IP Library › Granted Patent US 12,273,368
Granted Patent B1
US 12,273,368 · App. 18/510,913 · Granted Apr 8, 2025

Cyber vulnerability assessment tool threat assessment heuristic

Inventors: Jacquelin A. Speck (Philadelphia, PA); Thomas Heverin (Philadelphia, PA); Mark Roman (Aston, PA); Marcello Balduccini (Wynnewood, PA); Matthew Bosack (Philadelphia, PA)
Assignee: The United States of America, as represented by the Secretary of the Navy
H04L63/1433G06N5/01H04L2012/40286
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,368
App. No.
18/510,913
Granted
Apr 8, 2025
Kind
B1
Abstract

A Cyber Vulnerability Assessment Tool (CVAST) and CVAST Threat Assessment Heuristic (CVAST THRASH) capable of automated modeling of cyber physical systems, assessment of the nature of cyber risks thereto, and output of such cyber risk assessments are provided.

Claims (21)

1. A computer system capable of implementing a Cyber Vulnerability Assessment Tool (CVAST) for conducting and outputting a cyber risk assessment of a Cyber Physical System (CPS), comprising:

a CPS Information Extraction System for extracting information from a data source;

a CPS Semantic Model for modeling relationships across a plurality of domains;

an Attack Graph Algorithm for analyzing a path from an entry point to a target using an electrical circuit analogy;

a Chain of Impacts Algorithm for evaluating a chain of cyber threat impacts;

a CPS Criticality Algorithm for evaluating a criticality of a system, a subsystem, or a component;

a THRASH Cyber Risk Algorithm for evaluating the cyber risk at component and system levels of the CPS.

2. The CVAST of claim 1 , further comprising a Cyber-Risk Information Database for storing the information extracted by the CPS Information Extraction System in accordance with a plurality of ontologies provided by the CPS Semantic Model.

3. The CVAST of claim 1 wherein the relationships modeled by the CPS Semantic Model derive from the domains comprising the engineering, information technology, cybersecurity, and mission domains.

4. The CVAST of claim 3 , wherein the CPS Semantic Model provides a plurality of ontologies linking components and systems of a CPS across the domains.

5. The CVAST of claim 1 , wherein the CPS is one operating in the group consisting of power grids, manufacturing plants, nuclear power plants, utility companies, and aviation systems.

6. The CVAST of claim 1 , wherein the CPS is Naval Control System (NCS).

7. The CVAST of claim 6 , wherein the CPS Semantic Model provides ontologies that support automated reasoning and computational analysis, in the form of semantic decompositions of CPS elements, the CPS elements comprising at least one of:

missions of Naval vessel platform vessels;

a Universal Naval Task List;

NCS systems for submarines, surface ships, and airframes;

lower level functioning systems; and

physical security systems.

8. The CVAST of claim 7 , wherein the CPS Semantic Model further comprises ontologies that support automated reasoning and computational analysis, in the form of semantic decompositions of types of adversaries which target NCS, and motivations of adversaries who target NCS.

9. The CVAST of claim 1 , wherein the risk assessment is a heat map.

10. A risk assessment produced by the CVAST of claim 1 .

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2023
From: SPECK, JACQUELIN A.
To: MCKEAN DEFENSE GROUP, LLC
Reel/Frame 065614/0446 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2023
From: BALDUCCINI, MARCELLO; HEVERIN, THOMAS
To: GRYPHON TECHNOLOGIES, LC
Reel/Frame 065614/0488 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2023
From: BOSACK, MATTHEW; ROMAN, MARK; MCKEAN DEFENSE GROUP, LLC; GRYPHON TECHNOLOGIES, LC
To: THE UNITED STATES OF AMERICA, AS REPRESENTED BY THE SECRETARY OF THE NAVY
Reel/Frame 065614/0491 →
Continuity (2)
Continuation 16949154 · Oct 15, 2020
Provisional Application 62915085 · Oct 15, 2019
References Cited (15)
US 8272061B1 · Lotem et al. · 2012 [cited by applicant]
US 11444974B1 · Shakhzadyan · 2022 [cited by examiner]
US 11863578B1 · Speck · 2024 [cited by examiner]
US 20180288085A1 · Hailpern · 2018 [cited by examiner]
US 20180337939A1 · Agarwal · 2018 [cited by examiner]
US 20190222597A1 · Crabtree · 2019 [cited by examiner]
US 20210133331A1 · Lipkis et al. · 2021 [cited by applicant]
US 20210273965A1 · Pi · 2021 [cited by examiner]
US 20210288995A1 · Attar et al. · 2021 [cited by applicant]
US 20220172146A1 · Zillner · 2022 [cited by examiner]
RU 2710985C1 · 2020 [cited by examiner]
WO WO2020183012A1 · 2020 [cited by examiner]
WO WO2020189668A1 · 2020 [cited by examiner]
P. Mell, K. Scarfone, and S. Romanosky, “A Complete Guide to the Common Vulnerability Scoring System Version 2.0,” Jun. 2007; available at www.first.org/cvss/v2/guide. [cited by applicant]
Open Web Application Security Project (OWASP), “OWASP Risk Rating Methodology,” OWASP, Sep. 13, 2015; available archived at web.archive.org/web/20160218160854/https://www.owasp.org/index.php/OWASP_Risk_Rating_Methodolog… [cited by applicant]