IP Library Granted Patent US 12,267,347
Granted Patent B2
US 12,267,347 · App. 18/460,667 · Granted Apr 1, 2025

System and method for comprehensive data loss prevention and compliance management

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/1425H04L43/045H04L43/08H04L63/1433G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,347
App. No.
18/460,667
Granted
Apr 1, 2025
Kind
B2
Abstract

A system and method to identify and prevent cybersecurity attacks on modern, highly-interconnected networks, to identify attacks before data loss occurs, using a combination of human level, device level, system level, and organizational level monitoring.

Claims (47)

1. A system for comprehensive data loss prevention and compliance management, comprising:

a computing system comprising a processor and a memory;

an observation and state estimation subsystem comprising a first plurality of programming instructions stored in the memory and operating on the processor, wherein the first plurality of programming instructions, when operating on the processor, cause the computing system to:

produce a cyber-physical graph representing a plurality of connected resources on a network, wherein:

the connected resources comprise one or more of people, devices, systems, and organizations within the network;

the cyber-physical graph comprises nodes representing the connected resources, with each node having one or more properties associated with the connected resource represented by that node;

the cyber-physical graph comprises edges representing logical or physical relationships between pairs of the connected resources; and

the cyber-physical graph includes information about sensitive data stored on one or more of the connected resources; and

an activity monitoring subsystem comprising a second plurality of programming instructions stored in the memory and operating on the processor, wherein the second plurality of programming instructions, when operating on the processor, cause the computing system to:

collect data from a plurality of sources within the network, wherein the plurality of sources includes one or more of: system endpoints, infrastructure servers, perimeter security devices, and network security monitoring tools;

analyze the collected data to identify sensitive data stored on one or more of the connected resources;

update the cyber-physical graph to include information about the identified sensitive data and its location; and

generate expected behavior data of at least some of the plurality of connected resources on the network by applying a behavioral model to nodes of the cyber-physical graph;

generate actual behavior data of at least some of the plurality of connected resources on the network from time-series data comprising a record of network events and the respective times at which each network event occurred;

detect a deviation between the actual behavior data and the expected behavior data for a first node by comparing properties of the expected behavior data of the first node with properties of the actual behavior data of the first node;

when a deviation is detected, transmit data relevant to the deviation to a risk analysis and scoring subsystem; and

the risk analysis and scoring subsystem comprising a third plurality of programming instructions stored in the memory and operating on the processor, wherein the third plurality of programming instructions, when operating on the processor, cause the computing system to:

receive data relevant to the deviation;

analyze severity of a threat posed by the deviation using at least one analysis algorithm; and

generate a risk score based on a plurality of factors that indicate the severity of the threat.

2. The system of claim 1 , wherein the risk analysis and scoring subsystem further generates an impact assessment score for each affected connected resource by determining an impact on the network using the cyber-physical graph.

3. The system of claim 2 , wherein the impact assessment score further comprises the calculation of the overall impact of a cyberattack, wherein the calculation is based at least in part on the impact assessment score for each connected resource affected by the cyberattack.

4. The system of claim 1 , wherein the detection of deviations is based in part on a comparison of relationships between the connected resources against known security vulnerabilities.

5. The system of claim 4 , wherein the risk score is based at least in part on the results of the comparison against known security vulnerabilities.

6. The system of claim 1 , wherein the observation and state estimation subsystem is further configured to produce a visualization based at least in part on at least a portion of the time-series data, wherein the visualization illustrates changes to the time-series data over time.

7. A method for comprehensive data loss prevention and compliance management, comprising the steps of:

monitoring a plurality of connected resources on a network;

producing a cyber-physical graph representing the plurality of connected resources, wherein:

the connected resources comprise one or more of people, devices, systems, and organizations within the network;

the cyber-physical graph comprises nodes representing the connected resources, with each node having one or more properties associated with the connected resource represented by that node;

the cyber-physical graph comprises edges representing logical or physical relationships between pairs of the connected resources on the network; and

the cyber-physical graph includes information about sensitive data stored on one or more of the connected resources;

collecting data from a plurality of sources within the network, wherein the plurality of sources includes one or more of: system endpoints, infrastructure servers, perimeter security devices, and network security monitoring tools;

analyzing the collected data to identify sensitive data stored on one or more of the connected resources;

updating the cyber-physical graph to include information about the identified sensitive data and its location;

generating expected behavior data of at least some of the plurality of connected resources on the network by applying a behavioral model to nodes of the cyber-physical graph;

generating actual behavior data of at least some of the plurality of connected resources on the network from time-series data comprising a record of network events and the respective times at which each network event occurred;

detecting a deviation between the actual behavior data of a first node and the expected behavior data of the first node; and

when the deviation is detected:

analyzing severity of a threat posed by the deviation using at least one analysis algorithm;

generating a risk score based on a plurality of factors that indicate the severity of the threat; and

displaying the risk score in text and graphical form.

8. The method of claim 7 , further comprising the step of generating an impact assessment score for each affected connected resource by determining an impact on the network using the cyber-physical graph.

9. The method of claim 8 , wherein the impact assessment score further comprises the calculation of the overall impact of a cyberattack, wherein the calculation is based at least in part on the impact assessment score for each connected resource affected by the cyberattack.

10. The method of claim 7 , wherein the detection of deviations is based in part on a comparison of relationships between the connected resources against known security vulnerabilities.

11. The method of claim 10 , wherein the risk score is based at least in part on the results of the comparison against known security vulnerabilities.

12. The method of claim 7 , further comprising the step of producing a visualization based at least in part on at least a portion of the time-series data, wherein the visualization illustrates changes to the time-series data over time.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA COMPANY NAME PREVIOUSLY RECORDED ON REEL 67566 FRAME 797. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 25, 2024
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 069048/0586 →
CHANGE OF NAME Recorded May 29, 2024
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 067557/0279 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: QOMPLX, INC.
To: QOMPLX LLC
Reel/Frame 067566/0797 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2024
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 067525/0257 →
Continuity (15)
Continuation 17589811 · Jan 31, 2022
Continuation 16896764 · Jun 9, 2020
Continuation 16191054 · Nov 14, 2018
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Related Publication 20230421593A1 · Dec 28, 2023
References Cited (112)
US 5669000A · Jessen et al. · 1997 [cited by applicant]
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 6477572B1 · Elderton et al. · 2002 [cited by applicant]
US 7072863B1 · Phillips et al. · 2006 [cited by applicant]
US 7657406B2 · Tolone et al. · 2010 [cited by applicant]
US 7698213B2 · Lancaster · 2010 [cited by applicant]
US 7739653B2 · Venolia · 2010 [cited by applicant]
US 8065257B2 · Kuecuekyan · 2011 [cited by applicant]
US 8145761B2 · Liu et al. · 2012 [cited by applicant]
US 8281121B2 · Nath et al. · 2012 [cited by applicant]
US 8615800B2 · Baddour et al. · 2013 [cited by applicant]
US 8788306B2 · Delurgio et al. · 2014 [cited by applicant]
US 8793758B2 · Raleigh et al. · 2014 [cited by applicant]
US 8914878B2 · Burns et al. · 2014 [cited by applicant]
US 8997233B2 · Green et al. · 2015 [cited by applicant]
US 9134966B2 · Brock et al. · 2015 [cited by applicant]
US 9141360B1 · Chen et al. · 2015 [cited by applicant]
US 9231962B1 · Yen et al. · 2016 [cited by applicant]
US 9306965B1 · Grossman et al. · 2016 [cited by applicant]
US 9503467B2 · Lefebvre et al. · 2016 [cited by applicant]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9654495B2 · Hubbard et al. · 2017 [cited by applicant]
US 9672355B2 · Titonis et al. · 2017 [cited by applicant]
US 9686308B1 · Srivastava · 2017 [cited by applicant]
US 9762443B2 · Dickey · 2017 [cited by applicant]
US 9887933B2 · Lawrence, III · 2018 [cited by applicant]
US 9946517B2 · Talby et al. · 2018 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10102480B2 · Dirac et al. · 2018 [cited by applicant]
US 10135848B2 · Muddu et al. · 2018 [cited by applicant]
US 10210246B2 · Stojanovic et al. · 2019 [cited by applicant]
US 10210255B2 · Crabtree et al. · 2019 [cited by applicant]
US 10242406B2 · Kumar et al. · 2019 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10318882B2 · Brueckner et al. · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 10511498B1 · Narayan et al. · 2019 [cited by applicant]
US 20030041254A1 · Challener et al. · 2003 [cited by applicant]
US 20030145225A1 · Bruton et al. · 2003 [cited by applicant]
US 20050289072A1 · Sabharwal · 2005 [cited by applicant]
US 20060149575A1 · Varadarajan et al. · 2006 [cited by applicant]
US 20070150744A1 · Cheng et al. · 2007 [cited by applicant]
US 20090064088A1 · Barcia et al. · 2009 [cited by applicant]
US 20090089227A1 · Sturrock et al. · 2009 [cited by applicant]
US 20090182672A1 · Doyle · 2009 [cited by applicant]
US 20090222562A1 · Liu et al. · 2009 [cited by applicant]
US 20090293128A1 · Lippmann et al. · 2009 [cited by applicant]
US 20100042846A1 · Trotter et al. · 2010 [cited by applicant]
US 20100205588A1 · Yu et al. · 2010 [cited by applicant]
US 20110060821A1 · Loizeaux et al. · 2011 [cited by applicant]
US 20110087888A1 · Rennie · 2011 [cited by applicant]
US 20110154341A1 · Pueyo et al. · 2011 [cited by applicant]
US 20120137367A1 · Dupont et al. · 2012 [cited by applicant]
US 20120266244A1 · Green et al. · 2012 [cited by applicant]
US 20120303396A1 · Winkler et al. · 2012 [cited by applicant]
US 20130073062A1 · Smith et al. · 2013 [cited by applicant]
US 20130132149A1 · Wei et al. · 2013 [cited by applicant]
US 20130191416A1 · Lee et al. · 2013 [cited by applicant]
US 20130246996A1 · Duggal et al. · 2013 [cited by applicant]
US 20130304623A1 · Kumar et al. · 2013 [cited by applicant]
US 20130346354A1 · Mizell et al. · 2013 [cited by applicant]
US 20140074826A1 · Cooper et al. · 2014 [cited by applicant]
US 20140156806A1 · Karpistsenko et al. · 2014 [cited by applicant]
US 20140244612A1 · Bhasin et al. · 2014 [cited by applicant]
US 20140279762A1 · Xaypanya et al. · 2014 [cited by applicant]
US 20140359552A1 · Misra et al. · 2014 [cited by applicant]
US 20150095303A1 · Sonmez et al. · 2015 [cited by applicant]
US 20150106941A1 · Muller et al. · 2015 [cited by applicant]
US 20150149979A1 · Talby et al. · 2015 [cited by applicant]
US 20150163242A1 · Laidlaw et al. · 2015 [cited by applicant]
US 20150169294A1 · Brock et al. · 2015 [cited by applicant]
US 20150195192A1 · Vasseur et al. · 2015 [cited by applicant]
US 20150236935A1 · Bassett · 2015 [cited by applicant]
US 20150281225A1 · Schoen et al. · 2015 [cited by applicant]
US 20150317481A1 · Gardner et al. · 2015 [cited by applicant]
US 20150339263A1 · Ata et al. · 2015 [cited by applicant]
US 20150347414A1 · Xiao et al. · 2015 [cited by applicant]
US 20150379424A1 · Dirac et al. · 2015 [cited by applicant]
US 20160004858A1 · Chen et al. · 2016 [cited by applicant]
US 20160006629A1 · Tanakiev et al. · 2016 [cited by applicant]
US 20160028758A1 · Ellis et al. · 2016 [cited by applicant]
US 20160072845A1 · Chiviendacz et al. · 2016 [cited by applicant]
US 20160078361A1 · Brueckner et al. · 2016 [cited by applicant]
US 20160099960A1 · Gerritz et al. · 2016 [cited by applicant]
US 20160105454A1 · Li et al. · 2016 [cited by applicant]
US 20160140519A1 · Trepca et al. · 2016 [cited by applicant]
US 20160179945A1 · Diaz et al. · 2016 [cited by applicant]
US 20160205122A1 · Bassett · 2016 [cited by examiner]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20160285732A1 · Brech et al. · 2016 [cited by applicant]
US 20160342606A1 · Mouel et al. · 2016 [cited by applicant]
US 20160350442A1 · Crosby · 2016 [cited by applicant]
US 20160364307A1 · Garg et al. · 2016 [cited by applicant]
US 20170019678A1 · Kim et al. · 2017 [cited by applicant]
US 20170063896A1 · Muddu et al. · 2017 [cited by applicant]
US 20170083380A1 · Bishop et al. · 2017 [cited by applicant]
US 20170126712A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170139763A1 · Ellwein · 2017 [cited by applicant]
US 20170149802A1 · Huang et al. · 2017 [cited by applicant]
US 20170193110A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170206360A1 · Brucker et al. · 2017 [cited by applicant]
US 20170322959A1 · Tidwell et al. · 2017 [cited by applicant]
US 20170323089A1 · Duggal et al. · 2017 [cited by applicant]
US 20180197128A1 · Carstens et al. · 2018 [cited by applicant]
US 20180300930A1 · Kennedy et al. · 2018 [cited by applicant]
US 20190082305A1 · Proctor · 2019 [cited by applicant]
US 20190095533A1 · Levine et al. · 2019 [cited by applicant]
CN 105302532B · 2018 [cited by applicant]
EP 3107026A1 · 2016 [cited by examiner]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]
Hutton et al. “Crowdsourcing Evaluations of Classifying Interpretability”. [cited by applicant]