Cybersecurity Rating via Probe-Based Reconnaissance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems lack an efficient method for performing active and passive external reconnaissance using network scanning in conjunction with probe-based risk analysis, which is necessary for producing accurate cybersecurity ratings for organizations.

Innovation Solution

A system and method for cybersecurity rating using active and passive external reconnaissance, comprising a web crawler that sends message prompts to external hosts and receives responses, a time-series data store that produces time-series data from message responses, and a directed computational graph module that analyzes the time-series data to produce a weighted score representing the overall cybersecurity state of an organization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If massive port scanning is performed across the entire IPv4 space, then comprehensive security information is obtained, but the time and computational resources required increase significantly

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidscanning time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the IPv4 address space into multiple zones and performs scanning in parallel using multiple scanning threads. Each thread scans a specific segment simultaneously, reducing the total time required while maintaining comprehensive coverage of the entire address space for accurate security assessment

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary scanning of commonly targeted port ranges (such as ports 1-1024 and 1024-65535) before conducting comprehensive scans. This preliminary action identifies high-risk targets early, allowing the system to focus resources on the most critical assessment areas and reduce overall scanning time while maintaining assessment accuracy

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive network reconnaissance is performed, then accurate cybersecurity ratings are produced, but the complexity of the system increases

Engineering Contradiction:
Improvecybersecurity rating accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a multi-functional scanning system that performs multiple types of reconnaissance operations (port scanning, service detection, vulnerability assessment, and security rating) through a unified platform. This universal system consolidates what would otherwise require separate tools and processes, maintaining comprehensive assessment capabilities while reducing overall system complexity through integration

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the data collection, analysis, and rating generation processes into an integrated workflow. The scanning results are directly fed into the analysis engine which automatically generates cybersecurity ratings, eliminating the need for separate manual analysis steps and simplifying the overall system architecture while maintaining comprehensive assessment accuracy

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250175503A1Rating organization cybersecurity using probe-based network reconnaissance techniques
Publication Date: 2025.05.29 QPX LLC
  • US20250175503A1 patent drawing
  • US20250175503A1 patent drawing
  • US20250175503A1 patent drawing

AI summary

A system and methods for cybersecurity rating using active and passive external reconnaissance, comprising a web crawler that send message prompts to external hosts and receives responses from external hosts, a time-series data store that produces time-series data from the message responses, and a directed computational graph module that probes, scans, and fingerprints devices within a cyber-physical graph and analyzes the results as time-series data to produce a weighted score representing the overall cybersecurity state of an organization.