IP Library › Granted Patent US 12,750,404
Granted Patent B2
US 12,750,404 · App. 17/545,663 · Granted Sep 29, 2026

AI-driven defensive cybersecurity strategy analysis and recommendation system

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/20G06F16/2477G06F16/951G06F21/577H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,750,404
App. No.
17/545,663
Filed
Dec 8, 2021
Granted
Sep 29, 2026
Kind
B2
Art Unit
2409
USPC
726/22
Abstract

A system and method for automated cybersecurity defensive strategy analysis that predicts the evolution of new cybersecurity attack strategies and makes recommendations for cybersecurity improvements to networked systems based on a cost/benefit analysis. The system and method use machine learning algorithms to run simulated attack and defense strategies against a model of the networked system created using a directed graph. Recommendations are generated based on an analysis of the simulation results against a variety of cost/benefit indicators. The recommendation engine runs continuously, makes suggestions, and takes adjustably autonomous actions to go further and actuate parts of the system using an orchestration service employing a distributed computational graph and actuation plugins based on generated plans. Actions are validated as required or as prudent from appropriate simulation modeling services.

Claims (41)

1 . A system for automated cybersecurity defensive strategy analysis and recommendations, comprising:

a plurality of programming instructions stored in a memory of, and operating on a processor of, a computing device, wherein the plurality of programming instructions, when operating on the processor, cause the computing device to:

generate a cyber-physical graph of a target network by requesting packet capture data from endpoint agents and network packet capturing devices deployed on networked devices of the target network, wherein the cyber-physical graph is a directed graph comprising nodes representing network devices, users, and resources, and edges representing physical and logical connections between the nodes, and wherein the cyber-physical graph further incorporates deployed software version information and access privilege relationships is from the captured packet data;

perform real-time attack tests on a simulated model of the target network that is based on the cyber-physical graph by:

executing iterative adversarial attack simulations on the cyber-physical graph by composing attack sequences and applying said attack sequences to the cyber-physical graph, wherein the adversarial attack simulations are based, at least in part, on the deployed software version information and the access privilege relationships incorporated in the cyber-physical graph;

updating a probability of success for each attack sequence based on a reward signal received for a successful exploitation of a node or edge in the cyber-physical graph; and

outputting simulation results of the adversarial attack simulations, wherein the simulation results comprise probability distributions over the probability of success for each attack sequence;

generate a cybersecurity improvement recommendation for the target network by:

generating new hypothetical controls for the target network;

analyzing the new hypothetical controls using the simulation results based on cost of implementation of the new hypothetical controls and benefit to be gained from implementation of the new hypothetical controls; and

incorporating the new hypothetical controls in a subsequent iterative adversarial attack simulation to determine whether the new hypothetical controls will be successful; and

upon determining that the new hypothetical controls will be successful, automatically reconfigure the target network using a distributed computational graph to send configuration data implementing the cybersecurity improvement recommendation to affected network devices.

2 . The system of claim 1 , wherein the packet capture data is requested from endpoint agents and network packet capturing devices deployed on the network devices.

3 . The system of claim 1 , wherein the performing real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph further includes determining one or more vectors of attack for the adversarial attack simulations.

4 . The system of claim 1 , wherein the performing real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph further includes determining a blast radius for the adversarial attack simulations.

5 . The system of claim 1 , wherein the performing real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph further includes determination of exploitable software by generating software exploitability scores that are determined at least by one or more of the following properties: address space layout randomization, data execution prevention, stack hardening, compilation options, or any combination thereof.

6 . The system of claim 5 , wherein the exploitability scores are compared to deep web, dark web, and internet data obtained via public data collection and scans.

7 . The system of claim 1 , wherein the real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph are triggered in response to a change event that causes a modification of the cyber-physical graph.

8 . The system of claim 3 , wherein the cybersecurity improvement recommendations include an identification of a vulnerable node based on the one or more determined vectors of attack.

9 . The system of claim 1 , wherein the plurality of programming instructions further cause the computing device to produce data to describe a set of metrics from the adversarial attack simulations, wherein the set of metrics comprises the following properties: observability, detectability, control effectiveness, compliance effectiveness, and response/mitigation ability.

10 . The system of claim 9 , wherein the set of metrics are also used to determine the attack sequences.

11 . A method for automated cybersecurity defensive strategy analysis and recommendations, comprising the steps of:

generating a cyber-physical graph of a target network by requesting packet capture data from endpoint agents and network packet capturing devices deployed on networked devices of the target network, wherein the cyber-physical graph is a directed graph comprising nodes representing network devices, users, and resources, and edges representing physical and logical connections between the nodes, and wherein the cyber-physical graph further incorporates deployed software version information and access privilege relationships from the captured packet data;

performing real-time attack tests on a simulated model of the target network that is based on the cyber-physical graph by:

executing iterative adversarial attack simulations on the cyber-physical graph by composing attack sequences and applying said attack sequences to the cyber-physical graph, wherein the adversarial attack simulations are based, at least in part, on the deployed software version information and the access privilege relationships incorporated in the cyber-physical graph;

updating a probability of success for each attack sequence based on a reward signal received for a successful exploitation of a node or edge in the cyber-physical graph; and

outputting simulation results of the adversarial attack simulations, wherein the simulation results comprise probability distributions over the probability of success for each attack sequence;

generating a cybersecurity improvement recommendation for the target network by:

generating new hypothetical controls for the target network;

analyzing the new hypothetical controls using the simulation results based on cost of implementation of the new hypothetical controls and benefit to be gained from implementation of the new hypothetical controls; and

incorporating the new hypothetical controls in a subsequent iterative adversarial attack simulation to determine whether the new hypothetical controls will be successful; and

upon determining that the new hypothetical controls will be successful, automatically reconfiguring the target network using a distributed computational graph to send configuration data implementing the cybersecurity improvement recommendation to affected network devices.

12 . The method of claim 11 , wherein the packet capture data is requested from endpoint agents and network packet capturing devices deployed on the network devices.

13 . The method of claim 11 , wherein the performing real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph further includes determining one or more vectors of attack for the adversarial attack simulations.

14 . The method of claim 11 , wherein the performing real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph further includes determining a blast radius for the adversarial attack simulations.

15 . The method of claim 11 , wherein the performing real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph further includes determination of exploitable software by generating software exploitability scores that are determined at least by one or more of the following properties: address space layout randomization, data execution prevention, stack hardening, compilation options, or any combination thereof.

16 . The method of claim 15 , wherein the exploitability scores are compared to deep web, dark web, and internet data obtained via public data collection and scans.

17 . The method of claim 11 , wherein the real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph are triggered in response to a change event that causes a modification of the cyber-physical graph.

18 . The method of claim 13 , wherein the cybersecurity improvement recommendations include an identification of a vulnerable node based on the one or more determined vectors of attack.

19 . The method of claim 11 , further comprising producing data to describe a set of metrics from the adversarial attack simulations, wherein the set of metrics comprises the following properties: observability, detectability, control effectiveness, compliance effectiveness, and response/mitigation ability.

20 . The method of claim 19 , wherein the set of metrics are also used to determine the vectors of attack.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TITLE PREVIOUSLY RECORDED ON REEL 059924 FRAME 0356. ASSIGNOR(S) HEREBY CONFIRMS THE AI-DRIVEN DEFENSIVE CYBERSECURITY STRATEGY ANALYSIS AND RECOMMENDATION SYSTEM. Recorded May 24, 2023
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 063754/0992 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2022
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 059924/0356 →
Continuity (19)
Continuation In Part 17389863 · Jul 30, 2021
Continuation 16792754 · Feb 17, 2020
Continuation In Part 16779801 · Feb 3, 2020
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Related Publication 20220210200A1 · Jun 30, 2022
References Cited (40)
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 8176561B1 · Hurst · 2012 [cited by examiner]
US 8281121B2 · Nath et al. · 2012 [cited by applicant]
US 8615800B2 · Baddour et al. · 2013 [cited by applicant]
US 8793758B2 · Raleigh et al. · 2014 [cited by applicant]
US 8914878B2 · Burns et al. · 2014 [cited by applicant]
US 9325728B1 · Kennedy · 2016 [cited by examiner]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9654495B2 · Hubbard et al. · 2017 [cited by applicant]
US 9762443B2 · Dickey · 2017 [cited by applicant]
US 9887933B2 · Lawrence, III · 2018 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10068493B2 · Brueckner · 2018 [cited by examiner]
US 10079850B1 · Patil · 2018 [cited by examiner]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 10686811B1 · Ehle · 2020 [cited by examiner]
US 20060109793A1 · Kim · 2006 [cited by examiner]
US 20060218640A1 · Lotem · 2006 [cited by examiner]
US 20080183520A1 · Cutts · 2008 [cited by examiner]
US 20130304623A1 · Kumar et al. · 2013 [cited by applicant]
US 20130312101A1 · Lotem · 2013 [cited by examiner]
US 20130347116A1 · Flores · 2013 [cited by examiner]
US 20140007241A1 · Gula · 2014 [cited by examiner]
US 20140245449A1 · Powell · 2014 [cited by examiner]
US 20150067857A1 · Symons · 2015 [cited by examiner]
US 20160140519A1 · Trepca et al. · 2016 [cited by applicant]
US 20160205122A1 · Bassett · 2016 [cited by examiner]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20170006055A1 · Strom · 2017 [cited by examiner]
US 20170048266A1 · Hovor · 2017 [cited by examiner]
US 20170126712A1 · Crabtree · 2017 [cited by examiner]
US 20170237778A1 · DiGiambattista · 2017 [cited by examiner]
US 20170244745A1 · Key · 2017 [cited by examiner]
US 20170289187A1 · Noel · 2017 [cited by examiner]
US 20210099476A1 · Montgomery · 2021 [cited by examiner]
US 20220078203A1 · Shakarian · 2022 [cited by examiner]
US 20230336581A1 · Dunn · 2023 [cited by examiner]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]