IP Library Granted Patent US 12,641,127
Granted Patent B2
US 12,641,127 · App. 18/639,844 · Granted May 26, 2026

Detection and mitigation of data compromises in adversarial environments

Inventors: Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
H04L63/20G06F16/215G06F16/2477G06F16/951G06F21/6218H04L63/1425H04L63/1433H04L63/1441H04L67/1097
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,641,127
App. No.
18/639,844
Granted
May 26, 2026
Kind
B2
Abstract

Detection and mitigation of data source compromises in an adversarial information environment, featuring the ability to scan for, ingest and process, and then use relational, wide column, and graph stores for capturing entity data, their relationships, and actions associated with them. Metadata is gathered and linked to the ingested data, which provides a broader contextual view of the environment leading up to and during an event of interest. Data quality analysis is conducted as data is ingested in order to identify if a data source may be compromised. The results are used to manage the reputation of the contributing data sources.

Claims (129)

1 . A system for detection and mitigation of data compromises in adversarial environments, comprising one or more computers with executable instructions that, when executed, cause the system to:

extract metadata from each of a plurality of data pulls from application programming interfaces (APIs) of a plurality of data services, wherein the metadata identifies the respective data service and a content of the data in the respective data pull;

for each data pull from each API, use the data and the extracted metadata to identify and measure a plurality of data quality metrics;

establish a reputation score for the data in each data pull by:

comparing the extracted metadata for identifying the content of the data against a breach content database;

comparing the extracted metadata for identifying a source of the data against a vulnerabilities and exploits database;

comparing the plurality of data quality metrics for determining if a data source has been compromised against a baseline database; and

generating a component reputation score for that data pull based on the comparisons;

updating the breach content database with a new reputation score; and

publishing the update on a first publication and subscription data feed for the breach content database; and

generate a recommendation of data services based on the new reputation score.

2 . The system of claim 1 , wherein the system is further caused to:

for each component reputation score generated:

create a new node in a reputation relationship graph representing the component reputation score, and

associate the new node via one or more edges with one or more existing nodes in the reputation relationship graph for the data service from which the data was pulled;

generate a new reputation score for each data service from which data was pulled by analyzing the new nodes and edges of the reputation relationship graph by, for each data pull from each data service:

updating the vulnerabilities and exploits database with the new reputation score; and

publishing the update on a second publication and subscription data feed for the vulnerabilities and exploits database;

wherein the reputation relationship graph logically organizes the plurality of data services into a distributed collaborative database with a reliability of each data service being indicated by its reputation score.

3 . The system of claim 1 , wherein the breach content database is stored in a non-volatile storage device of a cloud computing platform, the breach content database comprising historical data breach records.

4 . The system of claim 1 , wherein the vulnerability and exploits database stored in a non-volatile storage device of a cloud computing platform, the vulnerability and exploits database comprising information about vulnerabilities and exploits associated with a data service.

5 . The system of claim 1 , wherein the system is further caused to:

send the recommendation of data services to an end user;

receive feedback from the end user; and

use the feedback to update the new reputation score.

6 . The system of claim 1 , wherein the system is further caused to:

extract data from external score and metric databases;

extract user data from internal databases;

generate a cyber score from the combination of external data and internal data, wherein the cyber score is calculated from one or more of a plurality of scoring metrics;

send the cyber score to the cyber open market exchange; and

wherein the cyber open market exchange facilitates transactional behavior among market participants.

7 . The system of claim 1 , wherein the plurality of data quality metrics comprises at least one of data source relevance, data source consistency, data source connectedness, data source timing, data source completeness, data source reliability, data source accuracy, and data source market reputation.

8 . A method for detection and mitigation of data compromises in adversarial environments, comprising the steps of:

extracting metadata from each of a plurality of data pulls from application programming interfaces (APIs) of a plurality of data services, wherein the metadata identifies the respective data service and a content of the data in the respective data pull;

for each data pull from each API, using the data and the extracted metadata to identify and measure a plurality of data quality metrics;

establishing a reputation score for the data in each data pull by:

comparing the extracted metadata for identifying the content of the data against a breach content database;

comparing the extracted metadata for identifying a source of the data against a vulnerabilities and exploits database;

comparing the plurality of data quality metrics for determining if a data source has been compromised against a baseline database; and

generating a component reputation score for that data pull based on the comparisons;

updating the breach content database with a new reputation score; and

publishing the update on a first publication and subscription data feed for the breach content database;

generating a recommendation of data services based on the new reputation score.

9 . The method of claim 8 , further comprising the steps of:

for each component reputation score generated:

creating a new node in a reputation relationship graph representing the component reputation score, and

associating the new node via one or more edges with one or more existing nodes in the reputation relationship graph for the data service from which the data was pulled;

generating a new reputation score for each data service from which data was pulled by analyzing the new nodes and edges of the reputation relationship graph by, for each data pull from each data service:

updating the vulnerabilities and exploits database with the new reputation score; and

publishing the update on a second publication and subscription data feed for the vulnerabilities and exploits database;

wherein the reputation relationship graph logically organizes the plurality of data services into a distributed collaborative database with a reliability of each data service being indicated by its reputation score.

10 . The method of claim 8 , further comprising the step of storing the breach content database in a cloud computing platform, the breach content database comprising historical data breach records.

11 . The method of claim 8 , further comprising the step of storing the vulnerability and exploits database in a cloud computing platform, the vulnerability and exploits database comprising information about vulnerabilities and exploits associated with a data service.

12 . The method of claim 8 , further comprising the steps of:

sending the recommendation of data services to an end user;

receiving feedback from the end user; and

using the feedback to update the new reputation score.

13 . The method of claim 8 , further comprising the steps of:

extracting data from external score and metric databases;

extracting user data from internal databases;

generating a cyber score from the combination of external data and internal data, wherein the cyber score is calculated from a one or more of plurality of scoring metrics; and

sending the cyber score to the cyber open market exchange;

wherein the cyber open market exchange facilitates transactional behavior among market participants.

14 . The method of claim 8 , wherein the plurality of data quality metrics comprises at least one of data source relevance, data source consistency, data source connectedness, data source timing, data source completeness, data source reliability, data source accuracy, and data source market reputation.

15 . A computing system for detection and mitigation of data compromises in adversarial environments, the computing system comprising:

one or more hardware processors configured for:

extracting metadata from each of a plurality of data pulls from application programming interfaces (APIs) of a plurality of data services, wherein the metadata identifies the respective data service and a content of the data in the respective data pull;

for each data pull from each API, using the data and the extracted metadata to identify and measure a plurality of data quality metrics;

establishing a reputation score for the data in each data pull by:

comparing the extracted metadata for identifying the content of the data against a breach content database;

comparing the extracted metadata for identifying a source of the data against a vulnerabilities and exploits database;

comparing the data quality metrics for determining if a data source has been compromised against a baseline database; and

generating a component reputation score for that data pull based on the comparisons;

updating the breach content database with a new reputation score; and

publishing the update on a first publication and subscription data feed for the breach content database; and

generating a recommendation of data services based on the new reputation score.

16 . The computing system of claim 15 , wherein the one or more hardware processors are further configured for:

for each component reputation score generated:

creating a new node in a reputation relationship graph representing the component reputation score, and

associating the new node via one or more edges with one or more existing nodes in the reputation relationship graph for the data service from which the data was pulled;

generating a new reputation score for each data service from which data was pulled by analyzing the new nodes and edges of the reputation relationship graph by, for each data pull from each data service:

updating the vulnerabilities and exploits database with the new reputation score; and

publishing the update on a second publication and subscription data feed for the vulnerabilities and exploits database;

wherein the reputation relationship graph logically organizes the plurality of data services into a distributed collaborative database with a reliability of each data service being indicated by its reputation score.

17 . The computing system of claim 15 , wherein the computing system wherein the one or more hardware processors are further configured for storing the breach content database in a cloud computing platform, the breach content database comprising historical data breach records.

18 . The computing system of claim 15 , wherein the computing system wherein the one or more hardware processors are further configured for storing the vulnerability and exploit database in a cloud computing platform, the vulnerability and exploits database comprising information about vulnerabilities and exploits associated with a data service.

19 . The computing system of claim 15 , wherein the computing system wherein the one or more hardware processors are further configured for:

sending the recommendation of data services to an end user;

receiving feedback from the end user; and

using the feedback to update the new reputation score.

20 . The computing system of claim 15 , wherein the computing system wherein the one or more hardware processors are further configured for:

extracting data from external score and metric databases;

extracting user data from internal databases;

generating a cyber score from the combination of external data and internal data, wherein the cyber score is calculated from one or more of a plurality of scoring metrics; and

sending the cyber score to the cyber open market exchange;

wherein the cyber open market exchange facilitates transactional behavior among market participants.

21 . The computing system of claim 15 , wherein the plurality of data quality metrics comprises at least one of data source relevance, data source consistency, data source connectedness, data source timing, data source completeness, data source reliability, data source accuracy, and data source market reputation.

22 . Non-transitory, computer-readable storage media having computer-executable instructions embodied thereon that, when executed by one or more processors of a computing system for detection and mitigation of data compromises in adversarial environments, cause the computing system to:

extract metadata from each of a plurality of data pulls from application programming interfaces (APIs) of a plurality of data services, wherein the metadata identifies the respective data service and a content of the data in the respective data pull;

for each data pull from each API, use the data and the extracted metadata to identify and measure a plurality of data quality metrics;

establish a reputation score for the data in each data pull by:

comparing the extracted metadata for identifying the content of the data against a breach content database;

comparing the extracted metadata for identifying a source of the data against a vulnerabilities and exploits database;

comparing the data quality metrics for determining if a data source has been compromised against a baseline database; and

generating a component reputation score for that data pull based on the comparisons;

updating the breach content database with a new reputation score;

publishing the update on a first publication and subscription data feed for the breach content database; and

generating a recommendation of data services based on the new reputation score.

23 . The non-transitory, computer-readable storage media of claim 22 , wherein the computing system is further caused to:

for each component reputation score generated:

create a new node in a reputation relationship graph representing the component reputation score; and

associate the new node via one or more edges with one or more existing nodes in the reputation relationship graph for the data service from which the data was pulled; and

generate a new reputation score for each data service from which data was pulled by analyzing the new nodes and edges of the reputation relationship graph by, for each data pull from each data service:

updating the vulnerabilities and exploits database with the new reputation score; and

publishing the update on a second publication and subscription data feed for the vulnerabilities and exploits database;

wherein the reputation relationship graph logically organizes the plurality of data services into a distributed collaborative database with a reliability of each data service being indicated by its reputation score.

24 . The non-transitory, computer-readable storage media of claim 22 , wherein the breach content database is stored in a non-volatile storage device of a cloud computing platform, the breach content database comprising historical data breach records.

25 . The non-transitory, computer-readable storage media of claim 22 , wherein the vulnerability and exploits database stored in the non-volatile storage device of a cloud computing platform, the vulnerability and exploits database comprising information about vulnerabilities and exploits associated with a data service.

26 . The non-transitory, computer-readable storage media of claim 22 , wherein the computing system is further caused to:

send the recommendation of data services to an end user;

receive feedback from the end user; and

use the feedback to update the new reputation score.

27 . The non-transitory, computer-readable storage media of claim 22 , wherein the computing system is further caused to:

extract data from external score and metric databases;

extract user data from internal databases;

generate a cyber score from the combination of external data and internal data, wherein the cyber score is calculated from one or more of a plurality of scoring metrics;

send the cyber score to the cyber open market exchange; and

wherein the cyber open market exchange facilitates transactional behavior among market participants.

28 . The non-transitory, computer-readable storage media of claim 22 , wherein the plurality of data quality metrics comprises at least one of data source relevance, data source consistency, data source connectedness, data source timing, data source completeness, data source reliability, data source accuracy, and data source market reputation.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA COMPANY NAME PREVIOUSLY RECORDED ON REEL 67566 FRAME 797. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 25, 2024
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 069048/0586 →
CHANGE OF NAME Recorded May 29, 2024
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 067557/0279 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: CRABTREE, JASON; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 067557/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: QOMPLX, INC.
To: QOMPLX LLC
Reel/Frame 067566/0797 →
Continuity (22)
Continuation 17845826 · Jun 21, 2022
Continuation In Part 16983253 · Aug 3, 2020
Continuation In Part 16887304 · May 29, 2020
Continuation In Part 16837551 · Apr 1, 2020
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Related Publication 20250373660A1 · Dec 4, 2025
References Cited (58)
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 7530105B2 · Gilbert et al. · 2009 [cited by applicant]
US 7562304B2 · Dixon et al. · 2009 [cited by applicant]
US 8281121B2 · Nath et al. · 2012 [cited by applicant]
US 8615800B2 · Baddour et al. · 2013 [cited by applicant]
US 8631489B2 · Antonakakis · 2014 [cited by examiner]
US 8793758B2 · Raleigh et al. · 2014 [cited by applicant]
US 8914878B2 · Burns et al. · 2014 [cited by applicant]
US 8973141B2 · Rowland et al. · 2015 [cited by applicant]
US 9141805B2 · Giakouminakis et al. · 2015 [cited by applicant]
US 9256735B2 · Stute · 2016 [cited by applicant]
US 9384345B2 · Dixon et al. · 2016 [cited by applicant]
US 9560065B2 · Neil et al. · 2017 [cited by applicant]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9654495B2 · Hubbard et al. · 2017 [cited by applicant]
US 9749336B1 · Zhang · 2017 [cited by examiner]
US 9762443B2 · Dickey · 2017 [cited by applicant]
US 9887933B2 · Lawrence, III · 2018 [cited by applicant]
US 9965627B2 · Ray et al. · 2018 [cited by applicant]
US 9967264B2 · Harris et al. · 2018 [cited by applicant]
US 9967282B2 · Thomas et al. · 2018 [cited by applicant]
US 9967283B2 · Ray et al. · 2018 [cited by applicant]
US 9992228B2 · Ray et al. · 2018 [cited by applicant]
US 10055473B2 · Allen et al. · 2018 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10083236B2 · Crosby · 2018 [cited by applicant]
US 10122687B2 · Thomas et al. · 2018 [cited by applicant]
US 10218736B2 · Ng et al. · 2019 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 10367830B2 · Laswell et al. · 2019 [cited by applicant]
US 10623284B2 · Yadav et al. · 2020 [cited by applicant]
US 10715534B2 · Sander et al. · 2020 [cited by applicant]
US 10965711B2 · Schiappa et al. · 2021 [cited by applicant]
US 11102093B2 · Gupta et al. · 2021 [cited by applicant]
US 11171982B2 · Vajipayajula et al. · 2021 [cited by applicant]
US 20040255167A1 · Knight · 2004 [cited by examiner]
US 20060253580A1 · Dixon · 2006 [cited by examiner]
US 20060253581A1 · Dixon · 2006 [cited by examiner]
US 20060253584A1 · Dixon · 2006 [cited by examiner]
US 20120023142A1 · Diorio · 2012 [cited by examiner]
US 20130304623A1 · Kumar et al. · 2013 [cited by applicant]
US 20140282871A1 · Rowland · 2014 [cited by examiner]
US 20150180903A1 · Cooper · 2015 [cited by examiner]
US 20160078225A1 · Ray · 2016 [cited by examiner]
US 20160080399A1 · Harris · 2016 [cited by examiner]
US 20160080417A1 · Thomas · 2016 [cited by examiner]
US 20160080418A1 · Ray · 2016 [cited by examiner]
US 20160080419A1 · Schiappa · 2016 [cited by examiner]
US 20160080420A1 · Ray · 2016 [cited by examiner]
US 20160140519A1 · Trepca et al. · 2016 [cited by applicant]
US 20160191465A1 · Thomas · 2016 [cited by examiner]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20160350442A1 · Crosby · 2016 [cited by examiner]
US 20180013774A1 · Sander · 2018 [cited by examiner]
US 20200382547A1 · Basballe Sorensen et al. · 2020 [cited by applicant]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]