IP Library Granted Patent US 12,603,914
Granted Patent B2
US 12,603,914 · App. 18/809,912 · Granted Apr 14, 2026

Cybersecurity gap identification using knowledge graphs

Inventors: Matthew Wayne Keen (Redmond, WA); Kaushik Sarkar (Mississauga, CA); Sylvain Huy Phong Lu (Toronto, CA); Saravana Bhawa Nukala (Milton, CA); Aditya Deepak Mahale (Toronto, CA); Avneet Singh (Niagara Falls, CA); Yuxuan Hu (Richmond Hill, CA); Mallik Imtiaz Hassan (Fredericton, CA); Rubin K C (Toronto, CA)
Assignee: Arctic Wolf Networks, Inc.
H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,603,914
App. No.
18/809,912
Granted
Apr 14, 2026
Kind
B2
Abstract

Disclosed are systems for detecting gaps in security measures performed in a network security environment. A system can: receive prevention data from a prevention system that generates and provides prevention measures to a third party system in a network security environment to prevent potential vulnerabilities, receive detection data from a detection system that generates and provides detection measures to the third party system to block the potential vulnerabilities, receive a framework taxonomy that includes relationships between vulnerabilities, tactics, techniques, and sub-techniques, and generate a knowledge graph based on mapping the prevention data, the detection data, and the tactics, techniques, and sub-techniques of the framework taxonomy. The system can also traverse the knowledge graph, iteratively detect gaps in the prevention measures or the detection measures based on traversing the knowledge graph, and return information about the detected gaps.

Claims (29)

1 . A system for detecting gaps in cybersecurity measures performed in a network security environment, the system comprising:

a cybersecurity prevention system comprising one or more processors and memory storing instructions that, when executed, cause the one or more processors to generate and provide prevention measures to a third party system in a network security environment, wherein the prevention measures comprise configuration settings that, when implemented at the third party system, cause the third party system to prevent potential cybersecurity vulnerabilities;

a cybersecurity detection system comprising one or more processors and memory storing instructions that, when executed, cause the one or more processors to generate and provide detection measures to the third party system in the network security environment, wherein the detection measures comprise rules that are triggered, by the third party system, in response to detecting and blocking the potential cybersecurity vulnerabilities;

a mapping engine comprising one or more processors and memory storing instructions that, when executed, cause the one or more processors to:

receive prevention data from the cybersecurity prevention system;

receive detection data from the cybersecurity detection system;

receive a framework taxonomy from a cybersecurity framework, wherein the framework taxonomy comprises relationships between cybersecurity vulnerabilities, tactics, techniques, and sub-techniques; and

generate a knowledge graph based on mapping the prevention data, the detection data, and the tactics, techniques, and sub-techniques of the framework taxonomy; and

a gap detection engine comprising one or more processors and memory storing instructions that, when executed, cause the one or more processors to:

receive the knowledge graph from the mapping engine;

traverse the knowledge graph;

iteratively detect gaps in the prevention measures or the detection measures based on traversing the knowledge graph, wherein iteratively detecting the gaps comprises generating weighted count values for connections between nodes in the knowledge graph and based on the traversing;

rank the detection measures and the prevention measures according to the weighted count values;

select a subset of the ranked detection measures and prevention measures having the weighted count values that satisfy one or more improvement criteria; and

return information about the selected subset of the ranked detection measures and prevention measures as opportunities for improvement.

2 . The system of claim 1 , wherein generating the knowledge graph is further based on applying a trained artificial intelligence (AI) model to the prevention data, the detection data, and the framework taxonomy, wherein the AI model was trained to correlate the prevention data and the detection data with the tactics, techniques, and sub-techniques according to the framework taxonomy.

3 . The system of claim 1 , wherein detecting the gaps is further based on applying a trained AI model to the knowledge graph.

4 . The system of claim 1 , wherein detecting the gaps comprises determining a sufficiency of coverage for the prevention measures or the detection measures against the potential cybersecurity vulnerabilities.

5 . The system of claim 4 , wherein determining the sufficiency of coverage comprises generating the weighted count values to quantify the detection measures and the prevention measures for the corresponding techniques or sub-techniques, wherein the nodes in the knowledge graph indicate the tactics, techniques, and the sub-techniques.

6 . The system of claim 1 , wherein the gap detection engine is further programmed to identify a particular prevention measure or a particular detection measure for improvement based on the respective weighted count value satisfying one or more improvement criteria.

7 . The system of claim 1 , wherein the weighted count values are weighted based on one or more predetermined weighting factors.

8 . The system of claim 1 , wherein detecting the gaps comprises determining a probability of chance that a malicious actor would transition between the tactics, techniques, or sub-techniques of the knowledge graph.

9 . The system of claim 8 , wherein the gap detection engine is further programmed to predict where, in the knowledge graph, the malicious actor is likely to end up based on the probability of chance.

10 . The system of claim 1 , wherein returning the information about the detected gaps comprises identifying an opportunity for improving at least one of the prevention measures or the detection measures corresponding to the detected gaps that satisfy one or more improvement criteria.

11 . The system of claim 1 , wherein generating the knowledge graph comprises encoding relationships between the detection measures and the techniques or the sub-techniques.

12 . The system of claim 1 , wherein generating the knowledge graph comprises encoding relationships between the prevention measures and the techniques or the sub-techniques that the respective prevention measures mitigate.

13 . The system of claim 1 , wherein traversing the knowledge graph comprises:

selecting a starting node in the knowledge graph; and

recursively traversing through edges of the knowledge graph between nodes, wherein the traversal begins at the starting node.

Assignments (2)
PATENT SECURITY AGREEMENT Recorded Feb 4, 2025
From: ARCTIC WOLF NETWORKS, INC.
To: BLUE OWL TECHNOLOGY FINANCE CORP., AS COLLATERAL AGENT
Reel/Frame 070110/0881 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2024
From: KEEN, MATTHEW WAYNE; SARKAR, KAUSHIK; LU, SYLVAIN HUY PHONG; NUKALA, SARAVANA BHAWA; MAHALE, ADITYA DEEPAK; SINGH, AVNEET; HASSAN, MALLIK IMTIAZ; K C, RUBIN; HU, YUXUAN
To: ARCTIC WOLF NETWORKS, INC.
Reel/Frame 068524/0834 →
Continuity (1)
Related Publication 20260058977A1 · Feb 26, 2026
References Cited (4)
US 20220329630A1 · Li · 2022 [cited by examiner]
US 20230300161A1 · Jenks · 2023 [cited by examiner]
US 20240144136A1 · Singh · 2024 [cited by examiner]
Choi, Seungoh et al., “Probabilistic Attack Sequence Generation and Execution Based on Mitre Att&ck for ICS Datasets”, CSET '21, Virtual, CA, USA, Aug. 9, 2021, 8 pages. [cited by applicant]