous behavior and associated with a remediation action executed on the network by a security mitigation engine. The system and method may also dynamically adjust monitoring characteristics based on trigger events.

Claims (61)

1 . A system for cybersecurity analysis using user and entity behavioral analysis (UEBA) with trigger-based network remediation, comprising:

a computing device comprising a memory, a processor, and a plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the plurality of programming instructions, when operating on the processor, cause the computing device to:

maintain a directed graph in the memory of the computing device, wherein the directed graph represents one or more predefined or system-defined groups within a computing network, and wherein the directed graph comprises: a plurality of nodes representing entities of the computing network, and a plurality of edges representing a directional relationship between one or more of the entities of the computing network;

perform network segmentation to represent the entities of the computing network in the directed graph, wherein performing network segmentation comprises:

assigning one or more of the entities of the computing network to logical segments representing the pre-defined or system-defined groups based on one or more properties of the entities; and

representing all entities assigned to a respective logical segment as a single entity in the directed graph;

monitor activity of a plurality of the entities based on one or more monitoring characteristics, wherein the monitoring characteristics used to monitor the activity of the plurality of the entities are selected based on one or more of the assigned logical segments of the monitored entity;

establish behavioral baseline data for each of the monitored entities from the monitored activity over a defined period of time;

receive an indication of a trigger event;

adjust one or more of the monitoring characteristics for one or more of the monitored entities based on the trigger event;

identify anomalous behavior of an entity of the monitored entities by comparing the monitored activity for said monitored entity to the behavioral baseline data for said monitored entity; and

calculate a risk of the anomalous behavior using one or more edges of the directed graph to determine a relationship between said monitored entity and one or more of the logical segments and their assigned entities;

in response to receipt of the indication of the trigger event, use a machine-learning algorithm or a rules-based algorithm to determine a sequence of actions to perform on one or more of the entities based on the calculated risk and one or more of the assigned logical segments of said entities; and

automatically execute the determined sequence of actions on one or more of the entities.

2 . The system of claim 1 , wherein the characteristics of how the directed graph is maintained is based on the trigger event and the one or more monitoring characteristics.

3 . The system of claim 1 , wherein the trigger event is associated with a detected anomaly, a detected deviation, or a specific pattern that differs from the behavioral baseline data.

4 . The system of claim 1 , wherein the monitoring characteristics include an amount of monitoring, a level of monitoring, a time period of monitoring, or a type of monitoring.

5 . The system of claim 1 , wherein the plurality of programming instructions, when operating on the processor, further cause the computing device to:

upon execution of the determined sequence of actions:

monitor the computing network to determine an effect of the sequence of actions on the computing network;

update the sequence of actions based on the determined effect; and

automatically execute the updated sequence of actions on one or more of the entities.

6 . The system of claim 1 , wherein the determined sequence of actions includes a remediation action.

7 . The system of claim 1 , wherein the plurality of programming instructions, when operating on the processor, further cause the computing device to:

upon execution of the determined sequence of actions:

continue to monitor the activity of the plurality of the entities based on the adjusted monitoring characteristics; and

update the behavioral baseline data for each of the monitored entities from the monitored activity.

8 . The system of claim 1 further comprising:

reconfiguring one or more of the logical segments of the directed graph stored in the memory of the computing device based on the trigger event.

9 . The system of claim 1 , wherein the plurality of programming instructions, when operating on the processor, further cause the computing device to generate one or more scores for each of the monitored entities, wherein the one or more scores are associated with one or more nodes or edges of the directed graph.

10 . The system of claim 9 , wherein the trigger event is based on the one or more scores.

11 . A method for cybersecurity analysis using user and entity behavioral analysis (UEBA) with trigger-based network remediation, comprising the steps of:

maintain a directed graph in a memory of a computing device, wherein the directed graph represents one or more predefined or system-defined groups within a computing network, and wherein the directed graph comprises: a plurality of nodes representing entities of the computing network, and a plurality of edges representing a directional relationship between one or more of the entities of the computing network;

performing network segmentation to represent the entities of the computing network in the directed graph, wherein performing network segmentation comprises:

assigning one or more of the entities of the computing network to logical segments representing the pre-defined or system-defined groups based on one or more properties of the entities; and

representing all entities assigned to a respective logical segment as a single entity in the directed graph;

monitoring activity of a plurality of the entities based on one or more monitoring characteristics, wherein the monitoring characteristics used to monitor the activity of the plurality of the entities are selected based on one or more of the assigned logical segments of the monitored entity;

establishing behavioral baseline data for each of the monitored entities from the monitored activity over a defined period of time;

receiving an indication of a trigger event;

adjusting one or more of the monitoring characteristics for one or more of the monitored entities based on the trigger event;

identifying anomalous behavior of an entity of the monitored entities by comparing the monitored activity for said monitored entity to the behavioral baseline data for said monitored entity; and

calculating a risk of the anomalous behavior using one or more edges of the directed graph to determine a relationship between said monitored entity and one or more of the logical segments and their assigned entities;

in response to receipt of the indication of the trigger event, using a machine-learning algorithm or a rules-based algorithm to determine a sequence of actions to perform on one or more of the entities based on the calculated risk and one or more of the assigned logical segments of said entities; and

automatically executing the determined sequence of actions on one or more of the entities.

12 . The method of claim 11 , wherein the characteristics of how the directed graph is maintained is based on the trigger event and the one or more monitoring characteristics.

13 . The method of claim 11 , wherein the trigger event is associated with a detected anomaly, a detected deviation, or a specific pattern that differs from the behavioral baseline data.

14 . The method of claim 11 , wherein the monitoring characteristics include an amount of monitoring, a level of monitoring, a time period of monitoring, or a type of monitoring.

15 . The method of claim 12 , further comprising the steps of:

upon execution of the determined sequence of actions:

monitoring the computing network to determine an effect of the sequence of actions on the computing network;

updating the sequence of actions based on the determined effect; and

automatically executing the updated sequence of actions on one or more of the entities.

16 . The method of claim 11 , wherein the determined sequence of actions includes a remediation action.

17 . The method of claim 11 , further comprising the steps of:

upon execution of the determined sequence of actions:

continuing to monitor the activity of the plurality of the entities based on the adjusted monitoring characteristics; and

updating the behavioral baseline data for each of the monitored entities from the monitored activity.

18 . The method of claim 11 further comprising the step of:

reconfiguring one or more of the logical segments of the directed graph stored in the memory of a computing device based on the trigger event.

19 . The method of claim 11 , further comprising the step of generating one or more scores for each of the monitored entities, wherein the one or more scores are associated with one or more nodes or edges of the directed graph.

20 . The method of claim 19 , wherein the trigger event is based on the one or more scores.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE SECOND INVENTOR'S LAST NAME PREVIOUSLY RECORDED AT REEL: 66428 FRAME: 824. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 22, 2024
From: CRABTREE, JASON; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 067504/0520 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2023
From: CRABTREE, JASON; KELLY, RICHARD
To: QOMPLX, INC.
Reel/Frame 064428/0824 →
Continuity (16)
Continuation In Part 17390889 · Jul 31, 2021
Continuation In Part 16807007 · Mar 2, 2020
Continuation In Part 15825350 · Nov 29, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Related Publication 20230412620A1 · Dec 21, 2023
References Cited (104)
US 5669000A · Jessen et al. · 1997 [cited by applicant]
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 6477572B1 · Elderton et al. · 2002 [cited by applicant]
US 7072863B1 · Phillips et al. · 2006 [cited by applicant]
US 7657406B2 · Tolone et al. · 2010 [cited by applicant]
US 7698213B2 · Lancaster · 2010 [cited by applicant]
US 7739653B2 · Venolia · 2010 [cited by applicant]
US 8065257B2 · Kuecuekyan · 2011 [cited by applicant]
US 8145761B2 · Liu et al. · 2012 [cited by applicant]
US 8281121B2 · Nath et al. · 2012 [cited by applicant]
US 8615800B2 · Baddour et al. · 2013 [cited by applicant]
US 8788306B2 · Delurgio et al. · 2014 [cited by applicant]
US 8793758B2 · Raleigh et al. · 2014 [cited by applicant]
US 8914878B2 · Burns et al. · 2014 [cited by applicant]
US 8997233B2 · Green et al. · 2015 [cited by applicant]
US 9134966B2 · Brock et al. · 2015 [cited by applicant]
US 9141360B1 · Chen et al. · 2015 [cited by applicant]
US 9231962B1 · Yen et al. · 2016 [cited by applicant]
US 9294497B1 · Ben-Or et al. · 2016 [cited by applicant]
US 9306965B1 · Grossman et al. · 2016 [cited by applicant]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9654495B2 · Hubbard et al. · 2017 [cited by applicant]
US 9672355B2 · Titonis et al. · 2017 [cited by applicant]
US 9686308B1 · Srivastava · 2017 [cited by applicant]
US 9762443B2 · Dickey · 2017 [cited by applicant]
US 9887933B2 · Lawrence, III · 2018 [cited by applicant]
US 9946517B2 · Talby et al. · 2018 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10102480B2 · Dirac et al. · 2018 [cited by applicant]
US 10210246B2 · Stojanovic et al. · 2019 [cited by applicant]
US 10210255B2 · Crabtree et al. · 2019 [cited by applicant]
US 10242406B2 · Kumar et al. · 2019 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10318882B2 · Brueckner et al. · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 10511498B1 · Narayan et al. · 2019 [cited by applicant]
US 20030041254A1 · Challener et al. · 2003 [cited by applicant]
US 20030145225A1 · Bruton et al. · 2003 [cited by applicant]
US 20040098610A1 · Hrastar · 2004 [cited by applicant]
US 20050289072A1 · Sabharwal · 2005 [cited by applicant]
US 20060149575A1 · Varadarajan et al. · 2006 [cited by applicant]
US 20070150744A1 · Cheng et al. · 2007 [cited by applicant]
US 20090012760A1 · Schunemann · 2009 [cited by applicant]
US 20090064088A1 · Barcia et al. · 2009 [cited by applicant]
US 20090089227A1 · Sturrock et al. · 2009 [cited by applicant]
US 20090182672A1 · Doyle · 2009 [cited by applicant]
US 20090222562A1 · Liu et al. · 2009 [cited by applicant]
US 20090293128A1 · Lippmann et al. · 2009 [cited by applicant]
US 20110060821A1 · Loizeaux et al. · 2011 [cited by applicant]
US 20110087888A1 · Rennie · 2011 [cited by applicant]
US 20110154341A1 · Pueyo et al. · 2011 [cited by applicant]
US 20120266244A1 · Green et al. · 2012 [cited by applicant]
US 20130073062A1 · Smith et al. · 2013 [cited by applicant]
US 20130132149A1 · Wei et al. · 2013 [cited by applicant]
US 20130191416A1 · Lee et al. · 2013 [cited by applicant]
US 20130246996A1 · Duggal et al. · 2013 [cited by applicant]
US 20130304623A1 · Kumar et al. · 2013 [cited by applicant]
US 20140074826A1 · Cooper et al. · 2014 [cited by applicant]
US 20140156806A1 · Karpistsenko et al. · 2014 [cited by applicant]
US 20140244612A1 · Bhasin et al. · 2014 [cited by applicant]
US 20140245443A1 · Chakraborty · 2014 [cited by applicant]
US 20140279762A1 · Xaypanya et al. · 2014 [cited by applicant]
US 20150095303A1 · Sonmez et al. · 2015 [cited by applicant]
US 20150149979A1 · Talby et al. · 2015 [cited by applicant]
US 20150163242A1 · Laidlaw et al. · 2015 [cited by applicant]
US 20150169294A1 · Brock et al. · 2015 [cited by applicant]
US 20150195192A1 · Vasseur et al. · 2015 [cited by applicant]
US 20150236935A1 · Bassett · 2015 [cited by applicant]
US 20150281225A1 · Schoen et al. · 2015 [cited by applicant]
US 20150317481A1 · Gardner et al. · 2015 [cited by applicant]
US 20150339263A1 · Ata et al. · 2015 [cited by applicant]
US 20150347414A1 · Xiao et al. · 2015 [cited by applicant]
US 20150379424A1 · Dirac et al. · 2015 [cited by applicant]
US 20160004858A1 · Chen et al. · 2016 [cited by applicant]
US 20160028758A1 · Ellis et al. · 2016 [cited by applicant]
US 20160072845A1 · Chiviendacz et al. · 2016 [cited by applicant]
US 20160078361A1 · Brueckner et al. · 2016 [cited by applicant]
US 20160099960A1 · Gerritz et al. · 2016 [cited by applicant]
US 20160105454A1 · Li et al. · 2016 [cited by applicant]
US 20160140519A1 · Trepca et al. · 2016 [cited by applicant]
US 20160212171A1 · Senanayake et al. · 2016 [cited by applicant]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20160285732A1 · Brech et al. · 2016 [cited by applicant]
US 20160342606A1 · Mouel et al. · 2016 [cited by applicant]
US 20160350442A1 · Crosby · 2016 [cited by applicant]
US 20160364307A1 · Garg et al. · 2016 [cited by applicant]
US 20170013003A1 · Samuni et al. · 2017 [cited by applicant]
US 20170019678A1 · Kim et al. · 2017 [cited by applicant]
US 20170063896A1 · Muddu et al. · 2017 [cited by applicant]
US 20170083380A1 · Bishop et al. · 2017 [cited by applicant]
US 20170126712A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170139763A1 · Ellwein · 2017 [cited by applicant]
US 20170149802A1 · Huang et al. · 2017 [cited by applicant]
US 20170193110A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170206360A1 · Brucker et al. · 2017 [cited by applicant]
US 20170322959A1 · Tidwell et al. · 2017 [cited by applicant]
US 20170323089A1 · Duggal et al. · 2017 [cited by applicant]
US 20170339168A1 · Balabine · 2017 [cited by examiner]
US 20180197128A1 · Carstens et al. · 2018 [cited by applicant]
US 20180300930A1 · Kennedy et al. · 2018 [cited by applicant]
US 20190082305A1 · Proctor · 2019 [cited by applicant]
US 20190095533A1 · Levine et al. · 2019 [cited by applicant]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]