Cybersecurity Risk Analysis Using Cyber-Physical Graph Reconnaissance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity rating methods, such as CVSS, fail to adequately profile and rate the cybersecurity profiles of organizations due to insufficient information incorporation, making it difficult to monitor critical infrastructure entities, identify anomalous network events, and assess associated risks.

Innovation Solution

A system and method for cybersecurity risk analysis and anomaly detection using active and passive external reconnaissance, which identifies critical network entities within a cyber-physical graph, determines the risk of identified anomalies based on entity values, and determines an effectiveness score for the network's cybersecurity implementation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If comprehensive data gathering about organization infrastructure and operations is performed, then cybersecurity profile accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvecybersecurity profile accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the cybersecurity assessment into distinct modules: data gathering module that collects infrastructure and operations data, cyber-physical graph construction module that models relationships, reconnaissance module that identifies vulnerabilities, and scoring module that generates ratings. This segmentation allows comprehensive data collection while managing system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cyber-physical graph as an intermediary data structure that mediates between raw organizational data and security assessment results. The graph transforms complex infrastructure and operations data into a structured representation of entities and relationships, enabling accurate cybersecurity profiling without overwhelming system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If active and passive reconnaissance searches are performed on the cyber-physical graph, then cybersecurity vulnerability detection is improved, but processing time increases

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary construction of the cyber-physical graph before conducting reconnaissance searches. By pre-processing organizational data into a structured graph format with defined entities, relationships, and attributes, the system prepares the data structure in advance, enabling faster and more efficient vulnerability detection during the reconnaissance phase without sacrificing detection comprehensiveness.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If criticality scores are assigned to multiple nodes in the cyber-physical graph, then risk assessment accuracy is improved, but computational complexity increases

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning criticality scores to individual nodes based on their specific characteristics, relationships, and importance to organizational operations. Each node receives a customized criticality assessment considering its local context within the cyber-physical graph, enabling precise risk assessment at the node level while managing computational complexity through localized evaluation rather than global analysis.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250047717A1Cybersecurity risk analysis and anomaly detection using active and passive external reconnaissance
Publication Date: 2025.02.06 QOMPLX INC
  • US20250047717A1 patent drawing
  • US20250047717A1 patent drawing
  • US20250047717A1 patent drawing

AI summary

A system and method for cybersecurity risk analysis and anomaly detection using active and passive external reconnaissance, that identifies critical network entities within a cyber-physical graph, identifies anomalous events within the network, determines the risk of identified anomalies based on the value of the entities involved, and determines an effectiveness score for the network based on the identified risks.