Cybersecurity profiling via cyber-physical graph analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity rating methods, such as CVSS, fail to provide comprehensive profiles and ratings for organizations due to their inability to incorporate sufficient information about infrastructure, operations, and context, leading to inadequate assessment of cybersecurity vulnerabilities and risks.

Innovation Solution

A system and method that generates comprehensive security profiles and ratings by gathering data on an organization's infrastructure, operations, and context, using active and passive internal and external reconnaissance to create a cyber-physical graph, which is then analyzed to estimate cyber-attack frequency and severity, identify risks, and assign resilience and cybersecurity scores.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing cybersecurity rating methods (e.g., CVSS) are used, then the assessment process is simple and quick, but the comprehensiveness and accuracy of the cybersecurity profile is insufficient

Engineering Contradiction:
Improvecybersecurity profile accuracyVSAvoidassessment system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the cybersecurity assessment into multiple distinct modules: data gathering module, cyber-physical graph creation module, reconnaissance module, scoring module, and rating module. Each module handles specific aspects of the assessment, allowing the system to process complex information systematically while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cyber-physical graph as an intermediary data structure that connects organizational infrastructure data with cybersecurity vulnerabilities. This graph serves as a mediator that integrates diverse data sources (network topology, assets, vulnerabilities, threats) into a unified representation, enabling comprehensive analysis without requiring direct complex interactions between all data elements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive data gathering about organization infrastructure and operations is performed, then the cybersecurity profile becomes more accurate, but the time and resources required increase exponentially

Engineering Contradiction:
Improvecybersecurity assessment accuracyVSAvoidprofile generation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by creating a cyber-physical graph that pre-organizes organizational infrastructure data, assets, and relationships before the actual cybersecurity assessment begins. This preliminary structuring of data enables faster querying and analysis during the reconnaissance and scoring phases, reducing the time required for comprehensive assessment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of data organization from unstructured or semi-structured formats to a structured graph-based representation. This parameter change in data structure enables efficient traversal and analysis of organizational infrastructure, allowing the system to process comprehensive data within reasonable time frames by optimizing the way data is stored and accessed.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple data sources and reconnaissance methods are used, then the cybersecurity risks are more thoroughly identified, but the complexity of data processing and analysis increases

Engineering Contradiction:
Improverisk identification completenessVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal cyber-physical graph data structure that can represent and integrate multiple types of data sources and reconnaissance results in a unified framework. This multi-functional graph structure can accommodate network topology, physical infrastructure, digital assets, vulnerabilities, threats, and controls simultaneously, simplifying the processing of diverse data sources through a single versatile data model.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11750659B2Cybersecurity profiling and rating using active and passive external reconnaissance
Publication Date: 2023.09.05 QOMPLX INC
  • US11750659B2 patent drawing
  • US11750659B2 patent drawing
  • US11750659B2 patent drawing

AI summary

A system and method for generating comprehensive security profiles and ratings for organizations that takes into account the organization's infrastructure and operations in generating the profile, and the context and purpose of the rating to be generated related to the profile. The system and method may further comprise gathering data about the totality of the organization's infrastructure and operations, generating a cybersecurity profile using active and passive internal and external reconnaissance of the organization to determine cybersecurity vulnerabilities and potential impacts to the business in light of the information gathered about the organization's infrastructure and operations, and generating cybersecurity scores and ratings that take into account all of the above information, plus the context and purpose of the score or rating to be generated based on the cybersecurity profile.