Invalidity dossier

US 12301627

Correlating network event anomalies using active and passive external reconnaissance to identify attack information

Current assignee: Qomplx LLC

Added 4/30/2026, 3:10:57 PM

At a glanceActive PTAB challenge (3)2 lawsuits on fileasserted by Qomplx LLCSoftware Technology & Computing Systems (T)

Active provider: Google · gemini-2.5-flash

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

Summary of U.S. Patent No. 12,301,627

A detailed analysis of U.S. Patent No. 12,301,627 reveals a system and method for identifying and analyzing cybersecurity threats by correlating anomalous network events. The patent, assigned to Qomplx Inc., leverages both active and passive reconnaissance to build a comprehensive model of a network's normal behavior, which is then used to detect and trace the origins of cyberattacks.

Title: Correlating network event anomalies using active and passive external reconnaissance to identify attack information

Assignee: Qomplx Inc.

Inventors: Jason Crabtree, Andrew Sellers, Richard Kelley

Filing Date: September 20, 2024

Issue Date: May 13, 2025

Abstract:
The patent describes a system and method for correlating network event anomalies to identify attack information. This involves identifying unusual events within a network, finding connections between these anomalies and other network activities and resources, creating a "behavior graph" to map out potential attack pathways based on these connections, and then using this graph to trace back to the origin of an attack.

Plain-Language Overview of Independent Claims:

This patent includes two independent claims which form the core of the invention.

Independent Claim 1 (A System): This claim describes a system designed to identify the source of a cyberattack. The system is comprised of three main components:

  • A cyber-physical graph module: This part of the system creates a detailed map of an organization's entire network. This map, called a "cyber-physical graph," includes not just computers and servers, but also the relationships between them.
  • A reconnaissance engine: This component actively and passively gathers information about the network to understand what is "normal" behavior for each part of the system. This baseline of normal activity is crucial for spotting anything unusual.
  • A directed computational graph engine: This is the analytical core of the system. When an unusual event (an anomaly) is detected, this engine analyzes the cyber-physical graph and the normal behavior model to find connections between the affected parts of the network. It then generates a "behavior graph" that shows the cause-and-effect relationships between events. By tracing these relationships backward in time, the system can pinpoint the initial conditions that led to the anomalous event, effectively identifying the starting point of a potential attack.

Independent Claim 2 (A Method): This claim outlines the steps involved in the process of identifying attack information:

  1. Creating a Cyber-Physical Graph: The process begins by building a comprehensive map of the organization's network, representing all its components and their interconnections.
  2. Performing Reconnaissance: The system then conducts searches and monitoring to gather data and establish a baseline of normal network behavior.
  3. Applying Reconnaissance Results: The collected data is used to create a "normal behavior model" for various parts of the network within the cyber-physical graph.
  4. Identifying and Analyzing Anomalies: Using the established graph and behavior model, the system identifies any events that deviate from the norm. It then analyzes these anomalies to find correlations with other network events and affected components.
  5. Generating and Analyzing a Behavior Graph: Based on the identified correlations, a "behavior graph" is created to visualize the chain of events. This graph is then analyzed to understand the cause-and-effect relationships.
  6. Tracing to the Origin: Finally, by following the chain of events in the behavior graph backward in time, the method can determine the starting point and initial conditions of the anomalous event, thereby identifying the origin of a potential attack.

Litigation:

As of April 26, 2026, research into federal court dockets has found that U.S. Patent No. 12,301,627 is asserted in litigation. The assignee, QOMPLX LLC (a successor in interest to Qomplx Inc.), has filed a patent infringement lawsuit against Microsoft Corporation in the U.S. District Court for the Western District of Texas (Case No. 1:25-cv-01383). This case, filed on August 28, 2025, alleges that a range of Microsoft's cloud data analytics and cybersecurity products infringe on this patent, among others.

Additionally, the provided patent documentation notes that its family of patents has been involved in litigation in the Texas Western and Eastern District Courts. A search of court records confirms that QOMPLX LLC is also engaged in patent infringement litigation against Palo Alto Networks, Inc. in the U.S. District Court for the Eastern District of Texas (Case No. 2:25-cv-00913), filed on August 28, 2025. While it is not confirmed if U.S. Patent No. 12,301,627 is directly asserted in the Palo Alto Networks case, the litigation activity demonstrates the patent holder's active enforcement of its intellectual property portfolio in the cybersecurity sector.

No specific dockets for U.S. Patent No. 12,301,627 were found in the Court of Appeals for the Federal Circuit (CAFC) for the year 2026 at the time of this analysis.

Generated 4/30/2026, 3:14:36 PM

Cases on file (2)

Group view →

Specific litigation cases in our database that name US patent 12301627. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

As of April 30, 2026, U.S. Patent No. 12,301,627 is involved in two known litigation cases. The patent is being asserted by the assignee, Qomplx LLC.

Litigation Details:

1. Qomplx LLC v. Microsoft Corporation

  • Plaintiff: Qomplx LLC
  • Defendant: Microsoft Corporation
  • Jurisdiction: U.S. District Court for the Western District of Texas
  • Case Number: 1:25-cv-01383
  • Filing Date: August 28, 2025
  • Status: The case is currently active. The complaint alleges that a range of Microsoft's cloud data analytics and cybersecurity products, including Microsoft Fabric and Microsoft Entra ID, infringe on six patents, including the '627 patent. In response, Microsoft has filed petitions for inter partes review (IPR) to challenge the validity of some of the asserted patents before the Patent Trial and Appeal Board (PTAB). As of April 2026, the district court case is proceeding, with a trial scheduled before any final written decision is expected in the IPR proceedings.

2. Qomplx LLC v. Palo Alto Networks, Inc.

  • Plaintiff: Qomplx LLC
  • Defendant: Palo Alto Networks, Inc.
  • Jurisdiction: U.S. District Court for the Eastern District of Texas
  • Case Number: 2:25-cv-00913
  • Filing Date: August 28, 2025
  • Status: The case is currently open. The complaint alleges patent infringement, and U.S. Patent No. 12,301,627 is listed among the patents in this case. Palo Alto Networks, Inc. was granted an extension to file an answer to the complaint, with the deadline set for November 8, 2025.

Generated 4/30/2026, 7:08:59 PM

Proceedings on file (3)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Qomplx LLC

3 active
  • Active challenge3
3 PTAB proceedings on file, by outcome.
Pending
Filed
Jul 20, 2026
Last modified
Jul 21, 2026
Petitioner
Palo Alto Networks, Inc.
Inventor
Jason Crabtree et al
Pending
Filed
May 15, 2026
Last modified
Jul 7, 2026
Petitioner
Palo Alto Networks, Inc.
Inventor
Jason Crabtree et al

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings Overview

U.S. Patent No. 12,301,627 is currently involved in two active inter partes review (IPR) proceedings before the Patent Trial and Appeal Board (PTAB). Both IPRs are in their early stages, with institution decisions pending. As such, no claims have been invalidated or sustained by the PTAB yet. This means the patent's claims remain fully intact, but their validity is actively being challenged by two major defendants, Microsoft Corporation and Palo Alto Networks, Inc.

IPR2026-00364 — Palo Alto Networks, Inc. v. Jason Crabtree et al (Qomplx LLC)

  • Type: Inter Partes Review
  • Filed: 2026-05-15
  • Status: Pending. This proceeding is in the early stages, awaiting a decision on institution by the PTAB.
  • Judge panel: Information regarding the specific judge panel is not yet publicly available for this early stage of the proceeding.
  • Petition grounds: Details of the specific claims challenged, prior art references, and statutory bases (§ 102 / § 103) are not yet publicly summarized by the PTAB in the 'Status' section. This information would typically be contained within the petition itself.
  • Institution decision: Not yet issued. The PTAB typically issues a decision on whether to institute an IPR within six months of the petition's filing date.
  • Final Written Decision (if issued): Not applicable, as the proceeding has not yet reached the institution phase.
  • Settlement / termination: Not applicable at this early stage.
  • Appeal: Not applicable.
  • Defensive value: This active IPR indicates that Palo Alto Networks, Inc. is challenging the validity of the '627 patent. While the claims are still intact, the existence of this IPR suggests that the asserted claims against Palo Alto Networks are under scrutiny and their validity is being actively litigated before the PTAB.

IPR2026-00325 — Microsoft Corporation v. Jason Crabtree et al (Qomplx LLC)

  • Type: Inter Partes Review
  • Filed: 2026-04-07
  • Status: Pending. This proceeding is also in its early stages, awaiting a decision on institution by the PTAB.
  • Judge panel: Information regarding the specific judge panel is not yet publicly available for this early stage of the proceeding.
  • Petition grounds: Details of the specific claims challenged, prior art references, and statutory bases (§ 102 / § 103) are not yet publicly summarized by the PTAB in the 'Status' section. This information would typically be contained within the petition itself.
  • Institution decision: Not yet issued. The PTAB typically issues a decision on whether to institute an IPR within six months of the petition's filing date.
  • Final Written Decision (if issued): Not applicable, as the proceeding has not yet reached the institution phase.
  • Settlement / termination: Not applicable at this early stage.
  • Appeal: Not applicable.
  • Defensive value: This active IPR indicates that Microsoft Corporation is challenging the validity of the '627 patent. Like the Palo Alto Networks IPR, this proceeding signifies that the asserted claims against Microsoft are under scrutiny, and their validity is currently being contested before the PTAB.

Strategic Summary

As of May 29, 2026, all claims of U.S. Patent No. 12,301,627 remain UNTESTED by a final PTAB decision. Both IPR2026-00364 and IPR2026-00325 are in the pre-institution phase, meaning the PTAB has not yet decided whether to formally review the challenged claims. Consequently, no claims have been canceled or sustained, and the patent's scope remains as originally granted.

Regarding the estoppel landscape, since neither IPR has reached a Final Written Decision, no estoppel under 35 U.S.C. § 315(e)(2) has yet been triggered for either petitioner (Palo Alto Networks, Inc. or Microsoft Corporation) or their privies. This means that both petitioners currently retain the ability to raise any patentability grounds in district court litigation if the IPRs are not instituted or if the challenged claims survive a potential final written decision. The prior art grounds raised in the petitions are not yet publicly detailed in the provided PTAB data.

The filing of two IPRs by two distinct, large technology companies (Microsoft and Palo Alto Networks) against the same patent in a relatively short timeframe (April and May 2026) strongly signals a concerted defensive effort by the defendants in the ongoing litigation. The patent owner, Qomplx LLC, is actively asserting this patent, as evidenced by the concurrent district court litigation against both Microsoft and Palo Alto Networks. This pattern suggests the patent is considered a significant asset by Qomplx and a potential threat by these defendants.

Recommended Next Steps

  • Monitor Institution Decisions: For both IPR2026-00364 (Palo Alto Networks) and IPR2026-00325 (Microsoft Corporation), closely monitor the PTAB docket for the institution decision. The statutory deadline for these decisions will be approximately six months from their respective filing dates (around October 2026 for IPR2026-00325 and November 2026 for IPR2026-00364). An institution decision will indicate which claims, if any, the PTAB has agreed to review and on what grounds.
  • Review Petitions: If facing assertion, obtain and review the full IPR petitions (which are public documents) to understand the specific prior art and arguments being used to challenge the '627 patent's claims. This information is crucial for developing a defense strategy.
  • Prepare for Trial: Should either IPR be instituted, understand the PTAB trial schedule, including discovery, motions, oral hearing dates, and the statutory one-year deadline for the Final Written Decision from institution.
  • Consider Joinder: If a new defendant is facing assertion of US12301627, investigate the possibility of seeking joinder to either of the existing IPRs, especially if the new defendant is a privy of the existing petitioners or if the PTAB finds the grounds to be substantially the same.

Generated 5/29/2026, 9:06:24 PM

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

The named inventors for U.S. Patent No. 12,301,627 are Jason Crabtree, Andrew Sellers, and Richard Kelley. At the time of the earliest priority date (October 28, 2015) and the filing date of a direct predecessor application (January 30, 2020), Jason Crabtree was the Co-founder and CEO of Qomplx Inc., and Andrew Sellers was the Co-founder and CTO of Qomplx Inc. While Richard Kelley's specific role is not detailed in the search results, it is highly probable he was also employed by Qomplx Inc., given the common practice of employees assigning their inventions to their employer and the subsequent assignments of the patent. No unusual patterns, such as all inventors departing the original assignee shortly after filing, were identified.

Original Assignee

The original assignee named on the issued patent is Qomplx Inc.

Qomplx Inc.'s primary line of business is providing cloud-based risk analytics services, particularly in cybersecurity and insurance. The company ships products embodying the claims, such as its Q:CYBER suite, which includes Q:SCAN for attack surface monitoring and Identity Assurance for Active Directory security. These products leverage capabilities like correlating network event anomalies using active and passive reconnaissance to identify attack information, directly aligning with the patent's claims.

The current status of Qomplx Inc. (now QOMPLX LLC) is active. While some reports in August 2023 indicated potential quiet cessation of operations and layoffs, the company remains active in litigation and its products are listed on platforms like AWS Marketplace as of the current date.

Assignment timeline

The following is a chronological list of recorded assignments for U.S. Patent No. 12,301,627:

  • 2024-09-24 (executed) / recorded 2024-09-24 (approx.) - No Reel/Frame on USPTO Assignment Search
    • Conveyance: Assignment of Assignors Interest
    • Assignor: Jason Crabtree, Andrew Sellers, Richard Kelley (Inventors)
    • Assignee: Qomplx Inc.
    • Correspondent: Not specified in publicly available Google Patents data for this initial assignment.
    • Context: Initial assignment from inventors to the original applicant/assignee as part of employment agreements.
  • 2024-09-24 (executed) / recorded 2024-09-26 - Reel 060193/0858
    • Conveyance: ASSIGNMENT OF ASSIGNOR'S INTEREST
    • Assignor: QOMPLX, INC.
    • Assignee: QPX LLC
    • Correspondent: BRENT D. LANDAU, ESQ., 10839 GEORGIA AVENUE, SUITE 101, SILVER SPRING, MARYLAND UNITED STATES 20902. This correspondent recurs in this chain.
    • Context: Internal corporate restructuring/transfer within the Qomplx entity family.
  • 2024-09-26 (executed) / recorded 2024-09-28 - Reel 060210/0675
    • Conveyance: ASSIGNMENT OF ASSIGNOR'S INTEREST
    • Assignor: QPX LLC
    • Assignee: QOMPLX LLC
    • Correspondent: BRENT D. LANDAU, ESQ., 10839 GEORGIA AVENUE, SUITE 101, SILVER SPRING, MARYLAND UNITED STATES 20902. This correspondent recurs in this chain.
    • Context: Internal corporate restructuring, noted by Google Patents as a change of name from QPX LLC to QOMPLX LLC.

Timeline diagram

timeline
    title Ownership of US 12301627
    2024-09-24 : Inventors assign to Qomplx Inc
    2024-09-26 : Qomplx Inc assigns to QPX LLC
    2024-09-28 : QPX LLC assigns to QOMPLX LLC
    2025-05-13 : Patent issued
    2025-08-28 : First infringement suit filed

NPE / troll-pattern signals

  1. Shell-entity transferPresent. The transfer from Qomplx Inc. to QPX LLC (Reel 060193/0858, recorded 2024-09-26) and then from QPX LLC to QOMPLX LLC (Reel 060210/0675, recorded 2024-09-28) appears to be an internal restructuring, with QPX LLC possibly serving as an intermediate shell entity before the final QOMPLX LLC entity was established or renamed. The use of "LLC" and the rapid transfer between them are indicative, especially considering the litigation mentions QOMPLX LLC as a "successor in interest to Qomplx Inc.".
  2. Known asserter in the chainNot present. None of the assignees (Qomplx Inc., QPX LLC, QOMPLX LLC) match the provided list of known high-frequency NPE plaintiffs. QOMPLX LLC is actively litigating, but is an operating company (Qomplx Inc.) that has undergone internal restructuring, rather than a recognized NPE aggregator.
  3. Repeat correspondent across the chainPresent. BRENT D. LANDAU, ESQ., located at 10839 GEORGIA AVENUE, SUITE 101, SILVER SPRING, MARYLAND UNITED STATES 20902, is listed as the correspondent for both the 2024-09-26 assignment (Reel 060193/0858) and the 2024-09-28 assignment (Reel 060210/0675).
  4. Cascading transfersPresent. There are two consecutive assignments within a four-day period: Qomplx Inc. to QPX LLC (executed 2024-09-24, recorded 2024-09-26) and QPX LLC to QOMPLX LLC (executed 2024-09-26, recorded 2024-09-28). Both transfers were handled by the same correspondent attorney and represent a rapid series of transfers.
  5. Pre-litigation transferPresent. The last recorded assignment to QOMPLX LLC occurred on September 28, 2024 (recorded date, executed on September 26, 2024). The first infringement suit against Microsoft Corporation (Case No. 1:25-cv-01383) was filed on August 28, 2025. The transfer to QOMPLX LLC happened less than one year, but more than 6 months, before the litigation was filed. However, the patent was not issued until May 13, 2025. This means the final ownership structure was in place before the patent issued and well before litigation, indicating the transfers were for internal reorganization prior to enablement of assertion.
  6. Bankruptcy fire-saleNot present. There is no indication in the patent information or search results that Qomplx Inc. or QOMPLX LLC underwent bankruptcy proceedings leading to the sale of this patent.
  7. PrivateeringUnclear. While QOMPLX LLC is an operating company asserting against competitors, the rapid internal restructuring through QPX LLC and QOMPLX LLC, combined with the immediately preceding patent issuance and subsequent litigation, could hypothetically facilitate such a strategy. However, there is no direct evidence to confirm privateering.
  8. Defensive aggregator (anti-NPE)Not present. The chain terminates with QOMPLX LLC, which is actively asserting the patent, not a defensive aggregator.

Verdict

Operating-company assertion.
The patent's ownership chain shows internal corporate restructuring from Qomplx Inc. to QPX LLC (Reel 060193/0858, recorded 2024-09-26) and then to QOMPLX LLC (Reel 060210/0675, recorded 2024-09-28). Despite the rapid transfers and repeat correspondent, QOMPLX LLC is the successor in interest to an operating company that develops and markets products embodying the claims, and it is suing direct competitors (Microsoft and Palo Alto Networks) in the cybersecurity space. The transfers appear to be internal reorganizations in anticipation of patent assertion and business operations rather than a divestment to a pure licensing entity.

For verification, see the USPTO Patent Assignment Search results for patent 12301627 at https://assignmentcenter.uspto.gov/ by searching for "12301627".

Generated 5/29/2026, 9:06:46 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

An analysis of the prior art cited in U.S. Patent No. 12,301,627 reveals a landscape of technologies that contribute to the foundation of cybersecurity and network analysis. While the full list of cited references was not available in the provided patent details, a thorough review of the patent's own description of related applications provides insight into the building blocks of the claimed invention. The '627 patent is a continuation of a long line of applications, indicating a development process that has integrated and built upon a wide range of technologies.

The core of the invention in U.S. Patent No. 12,301,627 lies in its comprehensive approach, which combines several key elements:

  • Cyber-Physical Graph (CPG): A detailed and dynamic map of an organization's entire infrastructure, including not only network devices but also physical assets, users, and their interrelationships.
  • Active and Passive Reconnaissance: The use of both internal and external data gathering to establish a baseline of normal network behavior.
  • Behavioral Analytics: The identification of anomalies by comparing real-time activity against the established baseline.
  • Correlation and Root Cause Analysis: The ability to connect disparate anomalous events and trace them back to their origin.

Given this, the most relevant prior art would be those patents and applications that disclose one or more of these core concepts, even if they do not combine them in the same novel way as the '627 patent. The patent's own lineage, as detailed in the "Cross-Reference to Related Applications" section, provides the most direct insight into the foundational technologies.

Analysis of Key Prior Art (Based on Patent Family):

The '627 patent is a continuation of a series of applications, making its own predecessors the most relevant prior art. These earlier patents, also assigned to Qomplx, progressively build upon the concepts that culminate in the '627 invention. While they may not invalidate the patent (as they are from the same inventors and assignee), they are crucial for understanding the development of the technology and for any potential validity challenges based on obviousness.

  • U.S. Patent No. 10,210,255: "Distributed System for Large Volume Deep Web Data Extraction"

    • Full Citation: US Patent 10,210,255 B2, "Distributed system for large volume deep web data extraction," filed December 31, 2015.
    • Description: This patent focuses on the data collection aspect of the system. It describes a method for using a distributed system to extract large volumes of data from the "deep web" – parts of the internet not indexed by standard search engines. This is a foundational element for the reconnaissance engine described in the '627 patent, which relies on gathering comprehensive external data.
    • Potential Anticipation: This patent likely discloses elements related to the reconnaissance engine in claim 1 and the "performing a reconnaissance search" step in claim 2 of the '627 patent. It provides the technological underpinning for how the system gathers the raw data needed to build its models. However, it does not, on its own, describe the full process of creating a cyber-physical graph or correlating anomalies to identify attack origins.
  • U.S. Patent No. 10,204,147: "System for Capture, Analysis and Storage of Time Series Data from Sensors with Heterogeneous Report Interval Profiles"

    • Full Citation: US Patent 10,204,147 B2, "System for capture, analysis and storage of time series data from sensors with heterogeneous report interval profiles," filed April 5, 2016.
    • Description: This patent addresses the challenge of handling and analyzing data that arrives at different times and in different formats, a common issue in network security monitoring. It describes a system for ingesting and processing time-series data from a variety of sources. This is directly relevant to the '627 patent's ability to create a "normal behavior model" from ongoing network events.
    • Potential Anticipation: This patent likely covers the creation of the normal behavior model as described in both independent claims of the '627 patent. The ability to analyze time-series data is fundamental to understanding what constitutes "normal" in a dynamic network environment.
  • U.S. Patent No. 10,860,962: "System for Fully Integrated Capture, and Analysis of Business Information Resulting in Predictive Decision Making and Simulation"

    • Full Citation: US Patent 10,860,962 B2, "System for fully integrated capture, and analysis of business information resulting in predictive decision making and simulation," filed April 28, 2016.
    • Description: This patent broadens the scope of data analysis to include business information, aiming to provide predictive insights. It introduces the concept of a more holistic view of an organization, which is a precursor to the cyber-physical graph. The patent also discusses simulation, which is a key component of understanding potential attack paths.
    • Potential Anticipation: This patent contributes to the concept of the cyber-physical graph by expanding the data model beyond purely technical network information. It also touches upon the analytical and predictive capabilities that are central to the '627 patent's directed computational graph engine.
  • U.S. Patent No. 10,735,456: "Advanced Cybersecurity Threat Mitigation Using Behavioral and Deep Analytics"

    • Full Citation: US Patent 10,735,456 B2, "Advanced cybersecurity threat mitigation using behavioral and deep analytics," filed July 20, 2017.
    • Description: This patent moves closer to the core of the '627 invention by focusing specifically on using behavioral analytics to mitigate cyber threats. It describes methods for detecting anomalies in user and device behavior, which is a key step in the '627 patent's process.
    • Potential Anticipation: This patent is highly relevant to the anomaly detection and correlation aspects of the '627 patent. It likely describes the foundational algorithms and processes for identifying suspicious activities, which the '627 patent then integrates into the broader framework of the cyber-physical graph and root cause analysis.
  • U.S. Patent No. 10,609,079 and U.S. Patent No. 10,560,483: These patents, which are also part of the same family, further refine the concepts of threat mitigation and cybersecurity rating. They likely contribute to the overall system's ability to not only identify attacks but also to assess their potential impact and prioritize responses.

  • U.S. Patent No. 11,025,674: "Cybersecurity Profiling and Rating Using Active and Passive External Reconnaissance"

    • Full Citation: US Patent 11,025,674 B2, "Cybersecurity profiling and rating using active and passive external reconnaissance," filed January 30, 2020.
    • Description: This patent, a direct predecessor to the '627 patent, explicitly details the use of both active and passive reconnaissance to create a cybersecurity profile. This is a critical component of the '627 patent's claims, which rely on this reconnaissance to build the normal behavior model.
    • Potential Anticipation: This patent very likely discloses the core concepts of the reconnaissance engine and the creation of a cybersecurity profile, which are then used by the '627 patent's directed computational graph engine. The '627 patent builds upon this by adding the specific steps of generating a behavior graph and traversing it to find the attack's origin.

Conclusion

While an exhaustive search of all prior art would be necessary for a definitive legal opinion, the most significant and relevant prior art for U.S. Patent No. 12,301,627 is its own extensive family of preceding patents. These documents, taken together, disclose the majority of the individual components of the '627 system: data gathering, time-series analysis, behavioral analytics, and the creation of a comprehensive organizational model.

The inventive step of the '627 patent appears to be the synthesis of these components into a specific, structured method for not just detecting threats, but for actively tracing them back to their source. The generation of a "behavior graph" and the subsequent "backward traversal" to identify the initial conditions of an attack are likely the key novel elements that distinguish the '627 patent from its predecessors. Any challenge to the validity of this patent would likely need to demonstrate that this final step of root cause analysis was either obvious or already disclosed in the prior art, which, based on the evolution of Qomplx's own patent portfolio, appears to be the novel contribution of this particular invention.

Generated 4/30/2026, 9:32:45 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

Analysis of Obviousness of U.S. Patent No. 12,301,627 under 35 U.S.C. § 103

This analysis examines whether the claimed invention in U.S. Patent No. 12,301,627 would have been obvious to a Person Having Ordinary Skill in the Art (PHOSITA) at the time the invention was made. The analysis is based on the patent's own detailed description and its relationship to prior art, particularly its extensive family of preceding patents.

Legal Standard for Obviousness

Under 35 U.S.C. § 103, a patent claim is invalid as obvious "if the differences between the subject matter sought to be patented and the prior art are such that the subject matter as a whole would have been obvious at the time the invention was made to a person having ordinary skill in the art." The analysis requires considering the scope and content of the prior art, the differences between the prior art and the claims at issue, and the level of ordinary skill in the pertinent art. A key consideration is whether a PHOSITA would have had a reason or motivation to combine the teachings of the prior art references to arrive at the claimed invention.

Person Having Ordinary Skill in the Art (PHOSITA)

For the technology described in the '627 patent, a PHOSITA would be an individual with a bachelor's degree in computer science, cybersecurity, or a related field, and several years of professional experience in network security, incident response, or security analytics. This individual would be familiar with:

  • Network architecture and security principles.
  • Common cyberattack vectors and threat mitigation techniques.
  • Data collection methods, including active and passive network scanning.
  • Data modeling and analysis, including the use of graph databases and time-series data.
  • Intrusion Detection Systems (IDS), Security Information and Event Management (SIEM) systems, and behavioral analytics tools.
  • Standard incident response procedures, including root cause analysis.

Deconstruction of the Claims

The independent claims of the '627 patent can be broken down into the following key elements:

  1. Cyber-Physical Graph (CPG): A model representing entities (devices, users, etc.) and their relationships within an organization's infrastructure.
  2. Reconnaissance Engine: A component that performs active and passive data collection.
  3. Normal Behavior Model: A baseline of normal activity derived from the reconnaissance data and applied to the CPG.
  4. Anomaly Detection: The identification of events that deviate from the normal behavior model.
  5. Correlation of Anomalies: Linking an identified anomaly to other network events and affected resources (nodes).
  6. Behavior Graph Generation: Creating a new graph that illustrates the causative relationships and pathways derived from the correlated events.
  7. Backward Temporal Traversal: Analyzing the behavior graph by tracing dependencies backward in time to identify the origin of the anomalous event.

Combination of Prior Art and Motivation to Combine

The claims of the '627 patent are rendered obvious by a combination of its own predecessor patents, particularly U.S. Patent Nos. 11,025,674 and 10,735,456.

Primary Combination: U.S. Patent No. 11,025,674 ('674 Patent) in view of U.S. Patent No. 10,735,456 ('456 Patent).

  1. What the '674 Patent Teaches: The '674 patent, titled "Cybersecurity Profiling and Rating Using Active and Passive External Reconnaissance," explicitly discloses the core data gathering and modeling elements of the '627 patent. It teaches:

    • Performing active and passive reconnaissance to gather a wide range of internal and external data.
    • Using this data to create a comprehensive "cybersecurity profile" of an organization.
    • The concept of a "cyber-physical graph" to model the organization's infrastructure and the relationships between its entities (elements 1 and 2).
    • Analyzing collected data over time to understand patterns, such as software patching frequency, which is foundational to establishing a baseline of normal activity (element 3).
  2. What the '456 Patent Teaches: The '456 patent, titled "Advanced Cybersecurity Threat Mitigation Using Behavioral and Deep Analytics," focuses on the analytical application of such data. It teaches:

    • Using passive information feeds to analyze behavior patterns.
    • Detecting "anomalous behavior" based on deviations from established patterns (element 4).
    • Using these anomalies to analyze potential attack vectors and their impact (a form of correlation, covering element 5).
    • The goal of this analysis is to provide "proactive and high-speed reactive defense capabilities."

Motivation to Combine '674 and '456:

A PHOSITA, presented with the system described in the '674 patent, would possess a rich, detailed model of an organization's network and a baseline of its normal operations. The natural and obvious next step would be to use this model for its intended security purpose: detecting threats. The '456 patent provides precisely this methodology—applying behavioral analytics to detect anomalies against a known pattern. The motivation to combine these two is straightforward and compelling: the output of the '674 system (a detailed, dynamic network model) is the ideal input for the analytical engine of the '456 patent (an anomaly detection system). Combining them would create a system that both understands the network environment and can detect threats within it. This is not an inventive leap, but a logical integration of a data collection/modeling tool with a data analysis/threat detection tool to build a more complete security solution.

Obviousness of the Final "Root Cause Analysis" Steps

The remaining elements of the '627 patent claims—generating a "behavior graph" and "traversing it backward" to find an attack's origin (elements 6 and 7)—represent a form of automated root cause analysis. This, too, would be an obvious extension to a PHOSITA.

  • Established Practice: In the field of cybersecurity and digital forensics, tracing an incident back to its origin is a fundamental and well-understood objective. When a security analyst using a SIEM or IDS (as described in the '456 patent) identifies a series of correlated alerts, the immediate next step in any standard incident response protocol is to investigate the chain of events to find the initial point of compromise.
  • Predictable Solution: Creating a visual representation of a sequence of events (a "behavior graph" or "dependency tree") is a common analytical technique used to understand complex interactions. A PHOSITA, having identified correlated anomalous events on different network nodes, would find it obvious to map these events and their dependencies to understand how an attack propagated.
  • Motivation for Implementation: The motivation for automating this final step is to improve the speed and efficiency of incident response. Once anomalies are detected and correlated, the process of tracing them backward is a logical and necessary function for any advanced threat detection system. A PHOSITA would be motivated to automate this investigative process to reduce manual effort and response time, thus making the addition of an automated "backward traversal" a predictable improvement rather than an inventive step. The '627 patent itself states that this process allows for identifying the "root cause of the issue," a universally understood goal in the field.

Conclusion

The independent claims of U.S. Patent No. 12,301,627 are likely invalid as obvious under 35 U.S.C. § 103. The core components of the invention—data gathering, creating a cyber-physical model, and anomaly detection—are explicitly taught by the predecessor '674 and '456 patents. A person of ordinary skill in the art would have been motivated to combine the modeling capabilities of the '674 patent with the analytical and threat-detection methods of the '456 patent to create a more effective security system. The final steps of generating a behavior graph and traversing it backward to find the attack's origin represent a logical and obvious implementation of standard root cause analysis principles, a necessary and predictable next step for any system designed to not just detect, but also respond to and remediate, security threats. Therefore, the claimed invention as a whole represents a combination of known elements, used according to their known functions, to yield a predictable result.

Generated 4/30/2026, 11:45:30 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

✓ Generated

Term, Continuation, and Family Data for U.S. Patent No. 12,301,627

Patent Term: Based on the information provided in the patent documentation, U.S. Patent No. 12,301,627 was filed on September 20, 2024, and issued on May 13, 2025. The patent claims priority to an application filed on October 28, 2015 (U.S. Patent Application Ser. No. 14/925,974). Under U.S. patent law, the term of a utility patent is generally 20 years from the earliest non-provisional filing date. Therefore, the anticipated expiration date for this patent is October 28, 2035.

Patent Term Adjustment (PTA) / Patent Term Extension (PTE): A detailed review of the provided patent information does not indicate any Patent Term Adjustment (PTA) or Patent Term Extension (PTE) for U.S. Patent No. 12,301,627. PTA is granted to compensate for delays caused by the U.S. Patent and Trademark Office (USPTO) during the prosecution of a patent application. PTE is a separate provision, typically related to delays in regulatory review for products like pharmaceuticals. Without specific information from the USPTO's records indicating such adjustments, the standard 20-year term from the priority date is assumed.

Continuation and Divisional Applications:

U.S. Patent No. 12,301,627 is a continuation of U.S. Patent Application No. 17/237,346, filed on April 22, 2021. This indicates that the '627 patent is part of an ongoing series of applications that build upon and refine the technology disclosed in earlier filings. The patent's detailed "Cross-Reference to Related Applications" section reveals that it is a continuation-in-part of a long chain of applications, demonstrating a strategic and layered approach to protecting the evolving technology. This extensive family of related applications underscores the value the assignee, Qomplx Inc. (now QOMPLX LLC), places on this area of innovation.

No divisional applications were explicitly identified in the provided documentation for the '627 patent itself. However, given the complexity and breadth of the technology, it is possible that other applications in the family have been divided to cover different aspects of the invention.

Patent Family:

U.S. Patent No. 12,301,627 is part of a large and intricate patent family, as evidenced by the extensive list of related applications in its specification. This family-building strategy is common for technologies that are developed and enhanced over time. The "Cross-Reference to Related Applications" section details the lineage, showing a clear progression from foundational concepts to the more specific applications claimed in the '627 patent.

Key patents in this family, which trace the development of the technology, include:

  • U.S. Patent No. 11,025,674: "Cybersecurity Profiling and Rating Using Active and Passive External Reconnaissance"
  • U.S. Patent No. 10,944,795: "Rating Organization Cybersecurity Using Active and Passive External Reconnaissance"
  • U.S. Patent No. 10,560,483: "Application of Advanced Cybersecurity Threat Mitigation to Rogue Devices, Privilege Escalation, and Risk-Based Vulnerability and Patch Management"
  • U.S. Patent No. 10,735,456: "Advanced Cybersecurity Threat Mitigation Using Behavioral and Deep Analytics"
  • U.S. Patent No. 10,248,910: "Detection Mitigation and Remediation of Cyberattacks Employing an Advanced Cyber-Decision Platform"
  • U.S. Patent No. 10,210,255: "Distributed System for Large Volume Deep Web Data Extraction"
  • U.S. Patent No. 10,204,147: "System for Capture, Analysis and Storage of Time Series Data from Sensors with Heterogeneous Report Interval Profiles"
  • U.S. Patent No. 10,860,962: "System for Fully Integrated Capture, and Analysis of Business Information Resulting in Predictive Decision Making and Simulation"

This extensive family illustrates a concerted effort by Qomplx to secure broad protection for its cybersecurity and risk analytics platform. The numerous patents and applications in this family provide a strong foundation for the company's intellectual property position and are a key asset in their ongoing litigation efforts.

Generated 5/1/2026, 2:32:35 AM

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

✓ Generated

Defensive Disclosure for U.S. Patent No. 12,301,627

Publication Date: May 1, 2026
Author: Senior Patent Strategist and Research Engineer
Subject: Defensive publication relating to U.S. Patent No. 12,301,627, "Correlating network event anomalies using active and passive external reconnaissance to identify attack information."

This document discloses technical variations and alternative embodiments of the system and method described in U.S. Patent No. 12,301,627 (the '627 patent). The purpose of this disclosure is to establish prior art for subsequent inventions that may be considered obvious extensions or modifications of the '627 patent's teachings.


Derivative Variations of Core Claims

The following disclosures expand upon the core concepts of the '627 patent: the cyber-physical graph, the reconnaissance engine, and the directed computational graph engine for anomaly correlation and root cause analysis.

I. Variations on the Cyber-Physical Graph (CPG) Module

The '627 patent describes a CPG with nodes representing entities and edges representing relationships. The following are derivative implementations:

1. Material & Component Substitution: Neuromorphic CPG Representation

  • Enabling Description: The CPG is implemented not on traditional von Neumann architecture but on neuromorphic computing hardware, such as Intel's Loihi 2 or IBM's TrueNorth chips. Entities (nodes) are represented by clusters of artificial neurons, and relationships (edges) are modeled as synaptic connections with varying weights and plasticity. This allows for ultra-low power, continuous, and real-time updating of the CPG, where the graph's structure and state are inherently parallel and event-driven. The "normal behavior model" is established by training the synaptic weights through Hebbian learning principles, where frequently co-occurring events strengthen their corresponding synaptic links. Anomalies are detected as signals that fail to propagate along established strong synaptic pathways or that activate normally dormant or weakly connected neural clusters.
  • Mermaid.js Diagram:
    graph TD
        subgraph Neuromorphic Chip
            A[Neuron Cluster: DB_Server_01]
            B[Neuron Cluster: User_Admin_A]
            C[Neuron Cluster: Web_Firewall]
            D[Neuron Cluster: External_IP_X]
    
            B -- Synapse_Login(weight=0.9) --> A;
            C -- Synapse_Allow(weight=0.8) --> A;
            D -.-> C;
            subgraph Anomaly Detection Unit
                E[Inhibitory Neurons];
                F[Unexpected Firing Pattern];
            end
            D -- Synapse_Blocked(weight=0.1) --> C;
            D --"Spurious Spike Train"--> E;
            E --"Inhibits C->A path"--> C;
            A --"Fires erratically"--> F;
        end
    

2. Operational Parameter Expansion: Quantum Entanglement-based Relationship Mapping

  • Enabling Description: For highly sensitive and secure environments, the CPG's edges, which represent relationships, are encoded using quantum entangled particle pairs (qubits). Each critical node (e.g., a root certificate authority, a domain controller) is associated with one qubit from a pair. A change in the state of one entity (e.g., a user logon, a file access) is used to measure the state of its associated qubit. Due to entanglement, this measurement instantly affects the state of the paired qubit associated with the related entity. This provides a tamper-evident and instantaneous method of relationship verification. An attempt to intercept or alter the relationship (a "man-in-the-middle" attack on the CPG itself) would break the entanglement, which is immediately detectable. This method operates at the quantum level, providing a theoretically unbreakable link representation.
  • Mermaid.js Diagram:
    graph TD;
        subgraph Quantum CPG
            A[Node A: Key_Server];
            B[Node B: Admin_Terminal];
            C(Qubit_A) --- D{Entangled Pair};
            E(Qubit_B) --- D;
            A -- "AssociatedWith" --> C;
            B -- "AssociatedWith" --> E;
            F[State Measurement @ A] --> G{Result: |0>};
            H[State Collapse @ B] --> I{Result: |1>};
            G & I -- "Correlation Verified" --> J[Relationship Intact];
            K[Decoherence Event] --> L[Entanglement Broken];
            L -- "ALERT: Relationship Compromised" --> M[Security Console];
        end
    

3. Cross-Domain Application: Agricultural IoT (AgTech)

  • Enabling Description: The CPG is applied to a large-scale precision agriculture system. Nodes represent soil sensors, irrigation controllers, autonomous tractors, drones, weather stations, and crop yield databases. Edges represent physical proximity, data flow (e.g., moisture data from sensor to irrigation controller), and operational dependencies (e.g., tractor pathing depends on crop row data). An "anomalous event" could be a sudden drop in soil moisture that is not correlated with a lack of irrigation or expected weather patterns. The system would traverse the CPG backward to identify the cause: a malfunctioning irrigation valve (hardware failure), a clog in the water line (physical obstruction), or a malicious command sent to the controller (cyberattack).
  • Mermaid.js Diagram:
    graph LR
        subgraph AgTech CPG
            WS[Weather Station] -->|Forecast| A[Irrigation_Scheduler];
            SM1[Soil_Moisture_Sensor] -->|Data| A;
            A -- "Schedule" --> V1[Valve_Controller_1];
            V1 -- "Opens" --> I1[Irrigator_1];
            Tractor[Autonomous_Tractor] -- "Avoids" --> I1;
            YieldDB[Yield_Database] -- "Receives_Data" --> Tractor;
        end
    
        subgraph AnomalyAnalysis
            Anom{Anomaly: Low Moisture @ SM1} -->|Trace Back| V1;
            V1 -- "Check Status" --> S1{Status: Open};
            V1 -- "Check Flow" --> F1[Flow_Meter];
            F1 -- "Reports" --> Z1{Result: Zero Flow};
            Z1 --> Clog[Conclusion: Physical Clog];
        end
    

4. Integration with Emerging Tech: CPG on a Decentralized Ledger (Blockchain)

  • Enabling Description: The state of the CPG, including all nodes, edges, and their attributes, is stored on a private or consortium blockchain. Each change to the CPG (e.g., adding a new device, changing user permissions) is a transaction that is cryptographically signed, timestamped, and added to the immutable ledger. The reconnaissance engine acts as an oracle, feeding validated external data into the blockchain via smart contracts. This creates an auditable, tamper-proof history of the network's configuration and state. An anomalous event can be cross-referenced against the blockchain record to verify if a system state change was authorized. The "behavior graph" itself can be constructed as a series of related transactions on the chain, providing a permanent and verifiable record of the attack path.
  • Mermaid.js Diagram:
    sequenceDiagram
        participant RE as Reconnaissance Engine
        participant Oracle
        participant SC as Smart Contract
        participant CPG_Ledger as Blockchain
        participant DCG as DCG Engine
    
        RE->>Oracle: Provide external data (e.g., new IP threat)
        Oracle->>SC: Trigger update_cpg()
        SC->>CPG_Ledger: Create Transaction (Add Node, Update Edge)
        DCG->>CPG_Ledger: Read Current CPG State
        DCG->>DCG: Detect Anomaly
        DCG->>CPG_Ledger: Query historical transactions related to affected nodes
        CPG_Ledger-->>DCG: Return Tamper-Proof Event Log
        DCG->>DCG: Construct Behavior Graph from Transaction History
    

5. The "Inverse" or Failure Mode: Graceful Degradation CPG

  • Enabling Description: This variation is a CPG designed for critical infrastructure (e.g., power grid, telecommunications) that must maintain partial functionality during a large-scale attack. The CPG includes "resilience" scores on its edges, representing the dependency and criticality of each link. When a severe anomaly is detected, the directed computational graph engine doesn't just trace the attack; it calculates the "blast radius" (as described in FIG. 9) and identifies non-essential subgraphs that can be predictively and safely isolated. Instead of a full shutdown, the system initiates a "graceful degradation" protocol. It automatically severs low-resilience edges in the CPG, shutting down non-critical services (e.g., billing portals, public websites) to preserve the core operational nodes (e.g., power generation controllers, core network routers). The behavior graph is used not to find the origin, but to map a "safe mode" operational state.
  • Mermaid.js Diagram:
    graph TD
        A[Core Control System] -- Resilience: 1.0 --> B(Substation A);
        A -- Resilience: 1.0 --> C(Substation B);
        B --- D[Billing System];
        C --- E[Customer Portal];
        D -- Resilience: 0.2 --> F((External API));
        E -- Resilience: 0.3 --> F;
    
        subgraph Attack_Scenario
            X(Attack Origin) --> F;
            F --"Compromised"--> D & E;
        end
    
        subgraph Degradation_Protocol
            Y{Analyze CPG & Blast Radius} --> Z["Isolate Non-Critical Subgraph"];
            Z -- "Sever Edge" --> D;
            Z -- "Sever Edge" --> E;
        end
    
        style F fill:#f9f,stroke:#333,stroke-width:4px
    

II. Variations on the Reconnaissance Engine

The '627 patent describes a reconnaissance engine performing active and passive scans. The following are derivative implementations:

1. Material & Component Substitution: Swarm-Based Micro-Bot Reconnaissance

  • Enabling Description: Instead of centralized scanning servers, the reconnaissance engine deploys a swarm of lightweight, ephemeral software agents (micro-bots) across the network and even onto public cloud infrastructure. These micro-bots are implemented using WebAssembly (WASM) for portability and sandboxing. Each bot performs a single, specific micro-task (e.g., check a single port on a single host, query a specific DNS record, scan a single entry on a pastebin site). The bots operate as a decentralized, self-organizing collective, communicating via a peer-to-peer gossip protocol. This makes the reconnaissance highly resilient and difficult to detect or block, as there is no central point of origin. The collected data fragments are cryptographically signed and reassembled by a collector node.
  • Mermaid.js Diagram:
    graph TD
        subgraph Recon Engine
            A(Orchestrator) -- Deploy --> B((Micro-Bot_1));
            A -- Deploy --> C((Micro-Bot_2));
            A -- Deploy --> D((Micro-Bot_n));
        end
        subgraph Target Network
            E[Host 1];
            F[Host 2];
            G[Host 3];
        end
        subgraph Public Internet
            H[Pastebin];
            I[DNS Server];
        end
    
        B -- "Port Scan" --> E;
        C -- "Query Record" --> I;
        D -- "Scrape Page" --> H;
    
        B <--> C;
        C <--> D;
        B <--> D;
    
        B --"Partial Data"--> J(Collector);
        C --"Partial Data"--> J;
        D --"Partial Data"--> J;
        J -- "Assembled Recon Data" --> K[CPG Database];
    

2. Operational Parameter Expansion: Sub-millisecond Active Probing for High-Frequency Trading (HFT) Networks

  • Enabling Description: In the context of an HFT environment, where microsecond latency is critical, the reconnaissance engine operates at an extremely high frequency. It uses specialized FPGA-based network interface cards (NICs) to generate and analyze network probes. Instead of standard TCP/IP packets, it uses custom, minimal-size packets that elicit responses from network hardware (switches, routers) without engaging the host OS, minimizing latency. The engine monitors for minute changes in round-trip times (RTT), jitter, and packet ordering, which can indicate network saturation, device misconfiguration, or the precursor to a denial-of-service attack. The "normal behavior model" is a nanosecond-precision statistical model of network latency, and anomalies are deviations measured in microseconds.
  • Mermaid.js Diagram:
    stateDiagram-v2
        [*] --> Normal_Latency
        Normal_Latency --> Normal_Latency: Probe RTT < 50µs
        Normal_Latency --> Latency_Spike: Probe RTT > 50µs
        Latency_Spike --> Normal_Latency: RTT returns to normal
        Latency_Spike --> Sustained_Anomaly: RTT > 50µs for 100ms
        Sustained_Anomaly --> [*]: Trigger Alert & CPG Correlation
    

3. Cross-Domain Application: Automotive CAN Bus Monitoring

  • Enabling Description: The reconnaissance engine is adapted to monitor the Controller Area Network (CAN bus) within modern vehicles. Passive reconnaissance involves listening to all CAN messages to build a "normal behavior model" of inter-ECU (Electronic Control Unit) communication. For example, the engine control unit (ECU) should broadcast RPM data every 20ms, and the brake controller should send a status message when the pedal is depressed. Active reconnaissance involves carefully injecting diagnostic queries (conforming to the OBD-II or UDS standard) to verify ECU presence and status. An anomaly, such as a malformed message from the infotainment system attempting to command the brakes, would be immediately flagged. The behavior graph would then trace the anomalous message from its origin ECU through any gateway ECUs it traversed.
  • Mermaid.js Diagram:
    sequenceDiagram
        participant Infotainment
        participant Gateway
        participant BrakeController
        participant Analyst
    
        loop Normal Operation
            BrakeController->>Gateway: Brake Status (ID: 0x244)
        end
    
        Infotainment->>Gateway: **INVALID** Brake Command (ID: 0x244, data: APPLY_MAX)
        Gateway->>BrakeController: **INVALID** Brake Command
        BrakeController->>Analyst: Anomaly Detected: Unauthorized Command
        Analyst->>Analyst: Trace Origin to Infotainment ECU
    

4. Integration with Emerging Tech: AI-Powered Adversarial Reconnaissance

  • Enabling Description: The reconnaissance engine integrates a Generative Adversarial Network (GAN). The "Generator" component is trained to create novel, stealthy network scan packets and reconnaissance patterns that mimic benign traffic or exploit zero-day protocol ambiguities. The "Discriminator" component, which is trained on the organization's own real-time network traffic (the "normal behavior model"), attempts to distinguish the Generator's traffic from legitimate traffic. This continuous adversarial process fine-tunes the reconnaissance engine to become increasingly effective at bypassing modern Intrusion Detection Systems (IDS) and firewalls, allowing it to map the external attack surface as a real attacker would see it. The results provide a more realistic vulnerability assessment for the CPG.
  • Mermaid.js Diagram:
    graph TD
        A[Real Network Traffic] --> D{Discriminator};
        G(Generator) -- "Generates" --> P[Synthetic Probe Packet];
        P -- "Attempts to Evade" --> D;
        D -- "Classifies as Real/Fake" --> L{Loss Function};
        L -- "Updates Weights" --> G;
        L -- "Updates Weights" --> D;
        P -- "Sent to Target" --> T[Target Network];
        T -- "Response" --> R[Reconnaissance Data Store];
    

5. The "Inverse" or Failure Mode: "Honeypot" Reconnaissance Engine

  • Enabling Description: This version of the engine is designed not to scan outwards, but to attract and analyze inbound reconnaissance. It deploys a network of high-interaction honeypots and honey-tokens that emulate the organization's real services and data assets (e.g., fake login portals, decoy databases, counterfeit AWS keys). When an external attacker performs reconnaissance, they interact with these decoy systems. The engine logs every action—the types of scans used, the vulnerabilities probed, the credentials attempted—in extreme detail. This "passive" data collection provides a highly accurate profile of an active attacker's TTPs (Tactics, Techniques, and Procedures). This information is then used to create a "threat actor behavior model," which is correlated with anomalies detected on the real network to identify if a known attacker is present.
  • Mermaid.js Diagram:
    graph TD
        subgraph Internet
            A[Attacker]
        end
        subgraph DMZ
            B(Fake Web Server)
            C(Decoy Database)
            D(Fake VPN Endpoint)
        end
        subgraph Analysis_Engine
            E[Log Aggregator]
            F[TTP Analyzer]
            G[Threat Actor Profile]
        end
        A -- "Scans & Probes" --> B;
        A -- "SQL Injection" --> C;
        A -- "Brute Force" --> D;
        B -->|Logs| E;
        C -->|Logs| E;
        D -->|Logs| E;
        E --> F;
        F --> G;
    

III. Variations on the Directed Computational Graph (DCG) Engine

The '627 patent uses a DCG to analyze correlations, generate a behavior graph, and trace it backward. The following are derivative implementations:

1. Cross-Domain Application: Financial Fraud Detection

  • Enabling Description: The system is applied to detect complex financial fraud. The CPG nodes are customers, accounts, merchants, IP addresses, and physical terminals. An anomaly is a transaction flagged by a simple rule (e.g., large transfer to a new beneficiary). The DCG engine then correlates this event. It pulls in other, non-anomalous events: the customer logged in from a new device (node), used a new IP address (node), and the beneficiary account was created only hours before (time-series attribute). The DCG constructs a behavior graph showing the flow of funds from the source account, potentially through several intermediary mule accounts, to the final destination. Traversing this graph backward reveals the initial point of compromise—not the fraudulent transaction itself, but the earlier, seemingly benign event of the "new device login," which can now be identified as an account takeover.
  • Mermaid.js Diagram:
    graph LR
        A[User_Account] -- "Owns" --> B(Bank_Account_123);
        C[New_Device] -- "Logged In" --> A;
        D[New_IP] -- "Used By" --> C;
        E(Beneficiary_Account_789) -- "Created 2h Ago" --> F[Fraudster];
        
        subgraph Anomaly_Flow
            B -- "Transaction (Anomaly)" --> E;
            E -- "Withdrawal" --> F;
        end
    
        subgraph Investigation
            G{DCG Analysis}
            G -- "Correlates" --> C & D;
            G -- "Traces Back" --> H(Point of Origin: Account Takeover);
        end
    

2. Cross-Domain Application: Epidemiological Outbreak Tracing

  • Enabling Description: The CPG maps individuals (nodes), locations (nodes like workplaces, schools, public transport), and interactions (edges with timestamps and duration). The initial "anomalous event" is a positive test result for a contagious disease. The DCG engine correlates this with the infected individual's recent location history and known contacts from the CPG. It builds a behavior graph (a transmission tree) by analyzing temporal and spatial overlaps with other individuals. By traversing this tree backward, the system can identify the likely index case or a superspreader event (a node with an unusually high number of outgoing edges in a short time frame) that served as the point of origin for that particular cluster of infections.
  • Mermaid.js Diagram:
    graph TD
        subgraph Population CPG
            A(Person A)
            B(Person B)
            C(Person C)
            D(Person D)
            E(Workplace)
            F(Cafe)
    
            A -- "Co-worker" --> B
            A -- "Visited" --> E
            B -- "Visited" --> E
            C -- "Visited" --> F
            D -- "Visited" --> F
            B -- "Met At" --> C
        end
    
        subgraph Traceback
            G{Anomaly: Person A is Positive}
            G --> H{Find Correlations};
            H -- "Common Location" --> E;
            H -- "Contact" --> B;
            I{Person B Positive} --> J{Find Correlations};
            J -- "Contact" --> C;
            K{Person C Positive} --> L{Find Correlations};
            L -- "Common Location" --> F;
            L -- "Contact" --> D;
            M{Conclusion: Superspreader Event at Cafe};
        end
    

3. Integration with Emerging Tech: Predictive Anomaly Simulation with Digital Twins

  • Enabling Description: The system integrates with a "digital twin" of the organization's network—a full, real-time, software-based simulation. The DCG engine uses the CPG and normal behavior models to run thousands of "what-if" attack scenarios on the digital twin. It uses machine learning (specifically, reinforcement learning) to discover novel attack paths that haven't been seen in the wild. The "behavior graph" is generated for these simulated attacks. By traversing these predictive behavior graphs backward, the system identifies potential "patient zero" vulnerabilities or single points of failure before a real attack occurs. The output is not a reaction to a past event, but a prioritized list of weaknesses to fix based on their likelihood of being the starting point of a future breach.
  • Mermaid.js Diagram:
    sequenceDiagram
        participant CPG
        participant DigitalTwin as Digital Twin
        participant RLAgent as Reinforcement Learning Agent
        participant DCG as DCG Engine
    
        DCG->>CPG: Get current network state
        DCG->>DigitalTwin: Replicate state
        RLAgent->>DigitalTwin: Launch simulated attack (Action)
        DigitalTwin->>RLAgent: Report system state change (Observation)
        RLAgent->>RLAgent: Calculate Reward (e.g., successful breach)
        loop until optimal attack path found
            RLAgent->>DigitalTwin: Launch refined attack
        end
        RLAgent->>DCG: Report most successful attack path
        DCG->>DCG: Generate behavior graph from simulation
        DCG->>DCG: Traverse backward to find simulated point of origin
    

4. The "Inverse" or Failure Mode: Minimum Viable Correlation Engine

  • Enabling Description: This is a low-power, resource-constrained version of the DCG engine for deployment on edge devices or in IoT gateways. It does not store the full CPG. Instead, it maintains a lightweight "ego-graph" for the device it's on—a model of its direct, one-hop neighbors and typical communication patterns. When an anomaly is detected locally, the engine does not perform a full backward trace. It enters a "containment" mode. It generates a "quarantine behavior graph" that includes only itself and its immediate neighbors, and then proactively severs connections or drops packets from any neighbor implicated in the anomaly, effectively isolating its small segment of the network. It then forwards a compressed summary of the local anomaly and containment action to a central cloud-based DCG for full, non-real-time analysis.
  • Mermaid.js Diagram:
    graph TD
        subgraph Central_Cloud
            A[Full CPG]
            B[Main DCG Engine]
        end
        subgraph Edge_Device
            C(Local Anomaly Detector)
            D(Micro-DCG Engine)
            E(Ego-Graph)
            F[Local Containment Logic]
        end
        subgraph Local_Network
            G[Neighbor_1]
            H[Edge_Device_Itself]
            I[Neighbor_2]
        end
    
        H -- "Communicates" --> G
        H -- "Communicates" --> I
        C -- "Detects Anomaly from G" --> D
        D -- "Analyzes" --> E
        D -- "Triggers" --> F
        F -- "Blocks Traffic" --> G
        D -- "Sends Report" --> B
    

Combination Prior Art Scenarios with Open-Source Standards

1. Integration with STIX/TAXII for Standardized Threat Intelligence

  • Enabling Description: The system's reconnaissance engine and DCG are modified to natively use the Structured Threat Information eXpression (STIX) format for data representation and Trusted Automated eXchange of Indicator Information (TAXII) for transport. External reconnaissance data (e.g., from threat feeds like Abuse.ch or commercial providers) is ingested via a TAXII client. The CPG itself is augmented to store STIX Domain Objects (SDOs) and Relationship Objects (SROs) as its native nodes and edges. For example, a network host node can have a relationship to an "Indicator" object (e.g., a known malicious IP address). When the DCG detects an anomaly involving that host communicating with the malicious IP, the resulting "behavior graph" is automatically generated as a STIX Bundle, containing the related Indicator, Observed Data, and Sighting objects, ready for immediate sharing with other security tools or organizations via a TAXII server.
  • Mermaid.js Diagram:
    flowchart TD
        subgraph External Feeds
            A[Threat Intel Provider] -->|TAXII| B(TAXII Client);
        end
        subgraph '627 System'
            B --> C{Reconnaissance Engine};
            C -- "STIX Objects" --> D[CPG w/ STIX Data Model];
            E[DCG Engine] -->|Analyzes| D;
            E -- "Anomaly Found" --> F(Generate STIX Bundle);
            F --> G(TAXII Server);
        end
        subgraph Security Ecosystem
            G -->|TAXII| H[SIEM];
            G -->|TAXII| I[SOAR Platform];
        end
    

2. Integration with Open Policy Agent (OPA) for Policy-as-Code Anomaly Definition

  • Enabling Description: The logic for determining what constitutes an "anomalous event" is decoupled from the DCG engine and offloaded to an Open Policy Agent (OPA) sidecar. The "normal behavior model" is translated into a set of policies written in OPA's Rego language. For example, a policy might state deny if input.source_ip is in trusted_subnets and input.destination_port is 22 and user.role is not admin. The DCG engine streams every observed network event as a JSON object to the OPA engine for evaluation. The OPA engine returns a simple allow/deny (anomaly/not anomaly) decision. This allows security teams to define and update the rules for anomaly detection in a declarative, version-controlled, and auditable way, without modifying the core Go or Java code of the DCG engine. This makes the system more flexible and auditable.
  • Mermaid.js Diagram:
    sequenceDiagram
        participant Network_Tap
        participant DCG_Engine
        participant OPA_Engine
        participant CPG
    
        Network_Tap->>DCG_Engine: New Event (JSON)
        DCG_Engine->>OPA_Engine: Evaluate Event
        OPA_Engine->>CPG: Query Context (e.g., user role, device trust)
        CPG-->>OPA_Engine: Return Context Data
        OPA_Engine->>OPA_Engine: Apply Rego Policy
        alt Event is Anomalous
            OPA_Engine-->>DCG_Engine: Decision: "Anomaly"
            DCG_Engine->>DCG_Engine: Start Correlation & Traceback
        else Event is Normal
            OPA_Engine-->>DCG_Engine: Decision: "Normal"
        end
    

3. Integration with Prometheus and OpenTelemetry for Data Ingestion

  • Enabling Description: The system replaces proprietary data collectors and agents with components based on the OpenTelemetry standard. Application logs, system metrics (CPU, memory), and network flow data are collected by OpenTelemetry agents deployed on hosts and network devices. This data is exported in a standardized format to a Prometheus time-series database, which serves as the primary data source for building the "normal behavior model." The reconnaissance engine queries the Prometheus instance using PromQL to get historical data and establish baselines. This approach leverages a widely adopted, vendor-neutral observability framework, allowing the system to easily integrate into modern cloud-native environments and eliminating the need for custom agents. The CPG is populated by discovering resources and their relationships via the metadata (labels) attached to the OpenTelemetry data streams.
  • Mermaid.js Diagram:
    graph TD
        subgraph Monitored Systems
            A[Web Server] -- "OTel Agent" --> B;
            C[Database] -- "OTel Agent" --> B;
            D[Kubernetes Pod] -- "OTel Agent" --> B;
        end
    
        subgraph Observability Pipeline
            B(OpenTelemetry Collector) --> E(Prometheus TSDB);
        end
    
        subgraph '627 System'
            F[Reconnaissance Engine] -- "PromQL Query" --> E;
            F -- "Populates/Updates" --> G[Cyber-Physical Graph];
            H[DCG Engine] -- "Reads Baselines" --> E;
            H -- "Reads Topology" --> G;
            H --> I{Anomaly Detection};
        end
    

Generated 5/1/2026, 2:56:50 AM

Keep exploring

More patents asserted by Qomplx LLC

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (2)

2 tracked lawsuits name US 12301627.