Cybersecurity Rating via Active Passive Reconnaissance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems lack an efficient method for performing active and passive external reconnaissance to effectively assess and rate the cybersecurity posture of organizations, especially given the vastness of IPv4 address space and the speed of modern network scanning technologies.

Innovation Solution

A system and method utilizing a web crawler to send message prompts to external hosts, a time-series data store to produce time-series data from responses, and a directed computational graph module to analyze this data and produce a weighted cybersecurity score, integrating active and passive reconnaissance for comprehensive cybersecurity ratings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If massive port scanning across the entire IPv4 space is performed, then comprehensive cybersecurity assessment is achieved, but the time and computational resources required increase significantly

Engineering Contradiction:
Improvecybersecurity assessment accuracyVSAvoidscanning time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the IPv4 address space into smaller subnets and performs scanning on individual subnets rather than the entire space at once. This allows the system to assess cybersecurity posture of specific organizational networks efficiently without the prohibitive time cost of scanning all 4.3 billion IP addresses, while maintaining assessment accuracy through systematic subnet-level analysis

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by first identifying and mapping organizational network boundaries and asset inventories before conducting security scans. This preliminary reconnaissance phase allows the system to focus scanning efforts only on relevant network segments and assets, reducing unnecessary scanning time while ensuring comprehensive coverage of actual organizational infrastructure

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive external reconnaissance is performed across all network hosts, then complete vulnerability identification is achieved, but the complexity of data processing and analysis increases

Engineering Contradiction:
Improvevulnerability identification completenessVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple reconnaissance techniques (port scanning, service identification, vulnerability detection, and asset inventory) into a unified security assessment platform. By combining these functions into a single integrated system with centralized data processing, the patent reduces the complexity that would arise from managing separate tools while maintaining complete vulnerability identification across all network hosts

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system introduces an intermediary layer consisting of centralized data processing servers and standardized data formats that mediate between the distributed scanning operations and the analysis phase. This intermediary infrastructure manages the complexity of processing data from multiple hosts by providing standardized interfaces and centralized coordination, allowing comprehensive vulnerability identification without proportional increases in processing complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11601475B2Rating organization cybersecurity using active and passive external reconnaissance
Publication Date: 2023.03.07 QOMPLX INC
  • US11601475B2 patent drawing
  • US11601475B2 patent drawing
  • US11601475B2 patent drawing

AI summary

A system for cybersecurity rating using active and passive external reconnaissance, that uses a web crawler that sends message prompts to external hosts and receives responses from external hosts, a time-series data store that produces time-series data from the message responses, and a directed computational graph module that analyzes the time-series data to produce a weighted score representing the overall cybersecurity state of an organization.