- Filed
- Apr 3, 2026
- Last modified
- Jul 31, 2026
- Petitioner
- Microsoft Corporation
- Inventor
- Jason Crabtree et al
Invalidity dossier
US 12301628
Correlating network event anomalies using active and passive external reconnaissance to identify attack information
Current assignee: Qomplx LLC
Added 4/30/2026, 3:10:58 PM
Active provider: Google · gemini-2.5-flash
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
Patent Analysis: US 12,301,628 B2
Date of Analysis: April 26, 2026
Patent Number: US 12,301,628 B2
Title: Correlating network event anomalies using active and passive external reconnaissance to identify attack information
Assignee: Qomplx Inc.
Inventors: Jason Crabtree, Andrew Sellers, Richard Kelley
Filing Date: September 20, 2024
Issue Date: May 13, 2025
Abstract:
The invention provides a system and method for correlating network event anomalies to identify attack information. This involves creating a cyber-physical graph of an organization, which maps entities and their relationships. A reconnaissance engine performs searches using this graph and applies the results to create a normal behavior model for various nodes. A directed computational graph engine then uses this model to identify anomalous events, analyze correlations between affected nodes, generate a behavior graph, and ultimately trace back to the origin of an attack by creating and analyzing a dependency tree.
Independent Claims Overview:
Independent Claim 1: A method for identifying attack information by:
- Creating a "cyber-physical graph" that maps an organization's entities (like users, devices, and data) and their relationships.
- Using this graph to perform reconnaissance and build a model of what constitutes "normal" behavior for the network.
- Detecting an anomalous event by comparing current activity to the normal behavior model.
- Analyzing the cyber-physical graph to find correlations between the nodes affected by the anomaly.
- Generating a "behavior graph" based on these correlations to show causative relationships between events.
- Tracing this behavior graph backward in time to pinpoint the origin of the anomalous event.
Independent Claim 9: A system designed to perform the method outlined in Claim 1. This system comprises:
- A cyber-physical graph module to create and manage the graph of the organization's assets and relationships.
- A reconnaissance engine to gather data and establish a baseline of normal behavior for the elements in the graph.
- A directed computational graph engine that actively analyzes the cyber-physical graph and the normal behavior model to detect anomalies, find correlations, create a behavior graph, and trace events back to their source.
Litigation Search:
A search of the CAFC (Court of Appeals for the Federal Circuit) dockets for 2026 for "US Patent 12,301,628" reveals that this patent family is involved in litigation, with the first worldwide family litigation filed in 2015. Specific details of the 2026 dockets were not available in the provided information.
Generated 4/30/2026, 7:07:22 PM
Cases on file (2)
Group view →Specific litigation cases in our database that name US patent 12301628. The free-form analysis below may also discuss cases beyond this list.
- Qomplx LLC v. Microsoft Corporationfiled Aug 28, 20251:25-cv-01383U.S. District Court for the Western District of Texas, Austin DivisionOpen
Defendants: Microsoft Corporation
- Qomplx LLC v. Palo Alto Networks, Inc.filed Aug 28, 20252:25-cv-00913U.S. District Court for the Eastern District of TexasOpen
Defendants: Palo Alto Networks, Inc.
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
As of April 30, 2026, US Patent No. 12,301,628 is involved in two known litigation cases. The patent is being asserted by the assignee, Qomplx LLC.
Here are the details of the known litigation:
Qomplx LLC v. Microsoft Corporation
- Plaintiff: Qomplx LLC
- Defendant: Microsoft Corporation
- Jurisdiction: U.S. District Court for the Western District of Texas, Austin Division
- Case Number: 1:25-cv-01383
- Filing Date: August 28, 2025
- Status: Open. The case is in its early stages, with preliminary infringement contentions and a scheduling order filed. The complaint alleges that a range of Microsoft's cloud data analytics and cybersecurity products, including Microsoft Fabric and Microsoft Entra ID, infringe upon six patents, including the '628 patent. Microsoft has also initiated an Inter Partes Review (IPR) against the '627 patent, which is related to the '628 patent.
Qomplx LLC v. Palo Alto Networks Inc.
- Plaintiff: Qomplx LLC
- Defendant: Palo Alto Networks, Inc.
- Jurisdiction: U.S. District Court for the Eastern District of Texas
- Case Number: 2:25-cv-00913
- Filing Date: August 28, 2025
- Status: Open. The complaint was filed for patent infringement. A jury trial has been demanded by Qomplx LLC.
Generated 4/30/2026, 7:07:35 PM
Proceedings on file (1)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
Current assignee: Qomplx LLC
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
Proceedings Overview
There is one pending Inter Partes Review (IPR) filed against U.S. Patent No. 12,301,628, which means the patent's validity is actively being challenged at the Patent Trial and Appeal Board (PTAB), offering a significant defensive opportunity for a company facing an infringement assertion.
IPR2026-00326 — Microsoft Corporation v. Qomplx Inc.
- Type: Inter Partes Review
- Filed: 2026-04-03
- Status: Pending. This proceeding is in its initial phase. The Patent Trial and Appeal Board has not yet decided whether to institute a trial.
- Judge panel: A judge panel has not yet been made public for this proceeding.
- Petition grounds: The IPR petition challenges claims 1-8 of the '628 patent as being obvious under 35 U.S.C. § 103 over a combination of prior art references. The primary combination asserts that the claimed invention is an obvious combination of the applicant's own prior art patents:
- Crabtree '464 (US 2017/0124464), which teaches the creation of a "cyber-physical system graph."
- Crabtree '910 (US 10,248,910), which teaches cybersecurity behavioral analytics to identify anomalies.
- Crabtree '147 (US 10,204,147), which teaches using the graph to calculate a "blast radius" by correlating affected resources.
- Institution decision: A decision on whether to institute a trial is not yet due. The statutory deadline for the PTAB to issue an institution decision is approximately October 3, 2026.
- Final Written Decision: Not yet issued. If a trial is instituted, a Final Written Decision would be due within one year of the institution date, approximately October 2027.
- Settlement / termination: There is no public record of settlement or termination.
- Appeal: Not applicable.
- Defensive value: This proceeding is highly valuable for a defendant. It indicates that Microsoft, a major technology company and co-defendant in parallel district court litigation, has identified what it believes are strong invalidity arguments. The petition and its accompanying expert declaration can serve as a detailed roadmap for another defendant's own invalidity contentions, potentially saving significant research and expert costs.
Strategic summary
Currently, all claims of the '628 patent remain valid and enforceable, as no PTAB proceeding has reached a final decision. However, claims 1-8 are under a significant challenge in IPR2026-00326. The patent has not been tested or narrowed in any prior PTAB proceeding.
Regarding estoppel, no party is currently estopped from challenging the '628 patent at the PTAB. If the pending IPR against Microsoft results in a Final Written Decision, Microsoft and any "real party in interest or privy" would be barred under 35 U.S.C. § 315(e)(2) from later asserting in district court or the ITC that the claims are invalid on any ground that they raised or reasonably could have raised in the IPR. Other potential defendants are not subject to this estoppel and can use the same art combinations, or different ones, in their own IPRs or in court.
The pattern here is clear: Microsoft's IPR filing is a direct defensive response to the district court litigation brought by Qomplx LLC. This is a standard tactic used by defendants to create a parallel, often faster and less expensive, proceeding at the PTAB to invalidate the asserted patent.
Recommended next steps
For a defendant currently facing an assertion of US Patent 12,301,628:
- Closely Monitor IPR2026-00326: The most critical upcoming milestone is the PTAB's institution decision, expected on or before October 3, 2026. A decision to institute would indicate the PTAB believes there is a "reasonable likelihood" that Microsoft will prevail in proving at least one challenged claim unpatentable.
- Obtain and Analyze the IPR Petition: The petition filed by Microsoft is a public document available on the PTAB's End-to-End (E2E) system. It contains a detailed breakdown of the prior art and expert testimony arguing for the invalidity of claims 1-8. This document is an invaluable resource for developing your own invalidity strategy. You can access the case file here: USPTO PTAB E2E for IPR2026-00326.
- Evaluate a "Tag-Along" IPR: Consider filing your own IPR petition against the '628 patent. You can leverage the arguments and art presented by Microsoft, potentially adding new references or improving upon their arguments. This would give you a seat at the table and prevent your case from being stayed pending the outcome of Microsoft's IPR without your direct involvement.
- Use the IPR in District Court Proceedings: The existence of the pending IPR can be a powerful tool in district court. You can use it to argue for a stay of the litigation pending the PTAB's review, which, if granted, could significantly delay and reduce litigation costs.
Generated 5/11/2026, 5:08:39 PM
Ownership chain (3)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
2024-09-20 · recorded 2024-09-24 · reel 56789/0123 · Assignment
Jason Crabtree, Richard Kelley, Andrew SellersQOMPLX, INC.
Correspondent: · Finnegan, Henderson, Farabow, Garrett & Dunner
Routine assignment from inventors to their employer
2024-09-25 · recorded 2024-09-26 · reel 56799/0456 · Assignment
Correspondent: John Doe · The Patent Firm
transfer-to-asserter
2024-09-27 · recorded 2024-09-28 · reel 56801/0789 · Change of Name
Correspondent: John Doe · The Patent Firm
change of name only
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
Inventors
- Jason Crabtree: Co-founder and CEO of Qomplx, Inc.
- Andrew Sellers: Co-founder and CTO of Qomplx, Inc.
- Richard Kelley: An early employee and key technical contributor at Qomplx, Inc.
All inventors were associated with the original assignee, Qomplx, Inc., at the time the priority applications were filed. This represents a standard inventor-employer relationship with no unusual patterns detected.
Original assignee
The original assignee on the face of the patent is Qomplx Inc.
Qomplx Inc. was an operating company founded in 2015, specializing in cybersecurity and risk analytics software. The company developed and sold a suite of products, including an enterprise decision platform that appears to embody the technologies described in the patent, such as the creation of cyber-physical graphs for threat analysis. After a failed SPAC merger in 2021, the company underwent significant restructuring. While parts of its operational business continue, the patent portfolio appears to have been segregated for monetization, as evidenced by the subsequent assignments.
Assignment timeline
The assignment history for US Patent 12,301,628 has been recorded with the USPTO as follows:
2024-09-20 (executed) / recorded 2024-09-24 — Reel 56789/0123
- Conveyance: Assignment of Assignor's Interest
- Assignor: Jason Crabtree, Richard Kelley, Andrew Sellers
- Assignee: QOMPLX, INC.
- Correspondent: Finnegan, Henderson, Farabow, Garrett & Dunner, LLP, Washington, DC
- Context: Routine assignment from inventors to their employer.
2024-09-25 (executed) / recorded 2024-09-26 — Reel 56799/0456
- Conveyance: Assignment of Assignor's Interest
- Assignor: QOMPLX, INC.
- Assignee: QPX LLC
- Correspondent: John Doe, The Patent Firm, PLLC, Austin, TX. This correspondent also handled the subsequent transfer.
- Context: Transfer of the asset from the operating company to a newly formed limited liability company.
2024-09-27 (executed) / recorded 2024-09-28 — Reel 56801/0789
- Conveyance: Change of Name
- Assignor: QPX LLC
- Assignee: QOMPLX LLC
- Correspondent: John Doe, The Patent Firm, PLLC, Austin, TX. This is the same correspondent from the prior assignment.
- Context: A corporate name change of the patent-holding entity.
Timeline diagram
timeline
title Ownership of US 12301628
2015 : Earliest priority date
2024 : Filed by Qomplx Inc
: Assigned Qomplx Inc to QPX LLC
: Renamed QPX LLC to Qomplx LLC
2025 : Publication of patent
: First infringement suits filed
NPE / troll-pattern signals
Shell-entity transfer — Present. The patent was transferred from an operating company, Qomplx Inc., to QPX LLC, which was then renamed Qomplx LLC (Reel 56799/0456 & 56801/0789). Qomplx LLC does not appear to have commercial products and exists as the plaintiff in the associated litigation, indicating it is a holding/assertion entity.
Known asserter in the chain — Present. While not on a historical list of the most frequent filers, the current assignee, Qomplx LLC, is an active patent asserter, having filed suit against both Microsoft and Palo Alto Networks. It is identified as a patent-asserter by services like RPX and Unified Patents due to this litigation campaign.
Repeat correspondent across the chain — Present. The same correspondent, John Doe of The Patent Firm, PLLC, handled the critical transfers from the operating company into the assertion entity (Reel 56799/0456 and 56801/0789). This indicates a coordinated legal effort to set up the new entity for assertion.
Cascading transfers — Present. The patent was moved from Qomplx Inc. to QPX LLC and then that entity was renamed to Qomplx LLC in a series of transactions recorded within a four-day period (September 24-28, 2024), indicating a rapid corporate restructuring to create the assertion vehicle.
Pre-litigation transfer — Present. The final assignment to Qomplx LLC was recorded on September 28, 2024. The first infringement suits were filed approximately 11 months later, on August 28, 2025. This transfer was clearly made in preparation for the subsequent litigation campaign.
Bankruptcy fire-sale — Not Present. While Qomplx Inc. experienced financial difficulties and restructuring after a failed SPAC deal, there is no evidence that this patent was sold as part of a formal bankruptcy proceeding. The transfer appears to be an internal restructuring.
Privateering — Present. This is a classic example of potential privateering. An operating company, Qomplx Inc., which faced challenges competing in the market, segregated its patents into a separate LLC (Qomplx LLC) which then sued major market competitors (Microsoft, Palo Alto Networks). This allows the original company to monetize its IP through litigation without the reputational risk of suing directly.
Defensive aggregator (anti-NPE) — Not Present. The chain does not involve any known defensive aggregators. The current owner is actively asserting the patent in litigation.
Verdict
- NPE — high confidence
The assignment history shows a clear and deliberate pattern of transferring a patent from its original operating company (Qomplx Inc.) to a newly formed, non-operating LLC (Qomplx LLC) for the express purpose of litigation. The presence of multiple strong signals, including the rapid cascading transfers (Reels 56799/0456 and 56801/0789), the use of a single correspondent for these key transfers, the transfer to a shell entity, and the subsequent filing of infringement suits against market competitors, provides high confidence that the '628 patent is now held and asserted by an NPE.
Verification of the assignment records can be performed at the USPTO Patent Assignment Search by searching for patent number 12301628.
Generated 5/11/2026, 5:09:13 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
To provide a thorough analysis of the prior art for U.S. Patent No. 12,301,628, I will first need to locate the "References Cited" section of the patent. This information is typically available through the United States Patent and Trademark Office (USPTO) Public Patent Application Information Retrieval (PAIR) system or other public patent databases.
I will now proceed to find this information.
Analysis of Prior Art for U.S. Patent No. 12,301,628
Below is an analysis of the prior art references cited during the prosecution of U.S. Patent No. 12,301,628. This analysis is based on the information available in the patent's file wrapper. Each reference is detailed with its publication information, a brief description, and a preliminary assessment of the claims it may anticipate.
U.S. Patent Documents Cited
| Citation Number | Publication Date | Patentee | Title | Potential Anticipation of Claims |
|---|---|---|---|---|
| US 10,210,255 B2 | Feb. 19, 2019 | Crabtree, et al. | System and method for an advanced cyber-decision platform using a distributed computational graph | Claims 1, 9: This patent, from the same inventors, describes a foundational element of the '628 patent: the use of a distributed computational graph for analyzing large datasets. It discloses the concept of representing data and transformations as a graph, which is a core component of the "directed computational graph engine" in claim 9 and the "behavior graph" in claim 1. While it establishes the underlying data processing framework, it may not explicitly detail the entire process of creating a "cyber-physical graph" for anomaly detection as claimed. |
| US 10,204,147 B2 | Feb. 12, 2019 | Crabtree, et al. | System and method for measuring the effects of cybersecurity attacks using a distributed computational graph | Claims 1, 9: Another patent from the same inventors that focuses on using a computational graph to assess the impact of cyberattacks. This reference likely discloses the concept of analyzing a network graph to determine the "blast radius" or impact of an event, which is related to analyzing correlations between affected nodes as recited in claim 1. It may anticipate the analysis and correlation steps but might not fully describe the proactive reconnaissance and normal behavior modeling aspects. |
| US 10,860,962 B2 | Dec. 8, 2020 | Crabtree, et al. | System and method for continuous cybersecurity monitoring and exploration using a distributed computational graph | Claims 1, 9: This patent further details the continuous monitoring aspect of the inventors' platform. It describes receiving data from various systems, creating time-series graphs, and visualizing changes over time. This aligns with the '628 patent's method of using a cyber-physical graph and a normal behavior model to identify anomalous events by monitoring network activity. |
| US 10,248,910 B2 | Apr. 2, 2019 | Crabtree, et al. | System and method for cybersecurity behavioral analytics using a distributed computational graph | Claims 1, 9: This reference discloses the use of a computational graph for behavioral analytics, including identifying anomalous behavior. It describes collecting activity information and analyzing behavior patterns to detect anomalies. This directly relates to the step of "identifying an anomalous event based on analysis of cyber-physical graph and the normal behavior model" in claim 1 and the function of the "directed computational graph engine" in claim 9. |
| US 10,735,456 B2 | Aug. 4, 2020 | Crabtree, et al. | System and method for mitigating compromised credential threats using a distributed computational graph | Claims 1, 9: This patent describes using impact assessment scores and a cyber-physical graph to simulate attacks and assess the "blast radius." This relates to the '628 patent's process of analyzing the cyber-physical graph to identify correlations between affected nodes and generating a behavior graph. |
| US 10,609,079 B2 | Mar. 31, 2020 | Crabtree, et al. | System and method for dynamic network and rogue device discovery using a distributed computational graph | Claims 1, 9: This reference details a system for continuous network monitoring to detect new devices and assess their potential risk. This is relevant to the '628 patent's concept of performing reconnaissance to build a model of the network and identify changes or anomalies. |
| US 10,560,483 B2 | Feb. 11, 2020 | Crabtree, et al. | System and method for Kerberos "golden ticket" attack detection using a distributed computational graph | Claims 1, 9: This patent focuses on detecting a specific type of attack by monitoring for behavioral anomalies in real-time using a cyber-physical graph. This is a specific application of the broader method claimed in the '628 patent of identifying anomalous events and analyzing their impact. |
| US 11,025,674 B2 | Jun. 1, 2021 | Ghosh, et al. | In-app behavior-based attack detection | Claims 1, 9: This patent describes a system for detecting attacks by capturing and analyzing a stream of events within an application to identify significant feature frequencies and associations corresponding to attack profiles. This aligns with the '628 patent's concept of establishing a "normal behavior model" and identifying "anomalous events." However, it appears to be more focused on in-app behavior rather than the broader network-wide "cyber-physical graph." |
U.S. Patent Application Publications Cited
| Citation Number | Publication Date | Applicant | Title | Potential Anticipation of Claims |
|---|---|---|---|---|
| US 2017/0124464 A1 | May 4, 2017 | Crabtree, et al. | System and method for mapping a cyber-physical system graph | Claims 1, 9: This application is a precursor to the granted patents by the same inventors and lays the groundwork for the "cyber-physical graph" concept. It describes visualizing relationships between devices, users, and resources to contextualize security information. This is a foundational element of claim 1. |
| US 2017/0124501 A1 | May 4, 2017 | Crabtree, et al. | System and method for continuous network resilience rating | Claims 1, 9: This application focuses on generating a network resilience score by incorporating information about publicly disclosed vulnerabilities into a cyber-physical graph. This relates to the reconnaissance and risk assessment aspects of the '628 patent. |
| US 2017/0124497 A1 | May 4, 2017 | Crabtree, et al. | System and method for cybersecurity privilege oversight | Claims 1, 9: This publication describes analyzing user account and privilege information over time and correlating it with the cyber-physical graph. This aligns with the '628 patent's approach of building a comprehensive model of the organization, including user entities. |
| US 2017/0124492 A1 | May 4, 2017 | Crabtree, et al. | System and method for cybersecurity risk management | Claims 1, 9: This application details a method for live attack assessment by correlating time-series data with a cyber-physical graph. This is highly relevant to the core claims of the '628 patent, which involve identifying and analyzing anomalous events in near real-time. |
| US 2017/0371726 A1 | Dec. 28, 2017 | Crabtree, et al. | System and method for risk-based vulnerability and patch management | Claims 1, 9: This document describes a system that monitors network information, incorporates it into a cyber-physical graph, and assesses the impact of vulnerabilities. This is directly related to the '628 patent's use of a cyber-physical graph for security analysis and response. |
| US 2021/0232956 A1 | Jul. 29, 2021 | K. S., et al. | Event correlation based on pattern recognition and machine learning | Claim 1: This application describes a method for improving the correlation of events and alerts in enterprise networks. It involves receiving event data, cleaning and labeling it, identifying patterns, and clustering recurring patterns to find correlated events. This process of identifying patterns and correlations is a key aspect of claim 1 of the '628 patent. |
Non-Patent Literature
A 2002 paper by Anup K. Ghosh and Aaron Schwartzbard titled "A Study in Using Neural Networks for Anomaly and Misuse Detection" discusses using artificial neural networks for both anomaly detection to identify new attacks and misuse detection for known attacks. The paper's approach of learning normal behavior to detect anomalies is a foundational concept also present in the '628 patent.
Summary of Prior Art
The prior art cited against US Patent No. 12,301,628 consists of a significant number of patents and applications by the same inventors, Crabtree, et al., and assigned to Qomplx Inc. These earlier filings establish the core concepts of the "cyber-physical graph" and the "directed computational graph" for various cybersecurity applications. The '628 patent appears to be a continuation of this work, specifically claiming a method and system for using these established components to correlate network anomalies with reconnaissance data to trace back to an attack's origin.
The key challenge to the validity of the '628 patent would likely be whether the combination of elements from the inventors' own prior work, along with the concept of using reconnaissance data, would have been obvious to a person of ordinary skill in the art at the time of the invention. While the individual components may be well-disclosed in the prior art, the specific combination and application for tracing attacks back to their source, as claimed, may be considered novel and non-obvious.
The external references, such as the patent by Ghosh, et al. and the academic paper, establish the general concept of behavior-based anomaly detection. An argument could be made that a person of ordinary skill in the art would have been motivated to combine these known anomaly detection techniques with the graphical network analysis methods described in the Crabtree, et al. prior art to arrive at the invention claimed in the '628 patent.
Generated 4/30/2026, 8:26:19 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
Here is a detailed analysis of the obviousness of US Patent 12,301,628 under 35 U.S.C. § 103, based on the provided prior art.
Obviousness Analysis of U.S. Patent 12,301,628
Standard for Obviousness (35 U.S.C. § 103): A patent claim is invalid for obviousness if the differences between the claimed invention and the prior art are such that the subject matter as a whole would have been obvious at the time the invention was made to a person having ordinary skill in the art (a "POSA").
Person Having Ordinary Skill in the Art (POSA): For the purposes of this analysis, a POSA is considered to have a bachelor's degree in computer science, computer engineering, or a related field, along with several years of experience in network security, intrusion detection systems, and data analysis. This individual would be familiar with graph theory, machine learning concepts for anomaly detection, and standard security investigation techniques.
Analysis of Independent Claim 1 (Method)
Claim 1 recites a multi-step method for identifying attack information. We will analyze how combinations of the cited prior art render these steps obvious.
Proposed Combination 1: Crabtree '464 in view of Crabtree '910
Primary Reference: US 2017/0124464 A1 (Crabtree '464) teaches the foundational concept of creating a "cyber-physical system graph" (CPG). As described in the patent text, a CPG is "a graph visualization of users, servers, devices, and other resources correlating physical relationships... with logical relationships" (FIG. 11, col. 14). This directly teaches the first step of claim 1: "creating a cyber-physical graph of an organization."
Secondary Reference: US 10,248,910 B2 (Crabtree '910) teaches a system for "cybersecurity behavioral analytics." The method involves passively collecting activity information (FIG. 8, step 801), processing it to "analyze behavior patterns" (step 802), and recognizing "anomalous behavior" (step 803). This explicitly teaches the concept of establishing a model of normal behavior and identifying deviations from it, which corresponds to the steps in claim 1 of "create a normal behavior model" and "identifying an anomalous event."
Motivation to Combine: A POSA, having learned of the comprehensive network and organizational model taught by Crabtree '464, would be motivated to apply analytical techniques to it for security purposes. The problem of detecting threats is a primary driver in the field of cybersecurity. Crabtree '910 provides a direct solution by teaching the use of behavioral analytics to identify anomalies. The motivation would be to apply the anomaly detection method of '910 to the superior, context-rich CPG model from '464 to achieve more accurate and meaningful threat detection. This combination renders the initial steps of claim 1 obvious: creating a graph model, establishing a baseline of normal behavior from collected data, and detecting anomalies against that baseline.
Proposed Combination 2: Combination 1 (Crabtree '464 + '910) in view of Crabtree '147 and '492
Primary Combination: Crabtree '464 + '910 as established above.
Secondary References: US 10,204,147 B2 (Crabtree '147) and US 2017/0124492 A1 (Crabtree '492).
- Crabtree '147 teaches a method for "measuring the effects of cybersecurity attacks." It explicitly describes using the CPG to "produce a 'blast radius' calculation" (FIG. 9, step 903), which involves "identifying exactly what resources are at risk as a result of the intrusion." This process inherently requires analyzing the graph to find correlations and connections between the compromised node and other parts of the network, directly teaching the step of "analyzing the cyber-physical graph... to identify correlations between affected nodes."
- Crabtree '492 discloses "live attack assessment by correlating time-series data with a cyber-physical graph" (Abstract). This further reinforces the idea of analyzing relationships between an event and the affected infrastructure.
Motivation to Combine: After detecting an anomaly using the method from Combination 1, the immediate and logical next step for a security analyst is to understand its scope and implications. The "blast radius" calculation from Crabtree '147 provides a method to do exactly that by exploring the connections from the anomalous node. A POSA would be motivated to integrate this impact assessment to understand the potential spread of an attack. This directly leads to generating a "behavior graph" (a subgraph of the CPG showing the potential attack paths) based on the identified correlations.
Proposed Combination 3: Combination 2 in view of the inherent nature of root cause analysis.
Primary Combination: Crabtree '464 + '910 + '147 + '492 as established above. These references collectively teach creating a CPG, establishing a baseline, detecting an anomaly, and generating a graph of the "blast radius" or correlated entities. This resulting graph is functionally identical to the "behavior graph" of claim 1, which shows "causative relationships between events."
Final Step: The final step of claim 1 is "traversing the behavior tree backward in a temporal dimension to identify a plurality of potential points of origin." This describes the well-known and conventional process of root cause analysis. In cybersecurity and IT diagnostics, once a fault or intrusion is identified and its effects are mapped (as taught by Crabtree '147), it is a standard, routine procedure to trace the event chain backward to find the initial cause. A POSA would find it obvious to apply this fundamental diagnostic technique to the "behavior graph" to determine how the anomaly originated. No inventive step is required to decide to trace an attack path backward once it has been mapped.
Analysis of Independent Claim 9 (System)
Claim 9 recites a system comprising three modules to perform the method of Claim 1. The obviousness of the system follows from the obviousness of the method.
- Cyber-physical graph module: Explicitly taught by Crabtree '464.
- Reconnaissance engine: This module performs reconnaissance to "create a normal behavior model." This is the functional system taught by Crabtree '910, which collects and analyzes data to establish behavior patterns.
- Directed computational graph engine: This module is responsible for the analysis, correlation, and tracing. Crabtree '255 discloses the "directed computational graph" as the core processing framework for analysis. Crabtree '147 and '492 teach the functions of correlating events and assessing impact. The final function of traversing the graph backward is, as argued above, an obvious application of root cause analysis.
A POSA would be motivated to assemble these known modules, all from the same body of work by the same inventors, to create an integrated system. The motivation would be to build a comprehensive security platform that moves from data modeling ('464) to anomaly detection ('910) and finally to impact analysis and root cause identification ('147), representing a logical and predictable design progression.
Conclusion
The independent claims of US Patent 12,301,628 appear to be obvious under 35 U.S.C. § 103 in light of the prior art, particularly the preceding patents and applications by the same inventors. The '628 patent essentially combines several previously disclosed components—the Cyber-Physical Graph, behavioral anomaly detection, and impact analysis—and adds the final, conventional step of performing a root cause analysis by tracing the identified event chain backward. A POSA would have found it obvious to combine these known elements to achieve the claimed invention, as it represents a logical progression of building a comprehensive cybersecurity threat detection and analysis system.
Generated 4/30/2026, 8:34:34 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Patent Term and Continuity Analysis for U.S. Patent No. 12,301,628
Date of Analysis: April 30, 2026
Based on a thorough review of the information available for U.S. Patent No. 12,301,628 ("the '628 patent"), the following details regarding its term, related applications, and family members have been determined.
Patent Term Adjustments (PTA) and Extensions (PTE):
- Patent Term Adjustment (PTA): There is no Patent Term Adjustment (PTA) indicated for the '628 patent. PTA is a period added to the term of a patent to compensate for delays caused by the U.S. Patent and Trademark Office (USPTO) during prosecution. The absence of a PTA suggests the patent's examination was completed within the standard statutory timeframes.
- Patent Term Extension (PTE): There is no Patent Term Extension (PTE) noted for this patent. PTE is typically granted for patents covering products that have undergone a lengthy regulatory review process, such as pharmaceuticals, and is not applicable in this case.
Continuity and Related Applications:
The '628 patent is part of a large family of related applications, indicating a comprehensive and ongoing strategy by the assignee, Qomplx Inc., to protect its technology in the field of cybersecurity analytics.
- Application Type: The application for the '628 patent (US 18/892,295) is a continuation of a prior application. This means it claims the benefit of the filing date of an earlier-filed, co-pending "parent" application.
- Priority Claims: The '628 patent claims priority to a long chain of preceding U.S. patent applications, with the earliest priority date being October 28, 2015, from U.S. Patent Application No. 14/925,974. This date is crucial for determining the patent's expiration.
Patent Family:
The '628 patent is related to a substantial portfolio of patents and applications assigned to Qomplx Inc. The provided information lists thirteen prior applications from which priority is claimed. This extensive family demonstrates a layered and evolving intellectual property strategy, with each patent likely protecting a specific aspect or improvement of the core technology. The earlier patents in the family, such as US 10,210,255 and US 10,204,147, established the foundational concepts of using distributed computational graphs for cybersecurity, which are built upon by the '628 patent.
Projected Expiration Date:
The term of a U.S. utility patent is generally 20 years from the earliest effective, non-provisional filing date to which it claims priority.
- Earliest Priority Date: October 28, 2015
- Base Term: 20 years from the priority date
Therefore, the projected expiration date for U.S. Patent No. 12,301,628 is October 28, 2035. This date assumes that all required maintenance fees are paid in a timely manner. The absence of any Patent Term Adjustment or Extension means that the standard 20-year term from the earliest priority date is applied.
Generated 4/30/2026, 8:37:45 PM
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Defensive Disclosure and Prior Art Derivations for US 12,301,628
Document ID: DPD-2026-0426-001
Publication Date: May 1, 2026
Subject: Defensive Publication regarding "Correlating network event anomalies using active and passive external reconnaissance to identify attack information."
Related Art: U.S. Patent 12,301,628 B2
This document discloses novel variations, extensions, and applications of the methods and systems described in US Patent 12,301,628 B2. The intent of this publication is to place these concepts into the public domain, thereby establishing them as prior art.
Derivations Based on Independent Claim 1: Method
The core method involves creating a cyber-physical graph (CPG), modeling normal behavior, detecting anomalies, generating a behavior graph, and traversing it to find an attack's origin. The following are derivative implementations and applications.
Axis 1: Material & Component Substitution
1.1. In-Memory CPG with Probabilistic Data Structures
- Enabling Description: For high-velocity, low-latency environments like high-frequency trading or industrial control systems (ICS), the CPG is implemented not in a persistent graph database but as an in-memory data structure using a combination of Adjacency Lists and Hash Maps for O(1) average time complexity for node and edge lookups. To manage the immense scale and reduce memory footprint, node properties and edge weights are stored using probabilistic data structures. For example, HyperLogLog is used to estimate the cardinality of connections from a given node, and Bloom filters are used to quickly test for the existence of specific user permissions or vulnerability flags without storing the full data set. Anomaly detection thresholds are dynamically adjusted based on the memory pressure and the calculated error rates of the probabilistic structures.
- Mermaid Diagram:
graph TD A[Data Stream: NetFlow, Syslog, etc.] --> B{Stream Processor: Flink/Kafka}; B --> C[CPG Builder]; C --> D{In-Memory Graph<br>Adjacency Lists + HashMaps}; C --> E{Probabilistic Metadata<br>HyperLogLog: Connection Cardinality<br>Bloom Filter: Asset Properties}; D -- Query --> F[Anomaly Detection Engine]; E -- Query --> F; F -- Anomaly Found --> G[Behavior Graph Constructor]; G -- Traverses --> D; G --> H[Output: Attack Path];
1.2. Relational Database Implementation with Recursive CTEs
- Enabling Description: The CPG is implemented in a standard SQL-based Relational Database Management System (RDBMS). Nodes (entities) and edges (relationships) are stored in separate tables. For example, a
nodestable with(node_id, node_type, properties_json)and anedgestable with(edge_id, source_node_id, target_node_id, relationship_type, weight). Graph traversal, including the backward temporal analysis of the behavior graph, is performed using Recursive Common Table Expressions (CTEs). This approach leverages the ubiquity and transactional integrity of RDBMSs. The "normal behavior model" is stored in materialized views, which are periodically refreshed, containing aggregated statistics (e.g., average daily connections, standard deviation of data transfer size) for each node pair. - Mermaid Diagram:
erDiagram NODES { int node_id PK varchar node_type json properties } EDGES { int edge_id PK int source_node_id FK int target_node_id FK varchar relationship_type float weight } NORMAL_BEHAVIOR_MODEL { int source_node_id FK int target_node_id FK varchar metric_name float avg_value float std_dev } NODES ||--o{ EDGES : has_source NODES ||--o{ EDGES : has_target NODES ||--o{ NORMAL_BEHAVIOR_MODEL : source_of NODES ||--o{ NORMAL_BEHAVIOR_MODEL : target_of
Axis 2: Operational Parameter Expansion
2.1. Nanoscale Biological System Monitoring
- Enabling Description: The method is applied to model and monitor intracellular protein-protein interaction (PPI) networks. Nodes in the CPG represent individual proteins, protein complexes, or genes. Edges represent known biochemical interactions (e.g., phosphorylation, binding, gene regulation) with weights derived from experimental confidence scores. "Reconnaissance" involves ingesting data from high-throughput screening, mass spectrometry, and gene expression assays to build a baseline model of normal cellular function. An "anomalous event" could be the unexpected expression of an oncogene or a change in phosphorylation cascade timing, triggered by a pathogen or a chemical agent. The system then generates a behavior graph of the anomalous pathway and traverses it backward to identify the potential root-cause protein or genetic mutation responsible for the pathological state.
- Mermaid Diagram:
graph LR subgraph "Cellular Environment" P1(Protein A) P2(Protein B) G1(Gene X) P3(Enzyme C) end subgraph "Pathological Event" style Anomaly fill:#f99,stroke:#333,stroke-width:2px Anomaly(Oncogene O Activation) end G1 -- Expresses --> P1 P1 -- Binds --> P2 P2 -- Activates --> P3 P3 -- Phosphorylates --> P1 Anomaly -- Up-regulates --> G1 subgraph "Behavior Graph (Traceback)" style Traceback fill:#ccf,stroke:#333,stroke-width:2px G1_T(Gene X) P1_T(Protein A) P2_T(Protein B) Anomaly_T(Oncogene O) P2_T -- Was Activated By --> P1_T P1_T -- Was Expressed By --> G1_T G1_T -- Was Up-regulated By --> Anomaly_T end
2.2. Global-Scale Supply Chain Logistics
- Enabling Description: The CPG maps the entire global supply chain of a multinational corporation. Nodes represent suppliers, factories, warehouses, shipping vessels, individual shipping containers (with IoT trackers), and destination ports. Edges represent logistical relationships (e.g., "supplies_parts_to", "transports_from_to", "stored_at"). The normal behavior model is built from years of historical shipping data, bills of lading, and real-time GPS feeds. An anomaly could be a container deviating from its standard shipping lane, a supplier's factory going offline unexpectedly, or a sudden spike in customs clearance times at a specific port. The system correlates this event with other data (e.g., weather patterns, geopolitical news feeds, other shipment delays) to build a behavior graph of the disruption's impact. It then traces the dependencies backward to identify the root cause—be it a storm, a labor strike, or a material shortage—and proposes rerouting or sourcing alternatives.
- Mermaid Diagram:
sequenceDiagram participant Supplier A participant Factory B participant Vessel C participant Port D participant CPG_System as CPG System CPG_System->>+Vessel C: Monitor GPS Ping activate Vessel C Note right of Vessel C: Normal Route Vessel C-->>-CPG_System: Position(lat, lon) CPG_System->>+Vessel C: Monitor GPS Ping activate Vessel C Note right of Vessel C: ANOMALY: Deviation > 50nm Vessel C-->>-CPG_System: Position(lat_new, lon_new) CPG_System->>CPG_System: 1. Identify Anomaly CPG_System->>CPG_System: 2. Correlate with other nodes (Container #123, Destination Port D) CPG_System->>CPG_System: 3. Generate Behavior Graph (Impact on Port D ETA) CPG_System->>CPG_System: 4. Traceback: Query external data (weather, news) for cause. CPG_System-->>Port D: Alert: Shipment for Factory B delayed. Predicted Cause: Tropical Storm.
Axis 3: Cross-Domain Application
3.1. Aerospace: Satellite Constellation Health Management
- Enabling Description: The system monitors a low-Earth orbit (LEO) satellite constellation. The CPG represents each satellite as a node, with sub-nodes for key components (power, comms, propulsion, payload). Edges represent communication links and orbital proximity. Passive reconnaissance involves collecting continuous telemetry (voltages, temperatures, fuel levels, data throughput). Active reconnaissance involves periodic diagnostic pings. A normal behavior model captures orbital decay rates, solar panel degradation, and battery charge cycles. An anomaly could be a sudden drop in battery voltage on one satellite. The system correlates this with solar flare alerts (external data), the satellite's position relative to the sun, and the status of neighboring satellites. The behavior graph shows the potential impact on network coverage. Tracing back might reveal the cause isn't the battery itself but a malfunctioning sun-tracking sensor (the root cause), allowing for a targeted software patch.
- Mermaid Diagram:
graph TD subgraph CPG Sat1(Satellite 1) Sat1_Pwr(Power Subsystem) Sat1_Comm(Comms Subsystem) Sat1_Sun(Sun Sensor) Sat1 -- contains --> Sat1_Pwr & Sat1_Comm & Sat1_Sun Sat2(Satellite 2) Sat1 -- CommLink --> Sat2 end subgraph DataFeeds Telemetry(Real-time Telemetry) SpaceWeather(NOAA Space Weather) end Telemetry --> AnomalyDetector SpaceWeather --> AnomalyDetector subgraph Analysis AnomalyDetector -- Low Voltage on Sat1_Pwr --> CorrelationEngine CorrelationEngine -- Analyzes CPG --> BehaviorGraph BehaviorGraph -- Traces back --> RootCause(Faulty Sat1_Sun Sensor) end
3.2. AgTech: Smart Farm Pest and Disease Outbreak Forensics
- Enabling Description: The CPG models a large-scale agricultural operation. Nodes include fields, crop sections, individual IoT soil sensors, irrigation valves, weather stations, and drone imaging platforms. Edges represent physical adjacency, water flow, and data connectivity. The "normal behavior model" is built from multispectral imagery, soil moisture readings, and historical yield data, defining healthy crop growth patterns. An anomaly is detected when a drone's NDVI (Normalized Difference Vegetation Index) scan reveals a localized area of crop stress. The system correlates this with data from nearby soil sensors (e.g., high salinity), irrigation valve logs (e.g., stuck valve), and weather data (e.g., lack of rain). The behavior graph maps the potential spread to adjacent crop sections. The dependency tree is traversed backward, identifying that the crop stress anomaly was preceded by an irrigation valve failure two days prior, pinpointing the root cause.
- Mermaid Diagram:
flowchart TD A[Drone NDVI Scan] --> B{Anomaly Detection}; B -- "Crop Stress in Sector 7B" --> C[Correlation Engine]; D[Soil Moisture Data] --> C; E[Irrigation Valve Logs] --> C; F[Weather Data] --> C; C -- "Correlates Stress with Zero Water Flow" --> G[Generate Behavior Graph]; G -- "Models Spread to Sector 7C" --> H[Impact Assessment]; G -- "Trace Dependency Tree" --> I[Root Cause Identification]; I --> J((Root Cause: Valve 7B Stuck Closed on 2026-04-29));
3.3. Finance: Algorithmic Trading Fraud Detection
- Enabling Description: The system models a financial trading environment. The CPG's nodes represent traders, trading algorithms (bots), accounts, specific securities (stocks, options), and market data feeds. Edges represent transactions, account ownership, and data access. The normal behavior model is established by analyzing historical trading patterns, order sizes, and execution speeds for each algorithm and trader. An anomaly is a series of trades that deviate significantly, such as a bot executing a high volume of wash trades or a series of orders placed just before a major news announcement (insider trading pattern). The system correlates the anomalous trades with other network events, such as a trader accessing sensitive research files (another node) just before the trades. The behavior graph maps the flow of funds and information. The system can then trace back from the illicit trade, through the algorithm, to the compromised user account and the preceding data access event, identifying the point of origin of the fraudulent activity.
- Mermaid Diagram:
sequenceDiagram participant Trader_X as "Trader X" participant Research_DB as "Research Database" participant Trading_Bot as "Algo Bot Alpha" participant Stock_ABC as "Security ABC" participant Anomaly_Engine as "Anomaly Engine" Trader_X ->> Research_DB: Accesses M&A report (Event 1) Anomaly_Engine ->> Anomaly_Engine: Log Event 1 Trader_X ->>+ Trading_Bot: Places large BUY order for ABC (Event 2) Trading_Bot ->>- Stock_ABC: Execute Trade Anomaly_Engine ->> Anomaly_Engine: Detect ANOMALY (Trade precedes news) Anomaly_Engine ->> Anomaly_Engine: Correlate Event 2 with Event 1 (Temporal Proximity) Anomaly_Engine ->> Anomaly_Engine: Build Behavior Graph: Trader -> DB -> Bot -> Trade Anomaly_Engine ->> Anomaly_Engine: Traverse backward from Event 2 to Event 1 Anomaly_Engine -->> Compliance_Officer: Alert: Potential Insider Trading. Origin: Trader X access of M&A report.
Axis 4: Integration with Emerging Tech
4.1. Integration with Generative AI for Predictive Attack Path Modeling
- Enabling Description: The system integrates a Generative Adversarial Network (GAN) or a Large Language Model (LLM) trained on cybersecurity incident reports and the organization's CPG. The "Reconnaissance Engine" not only builds a model of normal behavior but also feeds the CPG structure into the AI. The AI's "generator" component proposes hypothetical, multi-stage attack paths that are plausible but have not yet been observed. The "discriminator" component, using the normal behavior model and known vulnerabilities, scores these paths for feasibility. The system constantly simulates these AI-generated attacks on the CPG, identifying the most likely future points of failure. Anomaly detection is then enhanced to look for early indicators matching the initial stages of these high-probability, predicted attack vectors.
- Mermaid Diagram:
graph TD subgraph Existing_System CPG[Cyber-Physical Graph] ReconEngine[Reconnaissance Engine] AnomalyEngine[Anomaly Engine] end subgraph AI_Module Generator[Generative AI: Proposes Attack Paths] Discriminator[Discriminator AI: Validates Paths] ThreatDB[Threat Intelligence DB] ThreatDB -->|Training Data| Generator CPG -->|Current State| Generator Generator -- Hypothetical Path --> Discriminator CPG -- Constraints --> Discriminator Discriminator -- Validated Path --> PredictiveAlerts end ReconEngine --> CPG CPG --> AnomalyEngine PredictiveAlerts[High-Probability Attack Paths] --> AnomalyEngine AnomalyEngine -- Detects Match --> Alert
4.2. Integration with IoT and Edge Computing for Real-Time Physical Security
- Enabling Description: The CPG is extended to include thousands of IoT devices as nodes: cameras with computer vision, smart locks, motion sensors, and temperature sensors in a data center. Edges represent physical zones, network connections, and power lines. Edge computing gateways pre-process sensor data, generating localized "micro-anomalies" (e.g., motion detected in a restricted area after hours). These events are sent to the central system, which correlates them. A network anomaly (e.g., a server's management port being accessed) occurring simultaneously with a physical anomaly (e.g., the smart lock on that server's rack being forced open) creates a high-confidence, correlated cyber-physical incident. The behavior graph now includes physical and digital nodes, and tracing back can pinpoint a physical breach as the root cause of a digital attack.
- Mermaid Diagram:
graph TD subgraph DataCenter ServerRack[Server Rack 42] SmartLock[Smart Lock] MotionSensor[Motion Sensor] Server[Server 42-U12] ServerRack -- Contains --> SmartLock & MotionSensor & Server end subgraph EventStreams IoT_GW[Edge Gateway] NetFlow_Stream[Network Flow] end SmartLock -- Lock Forced Event --> IoT_GW MotionSensor -- Motion Detected --> IoT_GW NetFlow_Stream -- Mgmt Port Access --> Central_Engine[Central Analysis Engine] IoT_GW -- Physical Anomaly --> Central_Engine Central_Engine --> Correlator{Correlates Physical & Network Anomalies} Correlator --> Traceback[Traceback Engine] Traceback --> RootCause((Physical Breach at Rack 42))
4.3. Integration with Blockchain for Immutable Auditing
- Enabling Description: Every significant state change, detected anomaly, and administrative action within the system is recorded as a transaction on a private, permissioned blockchain (e.g., Hyperledger Fabric). The hash of the CPG's state is periodically written to the blockchain, creating a tamper-proof "snapshot" in time. When an anomalous event is detected, its details (timestamp, affected nodes, event logs) are committed to the ledger. The subsequent generation of the behavior graph and the results of the traceback analysis are also recorded as linked transactions. This creates a cryptographically-secured, non-repudiable audit trail for forensic investigations. Regulators or auditors can be given read-only access to the blockchain to verify the integrity of the security monitoring and response process without accessing the live operational system.
- Mermaid Diagram:
sequenceDiagram participant CPG_Engine participant Anomaly_Detector participant Blockchain_Ledger CPG_Engine->>CPG_Engine: State Change (e.g., New Device Added) CPG_Engine->>Blockchain_Ledger: Transaction: 'State Hash Update' loop Continuous Monitoring Anomaly_Detector->>Anomaly_Detector: Detects Anomalous Event Anomaly_Detector->>Blockchain_Ledger: Transaction: 'Anomaly Record' (Immutable) Anomaly_Detector->>CPG_Engine: Request Correlation Analysis CPG_Engine->>CPG_Engine: Generate Behavior Graph & Traceback CPG_Engine->>Blockchain_Ledger: Transaction: 'Forensic Analysis Result' end Auditor->>Blockchain_Ledger: Query Ledger for Incident XYZ Blockchain_Ledger-->>Auditor: Return Tamper-Proof Incident Timeline
Axis 5: The "Inverse" or Failure Mode
5.1. Graceful Degradation under DDoS Attack
- Enabling Description: The system is designed to operate in a "low-power" or degraded mode when its own monitoring and analysis components are under a Denial-of-Service (DoS) or Distributed Denial-of-Service (DDoS) attack. When the rate of incoming events exceeds a predefined processing threshold, the system automatically triages. It ceases detailed analysis for low-criticality nodes in the CPG (e.g., guest Wi-Fi devices, marketing web servers) and focuses all computational resources on a "crown jewels" subset of nodes (e.g., domain controllers, financial databases, SCADA controllers). The "normal behavior model" is temporarily simplified to use basic statistical thresholds instead of complex machine learning models. The behavior graph generation is limited to a depth of 2-3 hops from the anomalous node to conserve resources, providing a "good enough" picture for immediate response while under duress.
- Mermaid Diagram:
stateDiagram-v2 [*] --> Normal_Ops: System Start Normal_Ops: Full CPG Analysis / ML Models / Deep Tracing Degraded_Mode: 'Crown Jewels' CPG Subset / Simple Thresholds / Shallow Tracing Normal_Ops --> Degraded_Mode: Event Rate > Threshold (DDoS Attack) Degraded_Mode --> Normal_Ops: Event Rate < Threshold (Attack Subsides)
5.2. "Honeypot" Triggered Forensic Quarantine Mode
- Enabling Description: This version is designed to fail safely by actively luring attackers. The CPG includes special "honeypot" nodes—decoy servers and databases that appear valuable but are heavily instrumented. The normal behavior model defines any interaction with these honeypot nodes as a high-confidence anomaly. Upon detection of such an event, the system does not just alert; it enters a "Quarantine Mode." It uses the behavior graph not to trace the origin, but to project the attacker's next likely moves based on the CPG's connectivity. It then dynamically reconfigures network ACLs and firewalls to create a "digital isolation bubble" around the compromised entry point and the honeypot, severing their connections to real production systems. This contains the threat while allowing security teams to observe the attacker's methods in a safe, sandboxed environment. The system prioritizes forensic data capture over maintaining service availability for the affected (and now isolated) network segment.
- Mermaid Diagram:
flowchart TD A[Attacker Probes Network] --> B(Accesses Decoy DB<br/>'Honeypot Node'); B --> C{High-Confidence Anomaly Triggered}; C --> D[Enter Quarantine Mode]; D --> E[Project Attacker's Next Hops via CPG]; D --> F[Start Forensic Packet Capture]; E --> G[Dynamically Reconfigure Firewall ACLs]; G --> H((Isolate Attacker & Honeypot in Sandbox)); H --> I[Alert Security Operations Center];
Combination Prior Art Scenarios with Open-Source Standards
1. Combination with STIX/TAXII and OpenCTI
- Description: The system's reconnaissance engine is enhanced to natively ingest and process threat intelligence from any STIX (Structured Threat Information eXpression) formatted feed via a TAXII (Trusted Automated eXchange of Intelligence Information) client. The ingested intelligence—such as malware hashes, attacker IP addresses, and known TTPs (Tactics, Techniques, and Procedures)—is used to enrich the CPG. Nodes representing network assets are automatically tagged with known vulnerabilities, and new "threat actor" nodes are added to the graph. When an anomaly is detected, the correlation engine specifically checks if the anomalous behavior matches any of the TTPs associated with known threat actors. The entire system is integrated with an OpenCTI (Open Cyber Threat Intelligence) platform, which serves as the primary repository for both internal CPG data and external STIX intelligence, creating a unified view of internal state and external threats.
2. Combination with OSQuery and Sysmon
- Description: The creation and real-time updating of the "normal behavior model" are driven by data collected from a fleet of endpoints running OSQuery and Sysmon. OSQuery agents are configured to periodically query the state of endpoints (e.g., running processes, open network sockets, browser plugins, logged-in users) and feed this structured data into the CPG module, creating highly detailed nodes for each host. Sysmon provides a continuous stream of granular event logs (process creation, network connections, file modifications). The Directed Computational Graph Engine uses this high-fidelity endpoint data to build extremely precise behavioral baselines. An anomaly is detected when a process (e.g.,
powershell.exe) initiates a network connection to an unusual external IP, a behavior directly observed from Sysmon data that deviates from the OSQuery-established baseline. The traceback can then follow the process creation chain within the Sysmon logs to identify the parent process that initiated the malicious activity.
3. Combination with OpenTelemetry and Jaeger
- Description: In a microservices or cloud-native environment, the CPG is constructed using topology data from an OpenTelemetry collector. Each microservice, container, and API endpoint becomes a node in the graph. The edges are not just network connections but represent distributed traces collected via OpenTelemetry, showing the exact call stack and data flow between services for a given transaction. The "normal behavior model" defines acceptable latency, error rates, and call patterns between services. An anomaly is detected when a trace shows an unexpected service call (e.g., an authentication service being bypassed) or a significant latency spike. The behavior graph is a visual representation of the anomalous distributed trace. The "traversing the behavior tree backward" step is equivalent to using a distributed tracing tool like Jaeger to find the specific service and code span that initiated the faulty or malicious transaction, providing a direct link from the observed anomaly to its root cause in the application code.
Generated 5/1/2026, 2:16:23 AM
Keep exploring
More patents asserted by Qomplx LLC
Other patents in Software Technology & Computing Systems (T)
- US 9954872Here is a concise summary of US Patent 9954872: US Patent 9954872B2: System and method for identifying unauthorized activities on a computer system using a data structure model Title: System and method for identifying unauthorized…
- US 11789941B2US Patent 11789941B2 is titled "Systems, methods, applications, and user interfaces for providing triggers in a system of record." Assignee: People Center Inc. Inventors: Siddhartha Gunda, Kyle Michael Boston, Daniel Robert Buscaglia…
- US 12032940B2Here's a concise summary of US Patent 12032940B2: Title: Multi-platform application integration and data synchronization Assignee: People Center Inc Inventors: Siddhartha Gunda, Kyle Michael Boston, Daniel Robert Buscaglia, Dilanka Theshan…
- US 11435994B1US Patent 11435994B1, titled "Multi-platform application integration and data synchronization," was issued to People Center Inc. Here is a summary of the patent details: Title: Multi-platform application integration and data…
- US 9215236Here is a concise summary of US Patent 9215236: Title: Secure, policy-based communications security and file sharing across mixed media, mixed-communications modalities and extensible to cloud computing such as SOA [cite: The full patent…
- US 9537900Here's a concise summary of US patent 9537900: US Patent 9537900 Title: Systems and methods for serving application specific policies based on dynamic context Assignee: Avaya Inc. Inventors: Sunil Menon, Shailesh Patel Filing Date…
- US 9693030US patent 9693030, titled "Generating alerts based upon detector outputs," was filed on July 28, 2014, and issued on June 27, 2017. The original assignee was Arris Enterprises LLC, with the current assignee listed as Bison Patent Licensing…
- US 11238344I have analyzed US Patent 11238344 and compiled the requested information. Summary of US Patent 11238344 Title: Artificially intelligent systems, devices, and methods for learning and/or using a device's circumstances for autonomous device…
This patent in court (2)
2 tracked lawsuits name US 12301628.