IP Library Patent Application 19030944
Patent Application
App. No. 19/030,944

CORRELATING NETWORK EVENT ANOMALIES USING ACTIVE AND PASSIVE EXTERNAL RECONNAISSANCE TO IDENTIFY ATTACK INFORMATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/030,944
Filed
Jan 17, 2025
Art Unit
2497
USPC
726/22
Abstract

A system and method for correlating network event anomalies to identify attack information, that identifies anomalous events within the network, identifies correlations between anomalies and other network events and resources, generates a behavior graph describing an attack pathway derived from the correlations, and determines an attack point of origin using the behavior graph.

Claims (32)

1 . A computer system comprising a hardware memory, wherein the computer system is configured to execute software instructions stored on nontransitory machine-readable storage media that:

create a cyber-physical graph comprising nodes representing entities and edges representing relationships between the entities;

perform a reconnaissance search using the cyber-physical graph;

create a normal behavior model based on results of the reconnaissance search;

identify an anomalous event based on analysis of the cyber-physical graph and the normal behavior model;

generate a behavior graph based on correlations between nodes affected by the anomalous event; and

analyze the behavior graph to identify at least one starting condition associated with the anomalous event.

2 . The computer system of claim 1 , wherein the starting conditions comprise a node identified as the point-of-origin for the anomalous event.

3 . The computer system of claim 1 , wherein the information about the organization further comprises information about business processes within the organization.

4 . The computer system of claim 1 , wherein the information about the organization further comprises prior loss information for the organization.

5 . The computer system of claim 1 , wherein the reconnaissance search comprises both active and passive reconnaissance.

6 . The computer system of claim 1 , wherein the reconnaissance search includes collecting domain name service (DNS) information to create a DNS trust map.

7 . The computer system of claim 1 , wherein generating the behavior graph comprises identifying behavioral interactions between affected processes and resources using established known behavior patterns.

8 . The computer system of claim 1 , wherein the computer system is further configured to generate a network resilience rating based on the behavior graph.

9 . The computer system of claim 1 , wherein the computer system is further configured to perform continuous monitoring of network events to update the normal behavior model.

10 . The computer system of claim 1 , wherein identifying the anomalous event comprises comparing observed behavior against a configured threshold for aberrance.

11 . A method for correlating network event anomalies to identify attack information, comprising the steps of:

creating a cyber-physical graph comprising nodes representing entities and edges representing relationships between the entities;

performing a reconnaissance search using the cyber-physical graph;

creating a normal behavior model based on results of the reconnaissance search;

identifying an anomalous event based on analysis of the cyber-physical graph and the normal behavior model;

generating a behavior graph based on correlations between nodes affected by the anomalous event; and

analyzing the behavior graph to identify at least one starting condition associated with the anomalous event.

12 . The method of claim 11 , wherein the starting conditions comprise a node identified as the point-of-origin for the anomalous event.

13 . The method of claim 11 , wherein the information about the organization further comprises information about business processes within the organization.

14 . The method of claim 11 , wherein the information about the organization further comprises prior loss information for the organization.

15 . The method of claim 11 , wherein the reconnaissance search comprises both active and passive reconnaissance.

16 . The method of claim 11 , wherein the reconnaissance search includes collecting domain name service (DNS) information to create a DNS trust map.

17 . The method of claim 11 , wherein generating the behavior graph comprises identifying behavioral interactions between affected processes and resources using established known behavior patterns.

18 . The method of claim 11 , wherein the computer system is further configured to generate a network resilience rating based on the behavior graph.

19 . The method of claim 11 , wherein the computer system is further configured to perform continuous monitoring of network events to update the normal behavior model.

20 . The method of claim 11 , wherein identifying the anomalous event comprises comparing observed behavior against a configured threshold for aberrance.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2026
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 074939/0607 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2025
From: CRABTREE, JASON; SELLERS, ANDREW; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 071735/0595 →