IP Library Granted Patent US 12,452,284
Granted Patent B2
US 12,452,284 · App. 18/343,716 · Granted Oct 21, 2025

Dynamic cyberattack mission planning and analysis

Inventors: Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,284
App. No.
18/343,716
Filed
Jun 28, 2023
Granted
Oct 21, 2025
Kind
B2
Art Unit
2434
USPC
726/1
Abstract

A system and method for cybersecurity mission planning and analysis which uses artificial intelligence systems to make red and blue team exercises more comprehensive and effective by supplementing individual expertise, reducing reliance on intuition, and eliminating gaps in knowledge. In an embodiment, a platform for cyberattack missions planning and analysis by red and blue teams is coordinated by a control center. An incident generator generates cyberattack scenarios and events using data from external databases and an internal attack knowledge manager having a knowledge graph of data about the network under attack in conjunction with one or more machine learning algorithms configured to identify potential network vulnerabilities. Red are guided by a machine learning algorithm configured to provide suggestions as to potential successful attack paths. Blue teams are guided by a machine learning algorithm configured to provide suggestions as to potential successful attack paths.

Claims (52)

1. An artificial-intelligence-assisted (AI-assisted) cyberattack mission planning system, comprising:

a computing device comprising a memory, a processor, and a non-volatile data storage device;

a first machine learning algorithm operating on the computing device and trained to generate a cyberattack scenario based on information from a knowledge graph;

a knowledge graph stored on the non-volatile data storage device, the knowledge graph comprising nodes representing entities, concepts, or events, and edges representing relationships between the nodes, wherein the knowledge graph represents knowledge about a computer network;

an ontology manager comprising a first plurality of programming instructions stored in the memory which, when operating on the processor, causes the computing device to:

retrieve cybersecurity context information from a cybersecurity database;

organize the cybersecurity context information into an ontology;

receive information about the computer network, the information comprising a network configuration; and

create nodes and edges in the knowledge graph to store the information about the computer network according to the ontology

an incident generator comprising a second plurality of programming instructions stored in the memory which, when operating on the processor, causes the computing device to:

retrieve a cybersecurity threat in the form of a tactic, techniques, or procedure from the cybersecurity database;

process the cybersecurity threat through the first machine learning algorithm to generate a cyberattack scenario for the computer network based on the information about the computer network contained in the knowledge graph; and

generate a cybersecurity incident for the computer network from the cyberattack scenario, the cybersecurity incident comprising an attack mode and event severity.

2. The system of claim 1 , further comprising a control center comprising a third plurality of programming instructions stored in the memory which, when operating on the processor, causes the computing device to:

carry out the cybersecurity incident on the computer network; and

display a visualization of the progress of the cybersecurity incident.

3. The system of claim 2 , further comprising a second machine learning algorithm trained to suggest defense strategies for mitigating the cybersecurity incident.

4. The system of claim 3 , further comprising a blue team portal which provides the defense strategies to a blue team comprising information technology (IT) personnel or cybersecurity analysts assigned to mitigate the cybersecurity incident.

5. The system of claim 4 , further comprising a third machine learning algorithm trained to suggest attack strategies to overcome the defense strategies.

6. The system of claim 5 , further comprising a red team portal which provides the attack strategies to a red team comprising IT personnel or cybersecurity analysts assigned to expose weaknesses in the security of the computer network based on the cybersecurity incident.

7. The system of claim 2 , further comprising an incident monitor comprising a fourth plurality of programming instructions stored in the memory which, when operating on the processor, causes the computing device to log cyber metrics for the computer network during the course of the carrying out of the cybersecurity incident.

8. The system of claim 7 , further comprising an underwriting module comprising a fifth plurality of programming instructions stored in the memory which, when operating on the processor, causes the computing device to:

retrieve a cybersecurity insurance policy, the cybersecurity insurance policy comprising a policy term;

retrieve a cyber metric relevant to the policy term from the log of cyber metrics;

compare the cyber metric to the policy terms to determine a compliance of the cyber metric to the policy term; and

output the determination of compliance.

9. An artificial-intelligence-assisted (AI-assisted) cyberattack mission planning method, comprising the steps of:

a computing device comprising a memory, a processor, and a non-volatile data storage device;

training a first machine learning algorithm operating on a computing device comprising a memory, a processor, and a non-volatile data storage device to generate a cyberattack scenario based on information from a knowledge graph;

storing a knowledge graph stored on the non-volatile data storage device, the knowledge graph comprising nodes representing entities, concepts, or events, and edges representing relationships between the nodes, wherein the knowledge graph represents knowledge about a computer network;

using an ontology manager operating on the computing device to:

retrieve cybersecurity context information from a cybersecurity database;

organize the cybersecurity context information into an ontology;

receive information about the computer network, the information comprising a network configuration; and

create nodes and edges in the knowledge graph to store the information about the computer network according to the ontology

using an incident generator operating on the computing device to:

retrieve a cybersecurity threat in the form of a tactic, techniques, or procedure from the cybersecurity database;

process the cybersecurity threat through the first machine learning algorithm to generate a cyberattack scenario for the computer network based on the information about the computer network contained in the knowledge graph; and

generate a cybersecurity incident for the computer network from the cyberattack scenario, the cybersecurity incident comprising an attack mode and event severity.

10. The method of claim 9 , further comprising the step of using a control center operating on the computing device to:

carry out the cybersecurity incident on the computer network; and

display a visualization of the progress of the cybersecurity incident.

11. The method of claim 10 , further comprising the step of training a second machine learning algorithm to suggest defense strategies for mitigating the cybersecurity incident.

12. The method of claim 11 , further comprising the step of providing the defense strategies to a blue team comprising information technology (IT) personnel or cybersecurity analysts assigned to mitigate the cybersecurity incident via a blue team portal.

13. The method of claim 12 , further comprising the step of training a third machine learning algorithm to suggest attack strategies to overcome the defense strategies.

14. The method of claim 13 , further comprising the step of providing the attack strategies to a red team comprising IT personnel or cybersecurity analysts assigned to expose weaknesses in the security of the computer network based on the cybersecurity incident via a red team portal.

15. The method of claim 14 , further comprising the step of using an underwriting module operating on the computing device to:

retrieve a cybersecurity insurance policy, the cybersecurity insurance policy comprising a policy term;

retrieve a cyber metric relevant to the policy term from the log of cyber metrics;

compare the cyber metric to the policy terms to determine a compliance of the cyber metric to the policy term; and

output the determination of compliance.

16. The method of claim 9 , further comprising the step of using an incident monitor operating on the computing device to log cyber metrics for the computer network during the course of the carrying out of the cybersecurity incident.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CORRECTIVE ASSIGNMENT TO CORRECT THE INVENTOR RICHARD KELLEY LAST NAME ON THE ORIGINALLY FILED COVER SHEET PREVIOUSLY RECORDED ON REEL 64412 FRAME 814. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 22, 2024
From: CRABTREE, JASON; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 067504/0175 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2023
From: CRABTREE, JASON; KELLY, RICHARD
To: QOMPLX, INC.
Reel/Frame 064412/0814 →
Continuity (1)
Related Publication 20250007942A1 · Jan 2, 2025
References Cited (110)
US 5669000A · Jessen et al. · 1997 [cited by applicant]
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 6477572B1 · Elderton et al. · 2002 [cited by applicant]
US 7072863B1 · Phillips et al. · 2006 [cited by applicant]
US 7657406B2 · Tolone et al. · 2010 [cited by applicant]
US 7698213B2 · Lancaster · 2010 [cited by applicant]
US 7739653B2 · Venolia · 2010 [cited by applicant]
US 8065257B2 · Kuecuekyan · 2011 [cited by applicant]
US 8145761B2 · Liu et al. · 2012 [cited by applicant]
US 8281121B2 · Nath et al. · 2012 [cited by applicant]
US 8615800B2 · Baddour et al. · 2013 [cited by applicant]
US 8788306B2 · Delurgio et al. · 2014 [cited by applicant]
US 8793758B2 · Raleigh et al. · 2014 [cited by applicant]
US 8914878B2 · Burns et al. · 2014 [cited by applicant]
US 8997233B2 · Green et al. · 2015 [cited by applicant]
US 9134966B2 · Brock et al. · 2015 [cited by applicant]
US 9141360B1 · Chen et al. · 2015 [cited by applicant]
US 9231962B1 · Yen et al. · 2016 [cited by applicant]
US 9294497B1 · Ben-Or et al. · 2016 [cited by applicant]
US 9306965B1 · Grossman et al. · 2016 [cited by applicant]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9654495B2 · Hubbard et al. · 2017 [cited by applicant]
US 9672355B2 · Titonis et al. · 2017 [cited by applicant]
US 9686308B1 · Srivastava · 2017 [cited by applicant]
US 9762443B2 · Dickey · 2017 [cited by applicant]
US 9887933B2 · Lawrence, III · 2018 [cited by applicant]
US 9946517B2 · Talby et al. · 2018 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10102480B2 · Dirac et al. · 2018 [cited by applicant]
US 10210246B2 · Stojanovic et al. · 2019 [cited by applicant]
US 10210255B2 · Crabtree et al. · 2019 [cited by applicant]
US 10216485B2 · Misra et al. · 2019 [cited by applicant]
US 10242406B2 · Kumar et al. · 2019 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10318882B2 · Brueckner et al. · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 10511498B1 · Narayan et al. · 2019 [cited by applicant]
US 11736527B1 · Joseph Durairaj et al. · 2023 [cited by examiner]
US 12225031B1 · Coull · 2025 [cited by examiner]
US 20030041254A1 · Challener et al. · 2003 [cited by applicant]
US 20030145225A1 · Bruton et al. · 2003 [cited by applicant]
US 20040098610A1 · Hrastar · 2004 [cited by applicant]
US 20050289072A1 · Sabharwal · 2005 [cited by applicant]
US 20060149575A1 · Varadarajan et al. · 2006 [cited by applicant]
US 20070150744A1 · Cheng et al. · 2007 [cited by applicant]
US 20090012760A1 · Schunemann · 2009 [cited by applicant]
US 20090064088A1 · Barcia et al. · 2009 [cited by applicant]
US 20090089227A1 · Sturrock et al. · 2009 [cited by applicant]
US 20090182672A1 · Doyle · 2009 [cited by applicant]
US 20090222562A1 · Liu et al. · 2009 [cited by applicant]
US 20090293128A1 · Lippmann et al. · 2009 [cited by applicant]
US 20110060821A1 · Loizeaux et al. · 2011 [cited by applicant]
US 20110087888A1 · Rennie · 2011 [cited by applicant]
US 20110154341A1 · Pueyo et al. · 2011 [cited by applicant]
US 20120266244A1 · Green et al. · 2012 [cited by applicant]
US 20130073062A1 · Smith et al. · 2013 [cited by applicant]
US 20130132149A1 · Wei et al. · 2013 [cited by applicant]
US 20130191416A1 · Lee et al. · 2013 [cited by applicant]
US 20130246996A1 · Duggal et al. · 2013 [cited by applicant]
US 20130304623A1 · Kumar et al. · 2013 [cited by applicant]
US 20140074826A1 · Cooper et al. · 2014 [cited by applicant]
US 20140156806A1 · Karpistsenko et al. · 2014 [cited by applicant]
US 20140244612A1 · Bhasin et al. · 2014 [cited by applicant]
US 20140245443A1 · Chakraborty · 2014 [cited by applicant]
US 20140279762A1 · Xaypanya et al. · 2014 [cited by applicant]
US 20150095303A1 · Sonmez et al. · 2015 [cited by applicant]
US 20150149979A1 · Talby et al. · 2015 [cited by applicant]
US 20150163242A1 · Laidlaw et al. · 2015 [cited by applicant]
US 20150169294A1 · Brock et al. · 2015 [cited by applicant]
US 20150195192A1 · Vasseur et al. · 2015 [cited by applicant]
US 20150236935A1 · Bassett · 2015 [cited by applicant]
US 20150281225A1 · Schoen et al. · 2015 [cited by applicant]
US 20150317481A1 · Gardner et al. · 2015 [cited by applicant]
US 20150339263A1 · Ata et al. · 2015 [cited by applicant]
US 20150347414A1 · Xiao et al. · 2015 [cited by applicant]
US 20150379424A1 · Dirac et al. · 2015 [cited by applicant]
US 20160004858A1 · Chen et al. · 2016 [cited by applicant]
US 20160028758A1 · Ellis et al. · 2016 [cited by applicant]
US 20160072845A1 · Chiviendacz et al. · 2016 [cited by applicant]
US 20160078361A1 · Brueckner et al. · 2016 [cited by applicant]
US 20160099960A1 · Gerritz et al. · 2016 [cited by applicant]
US 20160105454A1 · Li et al. · 2016 [cited by applicant]
US 20160140519A1 · Trepca et al. · 2016 [cited by applicant]
US 20160212171A1 · Senanayake et al. · 2016 [cited by applicant]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20160285732A1 · Brech et al. · 2016 [cited by applicant]
US 20160342606A1 · Mouel et al. · 2016 [cited by applicant]
US 20160350442A1 · Crosby · 2016 [cited by applicant]
US 20160364307A1 · Garg et al. · 2016 [cited by applicant]
US 20170013003A1 · Samuni et al. · 2017 [cited by applicant]
US 20170019678A1 · Kim et al. · 2017 [cited by applicant]
US 20170063896A1 · Muddu et al. · 2017 [cited by applicant]
US 20170083380A1 · Bishop et al. · 2017 [cited by applicant]
US 20170126712A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170139763A1 · Ellwein · 2017 [cited by applicant]
US 20170149802A1 · Huang et al. · 2017 [cited by applicant]
US 20170193110A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170206360A1 · Brucker et al. · 2017 [cited by applicant]
US 20170322959A1 · Tidwell et al. · 2017 [cited by applicant]
US 20170323089A1 · Duggal et al. · 2017 [cited by applicant]
US 20180197128A1 · Carstens et al. · 2018 [cited by applicant]
US 20180300930A1 · Kennedy et al. · 2018 [cited by applicant]
US 20180367549A1 · Jang · 2018 [cited by examiner]
US 20190082305A1 · Proctor · 2019 [cited by applicant]
US 20190095533A1 · Levine et al. · 2019 [cited by applicant]
US 20210194909A1 · Tang · 2021 [cited by examiner]
US 20230179622A1 · Underwood · 2023 [cited by examiner]
US 20230412635A1 · Binyamini · 2023 [cited by examiner]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]