IP Library Granted Patent US 12,495,076
Granted Patent B2
US 12,495,076 · App. 18/339,207 · Granted Dec 9, 2025

System and method for internet activity and health forecasting and internet noise analysis

Inventors: Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
H04L63/20G06F16/2477G06F16/951G06F21/6218H04L63/1425H04L63/1433H04L63/1441H04L67/1097
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,495,076
App. No.
18/339,207
Filed
Jun 21, 2023
Granted
Dec 9, 2025
Kind
B2
Art Unit
2497
USPC
726/22
Abstract

A system and method for large-scale internet health forecasting and internet noise analysis. The system and method feature the ability to scan for, ingest and process, and then use various data stores for capturing entity data, their relationships, and actions associated with them. This data forms the basis for cyber enrichment service databases which can used to provide information responsive to user submitted queries as well as to produce large-scale (e.g., Internet scale) simulation models using statistical models, generative ML models, massively multiplayer online gaming simulation systems, or full discrete event simulation engines or some combination. User submitted queries can be ran against the raw data or against simulations to provide simulation results that can be used improve cybersecurity for an organization against actual observed behaviors or simulations.

Claims (46)

1 . A system for large-scale internet health forecasting and internet noise analysis, comprising:

a computer system comprising a memory and a processor;

a simulation engine comprising a first plurality of programming instructions stored in the memory and operating on the processor, wherein the first plurality of programming instructions, when operating on the processor, causes the computer system to:

retrieve a first plurality of cyber enrichment service data from cyber enrichment tables comprising at least a breach content database, an event database, a vulnerability and exploit database, a threat actor database, a reputation database, an internet infrastructure health database, and a tool database;

retrieve a plurality of routing information from external routing data sources;

retrieve a plurality of internet infrastructure data from internet infrastructure scanning sources;

use the plurality of cyber enrichment service data, the plurality of routing information, and the plurality of internet infrastructure data as inputs into a multiplayer online game simulator to create a large-scale internet health simulation;

receive a user submitted query from a query engine;

dynamically retrieve a second plurality of cyber enrichment service data from the cyber enrichment service tables based on parsed query details of the user submitted query, wherein the second plurality of cyber enrichment service data comprises query-specific threat intelligence data that differs from the first plurality of cyber enrichment service data;

apply the user submitted query to the large-scale internet health simulation to determine a predictive scenario comprising at least one of a predicted cyber threat, a routing security vulnerability, an internet infrastructure health forecast, or a threat actor behavior pattern;

normalize and schematize the predictive scenario and the second plurality of cyber enrichment service data to enable interoperability between different threat intelligence taxonomies; and

return the normalized and schematized scenario and the second plurality of cyber enrichment service data as a response to the user submitted query.

2 . The system of claim 1 , wherein the multiplayer online game simulator simulates border gateway protocol interactions across autonomous systems to model internet-scale routing behavior.

3 . The system of claim 1 , wherein the cyber enrichment service data comprises event data, reputation data, vulnerability and exploit data, threat actor data, breach detail data, tool data with offensive and defensive security tool metadata, and internet infrastructure health data, and wherein the cyber enrichment service tables support normalizing and schematizing interoperability between threat intelligence feeds from different vendors.

4 . The system of claim 1 , wherein the predictive scenario comprises real-time monitoring and forecasting predictions for internet infrastructure health changes.

5 . The system of claim 1 , wherein the predictive scenario comprises routing security vulnerability assessments and border gateway protocol anomaly predictions.

6 . The system of claim 1 , wherein the predictive scenario comprises a predicted threat to internet infrastructure with associated threat actor attribution and recommended countermeasures.

7 . The system of claim 1 , further comprising the query engine comprising second plurality of programming instructions stored in the memory and operating on the processor, wherein the second plurality of programming instructions, when operating on the processor, causes the computer system to:

receive the user submitted query;

parse the user submitted query to identify relevant threat intelligence domains;

send the parsed user submitted query to the simulation engine;

receive the returned normalize and schematized scenario and the second plurality of cyber enrichment service data from the simulation engine; and

display the normalized and schematized scenario and the second plurality of cyber enrichment service data as a response to the user submitted query via a user interface with threat actor taxonomy mapping.

8 . The system of claim 1 , wherein the computer system is a cloud computing platform.

9 . A computer-implemented method for large-scale internet health forecasting and internet noise analysis, comprising the steps of:

retrieving a first plurality of cyber enrichment service data from cyber enrichment service tables comprising at least a breach content database, an event database, a vulnerability and exploit database, a threat actor database, a reputation database, an internet infrastructure health database, and a tool database;

retrieving a plurality of routing information from external routing data sources;

retrieving a plurality of internet infrastructure data from internet infrastructure scanning sources;

using the plurality of cyber enrichment service data, the plurality of routing information, and the plurality of internet infrastructure data as inputs into a multiplayer online game simulator to create a large-scale internet health simulation;

receiving a user submitted query from a query engine;

dynamically retrieving a second plurality of cyber enrichment service data from the cyber enrichment service tables based on parsed query details of the user submitted query, wherein the second plurality of cyber enrichment service data comprises query-specific threat intelligence data that differs from the first plurality of cyber enrichment service data;

applying the user submitted query to the large-scale internet health simulation to determine a predictive scenario comprising at least one of a predicted cyber threat, a routing security vulnerability, an internet infrastructure health forecast, or a threat actor behavior pattern; and

normalizing and schematizing the predictive scenario and the second plurality of cyber enrichment service data to enable interoperability between different threat intelligence taxonomies; and

returning the normalize and schematized scenario and the second plurality of cyber enrichment service data as a response the user submitted query.

10 . The computer-implemented method of claim 9 , wherein the multiplayer online game simulator simulates border gateway protocol interactions across autonomous systems to model internet-scale routing behavior.

11 . The computer-implemented method of claim 9 , wherein the cyber enrichment service data comprises event data, reputation data, vulnerability and exploit data, threat actor data, breach detail data, tool data with offensive and defensive security tool metadata, and internet infrastructure health data, and wherein the cyber enrichment service tables support normalized and schematized interoperability between threat intelligence feeds from different vendors.

12 . The computer-implemented method of claim 9 , wherein the predictive scenario comprises real-time monitoring and forecasting predictions for internet infrastructure health changes.

13 . The computer-implemented method of claim 9 , wherein the predictive scenario comprises routing security vulnerability assessments and border gateway protocol anomaly predictions.

14 . The computer-implemented method of claim 9 , wherein the predictive scenario comprises a predicted threat to internet infrastructure with associated threat actor attribution and recommended countermeasures.

15 . The computer-implemented method of claim 9 , further comprising the steps of:

receiving the user submitted query;

parsing the user submitted query to identify relevant threat intelligence domains;

sending the parsed user submitted query to the simulation engine;

receiving the returned normalize and schematized scenario and the second plurality of cyber enrichment service data from the simulation engine; and

displaying the normalize and schematized scenario and the second plurality of cyber enrichment service data as a response to the user submitted query via a user interface with threat actor taxonomy mapping.

16 . The computer-implemented method of claim 9 , wherein the computer system is a cloud computing platform.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CORRECTIVE ASSIGNMENT TO CORRECT THE INVENTOR RICHARD KELLEY LAST NAME ON THE ORIGINALLY FILED COVER SHEET PREVIOUSLY RECORDED ON REEL 64412 FRAME 833. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 22, 2024
From: CRABTREE, JASON; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 067504/0197 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2023
From: CRABTREE, JASON; KELLY, RICHARD
To: QOMPLX, INC.
Reel/Frame 064412/0833 →
Continuity (22)
Continuation In Part 17829211 · May 31, 2022
Continuation 16983253 · Aug 3, 2020
Continuation In Part 16887304 · May 29, 2020
Continuation In Part 16837551 · Apr 1, 2020
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Related Publication 20240171614A1 · May 23, 2024
References Cited (25)
US 9384345B2 · Dixon et al. · 2016 [cited by applicant]
US 9967264B2 · Harris et al. · 2018 [cited by applicant]
US 10715534B2 · Sander et al. · 2020 [cited by applicant]
US 20040255167A1 · Knight · 2004 [cited by applicant]
US 20060253580A1 · Dixon et al. · 2006 [cited by applicant]
US 20140279995A1 · Wang · 2014 [cited by examiner]
US 20150244732A1 · Golshan et al. · 2015 [cited by applicant]
US 20150373039A1 · Wang · 2015 [cited by applicant]
US 20150381649A1 · Schultz et al. · 2015 [cited by applicant]
US 20160057159A1 · Yin et al. · 2016 [cited by applicant]
US 20160078225A1 · Ray et al. · 2016 [cited by applicant]
US 20160080399A1 · Harris et al. · 2016 [cited by applicant]
US 20160080417A1 · Thomas et al. · 2016 [cited by applicant]
US 20160080418A1 · Ray et al. · 2016 [cited by applicant]
US 20160080419A1 · Schiappa et al. · 2016 [cited by applicant]
US 20160080420A1 · Ray et al. · 2016 [cited by applicant]
US 20160132578A1 · Allen et al. · 2016 [cited by applicant]
US 20160191465A1 · Thomas et al. · 2016 [cited by applicant]
US 20160191559A1 · Mhatre et al. · 2016 [cited by applicant]
US 20160248800A1 · Ng et al. · 2016 [cited by applicant]
US 20180013774A1 · Sander et al. · 2018 [cited by applicant]
US 20180046811A1 · Andriani · 2018 [cited by examiner]
US 20180357422A1 · Telang et al. · 2018 [cited by applicant]
US 20200125734A1 · Light et al. · 2020 [cited by applicant]
US 20220035930A1 · Carey et al. · 2022 [cited by applicant]