IP Library Granted Patent US 10,341,369
Granted Patent B2
US 10,341,369 · App. 15/083,691 · Granted Jul 2, 2019

Security system monitoring techniques by mapping received security score with newly identified security score

Inventors: Claudio Cifarelli (Rome, IT); Massimo Mastropietro (Rome, IT)
Assignee: NCR Corporation
H04L63/1425G06F16/24578G06Q20/1085G06Q20/4016G06Q40/02H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,341,369
App. No.
15/083,691
Granted
Jul 2, 2019
Kind
B2
Abstract

Security rules of a security system include original security scores as conditions for raising alerts. The original security scores are dependent on the underlying scoring mechanism of the security system. When the scoring mechanism is updated to produce new security scores, the security rules are updated ensuring that the alert rates associated with the original security scores match the alert rates associated with the new security scores, which replace the original security scores in the security rules.

Claims (34)

1. A method, comprising:

receiving, by executable instructions that execute on a hardware processor of a server from a non-transitory computer-readable storage medium over a network, a security score along with an alert rate for the security score, wherein receiving further includes identifying a particular security rule that relies on the security score and identifying an original scoring mechanism relied on by the particular security rule, wherein the alert rate is calculated as a total number of particular alerts generated for the particular security rule divided by a total number of transactions occurring over the network;

identifying, by the executable instructions, a new security score by matching the alert rate with the new security score;

mapping, by the executable instructions, the security score to the new security score in the original scoring mechanism;

triggering, by the executable instructions, over the network, a processing of an automated security action in response to the new security score;

processing, a transaction rule directed to a financial transaction with transaction information for the financial transaction and the new security rule as the automated security action; and

declining the financial transaction when the transaction rule evaluates to true.

2. The method of claim 1 , wherein receiving further includes receiving the security score from the particular security rule that is being evaluated in a security system over the network, wherein the security score produced by the original scoring mechanism.

3. The method of claim 1 , wherein identifying further includes obtaining the new security score by searching a mapping table having the alert rate and other alert rates produced by an updated scoring mechanism that is replacing the original scoring mechanism, wherein an original scoring mechanism produced the security score.

4. The method of claim 1 , wherein mapping further includes updating an original security rule that utilizes the security score as a condition within the original security rule with the new security score.

5. The method of claim 1 further comprising, maintaining, by the executable instructions, an original score mapping table that includes entries for the security score and other security scores produced by the original scoring mechanism of a security system, each entry includes a unique security score and particular alert rate combination.

6. The method of claim 5 further comprising, maintaining, by the executable instructions, a new score mapping table that includes new entries for the new security score and other new security scores produced by an updated version of the original scoring mechanism, each new entry includes a unique new security score and a particular alert rate combination.

7. The method of claim 6 further comprising, creating, by the executable instructions, a mapping transition table that includes mapping entries, each mapping entry including: a unique security score, a unique new security score, and a particular alert rate.

8. The method of claim 7 further comprising, processing, in real time within a context of a security system, by the executable instructions, the original score mapping table, the new score mapping table, and the mapping transition table to update security rules of the security system by replacing the security scores identified in the security rules with the new security scores.

9. The method of claim 8 , further comprising, logging, by the executable instructions, the original score mapping table, the new score mapping table, and the mapping transition table when each of the security rules have been successfully updated within the security system.

10. A method, comprising:

maintaining, by executable instructions that execute on a hardware processor from a non-transitory computer-readable medium over a network, an original mapping between original security scores and alert rates produced by an original scoring mechanism of a risk management system, wherein each alert rate calculated as a total number of particular alerts generated for a particular security rule divided by a total number of transactions occurring over the network, wherein the particular security rule relies on a particular original score and the original scoring mechanism;

creating, by the executable instructions, a new mapping between new security scores and the alert rates produced by a new scoring mechanism that is to update the original scoring mechanism within the risk management system;

updating, by the executable instructions, security rules that include the original security scores with the new security scores and maintaining for each security rule update a proper alert rate that corresponds to both that security rule's original security score and a replacement new security score for that security rule by utilizing the original mapping and the new mapping;

automatically triggering, by the executable instructions, over the network, a processing of a security action in response to evaluation of the updated security rules having the new security scores;

processing, a transaction rule directed to a financial transaction with transaction information for the financial transaction and a particular one of the new security rules as the automated security action; and

declining the financial transaction when the transaction rule evaluates to true.

11. The method of claim 10 , wherein maintaining further includes maintaining the original mapping as an original score-to-alert rate mapping table.

12. The method of claim 10 , wherein creating further includes dynamically building the new mapping as a new-score-to-alert rate mapping table for a configurable period of time as the new scoring mechanism processes within a non-production environment of the risk management system.

13. The method of claim 12 , wherein dynamically building further includes promoting the new scoring mechanism to a production environment of the risk management system to replace the original scoring mechanism after the configurable period of time.

14. The method of claim 10 , wherein updating further includes dynamically and in real time performing the updating of the security rules within the risk management system as each security rule is accessed for evaluation within the risk management system for a first time after the new scoring mechanism is active within a production environment of the risk management system and has replaced the original scoring mechanism.

15. The method of claim 14 further comprising, retiring and logging, by the executable instructions, the original mapping as an archived original mapping once each security rule has been updated with that security rule's new security score.

16. The method of claim 15 further comprising, iterating processing of the method, by the executable instructions, by replacing the original mapping with the new mapping and creating a second mapping as the new mapping when a subsequent update is made to the new scoring mechanism within the risk management system.

17. The method of claim 10 further comprising, managing, by the executable instructions, the alert rates as basis points within the risk management system.

18. A system, comprising:

a processor configured to execute instructions representing a score mapper from memory or a non-transitory computer-readable storage medium, wherein the processor is part of a server accessible over a network; and

the score mapper configured and adapted to: i) execute on the processor, ii) maintain a linkage between original security scores embedded in security rules of a security system and alert rates, wherein each alert rate calculated as a total number of particular alerts generated for a particular security rule divided by a total number of transactions, wherein the particular secure rule relies on a particular security score associated with a scoring mechanism of the security system, iii) update the security rules with new security scores when the scoring mechanism of the security system is updated by maintaining a same alert rate for each updated security rule that existed prior to update; iv) trigger over the network an automatic processing of a security action in response to evaluation of the updated security rules with the new security scores, v) process a transaction rule directed to a financial transaction with transaction information for the financial transaction and a particular one of the new security rules as the automated security action; and vi) decline the financial transaction when the transaction rule evaluates to true.

19. The system of claim 18 , wherein the security system is a risk management system.

20. The system of claim 19 , wherein the risk management system is part of a core banking system of a financial institution.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PROPERTIES SECTION BY INCLUDING IT WITH TEN PREVIOUSLY OMITTED PROPERTY NUMBERS PREVIOUSLY RECORDED ON REEL 65346 FRAME 367. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Aug 13, 2025
From: NCR ATLEOS CORPORATION; CARDTRONICS USA, LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 072445/0072 →
CHANGE OF NAME Recorded May 30, 2024
From: NCR CORPORATION
To: NCR VOYIX CORPORATION
Reel/Frame 067578/0417 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2024
From: NCR VOYIX CORPORATION
To: NCR ATLEOS CORPORATION
Reel/Frame 067590/0109 →
CORRECTIVE ASSIGNMENT TO CORRECT THE DOCUMENT DATE AND REMOVE THE OATH/DECLARATION (37 CFR 1.63) PREVIOUSLY RECORDED AT REEL: 065331 FRAME: 0297. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 31, 2023
From: NCR ATLEOS CORPORATION
To: CITIBANK, N.A.
Reel/Frame 065627/0332 →
RELEASE OF PATENT SECURITY INTEREST Recorded Oct 25, 2023
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: NCR VOYIX CORPORATION
Reel/Frame 065346/0531 →
SECURITY INTEREST Recorded Oct 25, 2023
From: NCR ATLEOS CORPORATION; CARDTRONICS USA, LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 065346/0367 →
SECURITY INTEREST Recorded Oct 24, 2023
From: NCR ATLEOS CORPORATION
To: CITIBANK, N.A.
Reel/Frame 065331/0297 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS SECTION TO REMOVE PATENT APPLICATION: 15000000 PREVIOUSLY RECORDED AT REEL: 050874 FRAME: 0063. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Apr 12, 2021
From: NCR CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 057047/0161 →
SECURITY INTEREST Recorded Oct 29, 2019
From: NCR CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 050874/0063 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2016
From: CIFARELLI, CLAUDIO; MASTROPIETRO, MASSIMO
To: NCR CORPORATION
Reel/Frame 038705/0966 →
Continuity (1)
Related Publication 20170289182A1 · Oct 5, 2017