IP Library Granted Patent US 11,777,984
Granted Patent B1
US 11,777,984 · App. 17/013,285 · Granted Oct 3, 2023

Automatic threat detection and remediation

Inventors: Divakar Sastry Prayaga (Bangalore, IN); Rajasekhar Kode (Secunderabad, IN)
Assignee: Wells Fargo Bank, N.A.
H04L63/1441G06F8/65H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,777,984
App. No.
17/013,285
Granted
Oct 3, 2023
Kind
B1
Abstract

Threats to systems and data captured by such systems can be automatically detected and remediated. Inbound traffic on an enterprise network can be monitored and analyzed to detect a threat based on parameters of the inbound traffic. In response, a patch can be identified or generated to address known or unknown threats based on a comparison of parameters. Once identified or generated, the patch can be conveyed to a target computing resource for deployment to address the threat.

Claims (53)

1. A system, comprising:

a processor coupled to a memory that includes instructions, that when executed by the processor, cause the processor to:

detect a first threat based on analysis of a first plurality of parameter values of inbound traffic to an enterprise network;

automatically determine based on the first plurality of parameter values a first patch that mitigates the first threat on a computing resource in the enterprise network;

detect a second threat based on analysis of a second plurality of parameter values;

when the first plurality of parameter values and the second plurality of parameter values have one or more parameter values in common, automatically generate a second patch for the second threat based in part on a portion of the first patch and the second plurality of parameter values; and

convey the second patch to the computing resource for application;

generate a third patch for an unknown threat from at least one existing patch associated with a known threat;

identify one or more parameter values associated with the at least one existing patch;

compute a similarity score based on a result of a comparison of the one or more parameter values for associated with the threat and the one or more parameter values associated with the at least one existing patch; and

determine the at least one existing patch based on comparison of the similarity score to a predetermined threshold.

2. The system of claim 1 , wherein the instructions further cause the processor to determine the patch by matching at least one of the first plurality of parameter values of the inbound traffic to one or more parameter values of a known threat and corresponding patch.

3. The system of claim 1 , wherein the instructions further cause the processor to:

evaluate effectiveness of the patch with respect to the threat; and

notify a user when the effectiveness is below a predetermined threshold.

4. The system of claim 1 , wherein the instructions further cause the processor to analyze the inbound traffic in a test environment that is separate from the computing resource.

5. The system of claim 1 , wherein the instructions further cause the processor to detect the threat prior to the threat affecting the computer resource.

6. The system of claim 1 , wherein the computer resource is a server and the patch is applied to a kernel of the server.

7. The system of claim 1 , wherein the analysis of the first plurality of parameter values determines an impact on the enterprise network.

8. A method, comprising:

monitoring inbound traffic to an enterprise network;

detecting a first threat based on analysis of a first plurality of parameter values of the inbound traffic;

automatically determining based on the first plurality of parameter values a first patch that mitigates the first threat on a computing resource in the enterprise network;

detecting a second threat based on analysis of a second plurality of parameter values;

when the first plurality of parameter values and the second plurality of parameter values have one or more parameter values in common, automatically generating a second patch for the second threat based in part on a portion of the first patch and the second plurality of parameter values;

providing the second patch to the computing resource for deployment of the patch on the computing resource;

generating a third patch for an unknown threat from at least one existing patch associated with a known threat;

identifying one or more parameter values associated with the at least one existing patch;

computing a similarity score based on a result of a comparison of the one or more parameter values for associated with the threat and the one or more parameter values associated with the at least one existing patch; and

determining the at least one existing patch based on comparison of the similarity score to a predetermined threshold.

9. The method of claim 8 , further comprising determining the patch by matching at least one of the first plurality of parameter values of the inbound traffic to a known threat and corresponding patch.

10. The method of claim 8 , further comprising:

predicting effectiveness of the patch with respect to the threat; and

notifying a user when the effectiveness is below a predetermined threshold.

11. The method of claim 10 , further comprising updating the patch based on input received from the user.

12. The method of claim 8 , further comprising:

analyzing the inbound traffic in a test environment that is separate from the computing resource, wherein the analysis of the one or more parameter values determines an impact on the enterprise network.

13. A method, comprising:

executing, on a processor, instructions that cause the processor to perform operations comprising:

monitoring inbound traffic to an enterprise network;

detecting presence of an unknown threat, prior to the unknown threat impacting an enterprise server, based on analysis of values of a first plurality of parameters of the inbound traffic;

identifying at least one first patch associated with a threat based on the first plurality of parameter values;

detecting a second threat based on analysis of a second plurality of parameter values;

when the first plurality of parameter values and the second plurality of parameter values have one or more parameter values in common, automatically generating a second patch for the second threat based in part on a portion of the at least one patch to address the unknown threat and the second plurality of parameter values;

conveying the second patch for application on a kernel of the enterprise server;

generating a third patch for an unknown threat from at least one existing patch associated with a known threat;

identifying one or more parameter values associated with the at least one existing patch;

computing a similarity score based on a result of a comparison of the one or more parameter values for associated with the threat and the one or more parameter values associated with the at least one existing patch; and

determining the at least one existing patch based on comparison of the similarity score to a predetermined threshold.

14. The method of claim 13 , the operations further comprising:

predicting effectiveness of the at least one first patch with respect to the threat; and

notifying a user when the effectiveness is below a predetermined threshold.

15. The method of claim 14 , the operations further comprising updating the at least one first patch based on input received from the user.

Assignments (2)
ADDRESS CHANGE Recorded Jun 2, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071769/0158 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2022
From: PRAYAGA, DIVAKAR SASTRY; KODE, RAJASEKHAR
To: WELLS FARGO BANK, N.A.
Reel/Frame 060785/0661 →
Cited By (5)
US 12,519,821 US 12,524,552 US 12,526,295 US 12,609,959 US 12,639,193