IP Library Patent Application 19031055
Patent Application
App. No. 19/031,055

AI-DRIVEN DEFENSIVE CYBERSECURITY STRATEGY ANALYSIS AND RECOMMENDATION SYSTEM

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/031,055
Abstract

A system and method for automated cybersecurity defensive strategy analysis that predicts the evolution of new cybersecurity attack strategies and makes recommendations for cybersecurity improvements to networked systems based on a cost/benefit analysis. The system and method use machine learning algorithms to run simulated attack and defense strategies against a model of the networked system created using a directed graph. Recommendations are generated based on an analysis of the simulation results against a variety of cost/benefit indicators.

Claims (54)

1 . A computer system comprising a hardware memory, wherein the computer system is configured to execute software instructions stored on nontransitory machine-readable storage media that:

implement a cyberattack on a network under test;

gather system information about operation of the network under test during the cyberattack;

use the system information to initiate an iterative simulation of a cyberattack strategy sequence, each iteration comprising a simulated attack on a model of the network under test and a simulated defense against the simulated attack, each simulated attack and each simulated defense being generated by a first machine learning algorithm;

obtain a simulation result comprising the cyberattack strategy sequence and a probability of success of the attack and the defense in each iteration; and

determine a cybersecurity improvement recommendation for the network under test based on the simulation result.

2 . The computer system of claim 1 , wherein the system information comprises system logs of one or more devices affected during the cyberattack.

3 . The computer system of claim 1 , wherein the first machine learning algorithm is an evolutionary algorithm.

4 . The computer system of claim 3 , wherein the iterative simulation is an online simulation and the evolutionary algorithm is a continual online evolutionary planning algorithm.

5 . The computer system of claim 1 , further comprising a second machine learning algorithm, wherein each simulated attack is generated by the first machine learning algorithm and each simulated defense is generated by the second machine learning algorithm, such that the algorithms compete against each other in the simulation.

6 . The computer system of claim 1 , wherein the processor is further configured to implement the cybersecurity improvement recommendation on the network under test.

7 . The computer system of claim 6 , wherein the software instructions are configured to iteratively:

implement a new cyberattack;

gather new system information;

perform a new simulation;

determine a new cybersecurity improvement recommendation; and

implement the new cybersecurity improvement recommendation on the network under test.

8 . The computer system of claim 1 , wherein the model of the network under test comprises a cyber-physical graph representing relationships between devices, users, resources, and processes in the network under test.

9 . The computer system of claim 1 , wherein determining the cybersecurity improvement recommendation comprises:

receiving one or more cost factors;

receiving one or more benefit factors; and

comparing the simulation result against the cost factors and benefit factors.

10 . The computer system of claim 9 , wherein the cost factors comprise at least one of:

hardware replacement costs;

software configuration costs;

personnel training costs; and

operational costs associated with successful attacks.

11 . A computer-implemented method comprising the steps of:

implementing a cyberattack on a network under test;

gathering system information about operation of the network under test during the cyberattack;

using the system information to initiate an iterative simulation of a cyberattack strategy sequence, each iteration comprising a simulated attack on a model of the network under test and a simulated defense against the simulated attack, each simulated attack and each simulated defense being generated by a first machine learning algorithm;

obtaining a simulation result comprising the cyberattack strategy sequence and a probability of success of the attack and the defense in each iteration; and

determining a cybersecurity improvement recommendation for the network under test based on the simulation result.

12 . The computer-implemented method of claim 11 , wherein the system information comprises system logs of one or more devices affected during the cyberattack.

13 . The computer-implemented method of claim 11 , wherein the first machine learning algorithm is an evolutionary algorithm.

14 . The computer-implemented method of claim 13 , wherein the iterative simulation is an online simulation and the evolutionary algorithm is a continual online evolutionary planning algorithm.

15 . The computer-implemented method of claim 11 , wherein each simulated attack is generated by the first machine learning algorithm and each simulated defense is generated by a second machine learning algorithm, such that the algorithms compete against each other in the simulation.

16 . The computer-implemented method of claim 11 , further comprising the step of implementing the cybersecurity improvement recommendation on the network under test.

17 . The computer-implemented method of claim 16 , further comprising the steps of:

implementing a new cyberattack;

gathering new system information;

performing a new simulation;

determining a new cybersecurity improvement recommendation; and

implementing the new cybersecurity improvement recommendation on the network under test.

18 . The computer-implemented method of claim 11 , wherein the model of the network under test comprises a cyber-physical graph representing relationships between devices, users, resources, and processes in the network under test.

19 . The computer-implemented method of claim 11 , wherein determining the cybersecurity improvement recommendation comprises:

receiving one or more cost factors;

receiving one or more benefit factors; and

comparing the simulation result against the cost factors and benefit factors.

20 . The computer-implemented method of claim 19 , wherein the cost factors comprise at least one of:

hardware replacement costs;

software configuration costs;

personnel training costs; and

operational costs associated with successful attacks.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2025
From: CRABTREE, JASON; KELLEY, RICHARD; HOPPER, JASON; PARK, DAVID
To: QOMPLX LLC
Reel/Frame 071702/0500 →