IP Library Granted Patent US 12,301,626
Granted Patent B2
US 12,301,626 · App. 18/653,991 · Granted May 13, 2025

Automatically computing and improving a cybersecurity risk score

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/20G06F16/2477G06F16/951H04L63/1425H04L63/1441H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,626
App. No.
18/653,991
Granted
May 13, 2025
Kind
B2
Abstract

Automatically computing and managing a cybersecurity risk score. The cybersecurity risk score and cyber-physical graph for a network are retrieved and analyzed to identify potential improvements that can be made to network topography and device configurations, changes are applied automatically and an updated cyber-physical graph reflecting the applied changes is produced, and the updated cyber-physical graph is reassessed to determine the effect of the changes that were applied.

Claims (37)

1. A computing system for automatically computing and improving a cybersecurity risk score, comprising:

one or more hardware processors configured for:

generating a cybersecurity profile for the network via external reconnaissance of the network;

determining a cybersecurity risk score for at least a portion of the network based on the cybersecurity profile and a cyber-physical graph of the network;

providing the cybersecurity risk score and the cyber-physical graph to a distributed computational graph;

analyzing the cyber-physical graph and the cybersecurity risk score on a periodic or event-oriented basis using computations coordinated by the distributed computational graph; and

when the cybersecurity risk score falls below a threshold:

identifying, based on results of the analysis, a change applicable to each of a plurality of target devices within the network;

transmitting instructions to the plurality of target devices to apply or simulate the identified change; and

updating the cyber-physical graph based on the applied or simulated change.

2. A computer-implemented method for automatically computing and improving a cybersecurity risk score, the computer-implemented comprising the steps of:

generating a cybersecurity profile for the network via external reconnaissance of the network;

determining a cybersecurity risk score for at least a portion of the network based on the cybersecurity profile and a cyber-physical graph of the network;

providing the cybersecurity risk score and the cyber-physical graph to a distributed computational graph;

analyzing the cyber-physical graph and the cybersecurity risk score on a periodic or event-oriented basis using computations coordinated by the distributed computational graph; and

when the cybersecurity risk score falls below a threshold:

identifying, based on results of the analysis, a change applicable to each of a plurality of target devices within the network;

transmitting instructions to the plurality of target devices to apply or simulate the identified change; and

updating the cyber-physical graph based on the applied or simulated change.

3. A system for automatically computing and improving a cybersecurity risk score, comprising one or more computers with executable instructions that, when executed, cause the system to:

generate a cybersecurity profile for the network via external reconnaissance of the network;

determine a cybersecurity risk score for at least a portion of the network based on the cybersecurity profile and a cyber-physical graph of the network;

provide the cybersecurity risk score and the cyber-physical graph to a distributed computational graph;

analyze the cyber-physical graph and the cybersecurity risk score on a periodic or event-oriented basis using computations coordinated by the distributed computational graph; and

when the cybersecurity risk score falls below a threshold:

identify, based on results of the analysis, a change applicable to each of a plurality of target devices within the network;

transmit instructions to the plurality of target devices to apply or simulate the identified change; and

update the cyber-physical graph based on the applied or simulated change.

4. Non-transitory, computer-readable storage media having computer-executable instructions embodied thereon that, when executed by one or more processors of a computing system for automatically computing and improving a cybersecurity risk score, cause the computing system to:

generate a cybersecurity profile for the network via external reconnaissance of the network;

determine a cybersecurity risk score for at least a portion of the network based on the cybersecurity profile and a cyber-physical graph of the network;

provide the cybersecurity risk score and the cyber-physical graph to a distributed computational graph;

analyze the cyber-physical graph and the cybersecurity risk score on a periodic or event-oriented basis using computations coordinated by the distributed computational graph; and

when the cybersecurity risk score falls below a threshold:

identify, based on results of the analysis, a change applicable to each of a plurality of target devices within the network;

transmit instructions to the plurality of target devices to apply or simulate the identified change; and

update the cyber-physical graph based on the applied or simulated change.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA COMPANY NAME PREVIOUSLY RECORDED ON REEL 67566 FRAME 797. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 25, 2024
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 069048/0586 →
CHANGE OF NAME Recorded May 29, 2024
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 067557/0279 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 067557/0825 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: QOMPLX, INC.
To: QOMPLX LLC
Reel/Frame 067566/0797 →
Continuity (20)
Continuation 17392250 · Aug 2, 2021
Continuation In Part 16837551 · Apr 1, 2020
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15725274 · Oct 4, 2017
Related Publication 20240291870A1 · Aug 29, 2024
References Cited (23)
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 7530105B2 · Gilbert · 2009 [cited by examiner]
US 8281121B2 · Nath et al. · 2012 [cited by applicant]
US 8615800B2 · Baddour et al. · 2013 [cited by applicant]
US 8793758B2 · Raleigh et al. · 2014 [cited by applicant]
US 8881288B1 · Levy · 2014 [cited by examiner]
US 8914878B2 · Burns · 2014 [cited by examiner]
US 9256735B2 · Stute · 2016 [cited by applicant]
US 9560065B2 · Neil et al. · 2017 [cited by applicant]
US 9602530B2 · Ellis · 2017 [cited by examiner]
US 9654495B2 · Hubbard et al. · 2017 [cited by applicant]
US 9762443B2 · Dickey · 2017 [cited by applicant]
US 9887933B2 · Lawrence, III · 2018 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 20040143753A1 · Hernacki · 2004 [cited by examiner]
US 20130304623A1 · Kumar et al. · 2013 [cited by applicant]
US 20160140519A1 · Trepca et al. · 2016 [cited by applicant]
US 20160191532A1 · Seiver · 2016 [cited by examiner]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]