IP Library › Granted Patent US 12,412,179
Granted Patent B2
US 12,412,179 · App. 17/091,355 · Granted Sep 9, 2025

Patching security vulnerabilities using machine learning

Inventors: Galen Rafferty (Mahomet, IL); Austin Walters (Savoy, IL); Jeremy Goodsitt (Champaign, IL); Anh Truong (Champaign, IL); Vincent Pham (Champaign, IL); Reza Farivar (Champaign, IL); Mark Watson (Urbana, IL)
Assignee: Capital One Services, LLC
G06Q20/4016G06F8/65G06F21/572G06F21/577G06N3/08G06Q10/0635G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,412,179
App. No.
17/091,355
Filed
Nov 6, 2020
Granted
Sep 9, 2025
Kind
B2
Art Unit
2499
USPC
726/25
Abstract

Disclosed herein are system, method, and computer program product embodiments for process corruption prevention. An embodiment operates by determining security vulnerabilities for an entity and correlation values for the security vulnerabilities by applying completed processed records of the entity to a machine learning model. Each of the correlation values quantifies a relationship strength between a security vulnerability and fraudulent activity. The embodiment further operates by generating a security vulnerability score for the entity using the correlation values and identifying one or more patches for at least one of the security vulnerabilities. The one or more patches may be ranked and the ranking may be revised using a feedback mechanism after the one or more patches are implemented by the entity.

Claims (72)

1. A method of process corruption prevention, comprising:

storing, by one or more computing devices, a first plurality of processed records associated with an entity in a repository, wherein each of the first plurality of processed records includes a fraud indicator determined by a fraud detection model that classifies a completed transaction as confirmed fraudulent, suspected fraudulent, or not fraudulent;

determining, by the one or more computing devices, a first plurality of security vulnerabilities for the entity and a first plurality of correlation values for the first plurality of security vulnerabilities by applying a machine learning model to the first plurality of processed records, wherein each of the first plurality of correlation values quantifies a relationship strength between a security vulnerability and a fraudulent activity;

generating, by the one or more computing devices, a first security vulnerability score for the entity using the first plurality of correlation values;

identifying, by the one or more computing devices, a security vulnerability having a greatest correlation value from the first plurality of security vulnerabilities;

implementing, by the one or more computing devices, a patch to mitigate one or more security vulnerabilities of the first plurality of security vulnerabilities, wherein the patch is selected from a plurality of patches in a patch lookup table using the security vulnerability having the greatest correlation value;

determining, by the one or more computing devices, based in part on the implementing the patch for a predefined time period, a change in the first security vulnerability score, wherein the predefined time period is determined based on the security vulnerability having the greatest correlation value; and

implementing, by the one or more computing devices, based on determining the change in the first security vulnerability score, a different patch selected from the plurality of patches.

2. The method of claim 1 , wherein generating the first security vulnerability score comprises:

obtaining, by the one or more computing devices, a first plurality of impact values for the first plurality of security vulnerabilities, wherein each of the first plurality of impact values is a revenue amount of the entity attributable to one of the first plurality of security vulnerabilities; and

calculating, by the one or more computing devices, a weighted average based on the first plurality of impact values and the first plurality of correlation values.

3. The method of claim 1 , further comprising:

transmitting, by the one or more computing devices, the first plurality of security vulnerabilities and the first plurality of correlation values to a processor, wherein the processor updates the fraud detection model based on the first plurality of security vulnerabilities and the first plurality of correlation values.

4. The method of claim 1 , wherein the first plurality of security vulnerabilities comprises a user identifier (ID), and wherein the patch for the security vulnerability having the greatest correlation value comprises enforcing user logouts from user devices.

5. The method of claim 1 , further comprising:

issuing, by the one or more computing devices, a report to the entity, wherein the report comprises at least one of the first plurality of security vulnerabilities, the first plurality of correlation values for the first plurality of security vulnerabilities, the first security vulnerability score, the patch, and an average or median security vulnerability score for other entities similar to the entity receiving the report.

6. A system for process corruption prevention, comprising:

a memory; and

a computer processor coupled to the memory and configured to:

store a first plurality of processed records associated with an entity in a repository, wherein each of the first plurality of processed records includes a fraud indicator determined by a fraud detection model that classifies a completed transaction as confirmed fraudulent, suspected fraudulent, or not fraudulent;

determine a first plurality of security vulnerabilities for the entity and a first plurality of correlation values for the first plurality of security vulnerabilities by applying a machine learning model to the first plurality of processed records, wherein each of the first plurality of correlation values quantifies a relationship strength between a security vulnerability and a fraudulent activity;

generate a first security vulnerability score for the entity using the first plurality of correlation values;

identify a security vulnerability having a greatest correlation value from the first plurality of security vulnerabilities;

implement a patch to mitigate one or more security vulnerabilities of the first plurality of security vulnerabilities, wherein the patch is selected from a plurality of patches in a patch lookup table using the security vulnerability having the greatest correlation value;

determine, based in part on the implementing the patch for a predefined time period, a change in the first security vulnerability score, wherein the predefined time period is determined based on the security vulnerability having the greatest correlation value; and

implement based on determining the change in the first security vulnerability score, a different patch selected from the plurality of patches.

7. The system of claim 6 , wherein the computer processor generates the first security vulnerability score by:

obtaining a first plurality of impact values for the first plurality of security vulnerabilities, wherein each of the first plurality of impact values is a revenue amount of the entity attributable to one of the first plurality of security vulnerabilities; and

calculating a weighted average based on the first plurality of impact values and the first plurality of correlation values.

8. The system of claim 6 , wherein the first plurality of security vulnerabilities comprises a user identifier (ID), and wherein the patch for the security vulnerability having the greatest correlation value comprises enforcing user logouts from user devices.

9. The system of claim 6 , wherein the computer processor is further configured to:

update the fraud detection model based on the first plurality of security vulnerabilities and the first plurality of correlation values.

10. The system of claim 6 , wherein the computer processor is further configured to:

issue a report to the entity, wherein the report comprises at least one of the first plurality of security vulnerabilities, the first plurality of correlation values for the first plurality of security vulnerabilities, the first security vulnerability score, the patch, and an average or median security vulnerability score for other entities similar to the entity receiving the report.

11. A non-transitory computer-readable medium having instructions stored thereon that, when executed by at least one computing device, cause the at least one computing device to perform operations comprising:

storing a first plurality of processed records associated with an entity in a repository, wherein each of the first plurality of processed records includes a fraud indicator determined by a fraud detection model that classifies a completed transaction as confirmed fraudulent, suspected fraudulent, or not fraudulent;

determining a first plurality of security vulnerabilities for the entity and a first plurality of correlation values for the first plurality of security vulnerabilities by applying a machine learning model to the first plurality of processed records, wherein each of the first plurality of correlation values quantifies a relationship strength between a security vulnerability and a fraudulent activity;

generating a first security vulnerability score for the entity using the first plurality of correlation values;

identifying a security vulnerability having a greatest correlation value from the first plurality of security vulnerabilities;

implementing a patch to mitigate one or more security vulnerabilities of the first plurality of security vulnerabilities, wherein the patch is selected from a plurality of patches in a patch lookup table using the security vulnerability having the greatest correlation value;

determining, based in part on the implementing the patch for a predefined time period, a change in the first security vulnerability score, wherein the predefined time period is determined based on the security vulnerability having the greatest correlation value; and

implementing based on determining the change in the first security vulnerability score, a different patch selected from the plurality of patches.

12. The non-transitory computer-readable medium of claim 11 , wherein generating the first security vulnerability score comprises:

obtaining a first plurality of impact values for the first plurality of security vulnerabilities, wherein each of the first plurality of impact values is a revenue amount of the entity attributable to one of the first plurality of security vulnerabilities; and

calculating a weighted average based on the first plurality of impact values and the first plurality of correlation values.

13. The non-transitory computer-readable medium of claim 11 , wherein the first plurality of security vulnerabilities comprises a user identifier (ID), and wherein the patch for the security vulnerability having the greatest correlation value comprises enforcing user logouts from user devices.

14. The non-transitory computer-readable medium of claim 11 , the operations further comprising:

issuing a report to the entity, wherein the report comprises at least one of the first plurality of security vulnerabilities, the first plurality of correlation values for the first plurality of security vulnerabilities, the first security vulnerability score, the patch, and an average or median security vulnerability score for other entities similar to the entity receiving the report.

15. The non-transitory computer-readable medium of claim 11 , the operations further comprising:

transmitting the first plurality of security vulnerabilities and the first plurality of correlation values to a processor, wherein the processor updates the fraud detection model based on the first plurality of security vulnerabilities and the first plurality of correlation values.

16. The method of claim 1 , further comprising:

storing, by the one or more computing devices, a second plurality of processed records associated with the entity in the repository;

determining, by the one or more computing devices, a second plurality of security vulnerabilities for the entity and a second plurality of correlation values for the second plurality of security vulnerabilities by applying the second plurality of processed records to the machine learning model;

obtaining, by the one or more computing devices, a second plurality of impact values for the second plurality of security vulnerabilities;

generating, by the one or more computing devices, a second security vulnerability score for the entity using the second plurality of correlation values and the second plurality of impact values; and

in response to determining that the second security vulnerability score is greater than the first security vulnerability score, updating, by the one or more computing devices, rankings for the plurality of patches in the patch lookup table.

17. The method of claim 16 , further comprising:

training, by the one or more computing devices, the machine learning model using the updated rankings for the plurality of patches in the patch lookup table.

18. The system of claim 6 , wherein the computer processor is further configured to:

store a second plurality of processed records associated with the entity in the repository;

determine a second plurality of security vulnerabilities for the entity and a second plurality of correlation values for the second plurality of security vulnerabilities by applying the second plurality of processed records to the machine learning model;

obtain a second plurality of impact values for the second plurality of security vulnerabilities;

generate a second security vulnerability score for the entity using the second plurality of correlation values and the second plurality of impact values; and

in response to determining that the second security vulnerability score is greater than the first security vulnerability score, update rankings for the plurality of patches in the patch lookup table.

19. The system of claim 18 , wherein the computer processor is further configured to:

train the machine learning model using the updated rankings for the plurality of patches in the patch lookup table.

20. The non-transitory computer-readable medium of claim 11 , the operations further comprising:

storing a second plurality of processed records associated with the entity in the repository;

determining a second plurality of security vulnerabilities for the entity and a second plurality of correlation values for the second plurality of security vulnerabilities by applying the second plurality of processed records to the machine learning model;

obtaining a second plurality of impact values for the second plurality of security vulnerabilities;

generating a second security vulnerability score for the entity using the second plurality of correlation values and the second plurality of impact values; and

in response to determining that the second security vulnerability score is greater than the first security vulnerability score, updating rankings for the plurality of patches in the patch lookup table.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2025
From: RAFFERTY, GALEN; WALTERS, AUSTIN; GOODSITT, JEREMY; TRUONG, ANH; PHAM, VINCENT; FARIVAR, REZA; WATSON, MARK
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 071019/0692 →
Continuity (1)
Related Publication 20220148001A1 · May 12, 2022
References Cited (20)
US 8019678B2 · Wright et al. · 2011 [cited by applicant]
US 10134041B2 · Cowan · 2018 [cited by applicant]
US 10395252B2 · Eisen · 2019 [cited by applicant]
US 10470043B1 · Cherala et al. · 2019 [cited by applicant]
US 10509997B1 · Gupta · 2019 [cited by examiner]
US 10810106B1 · Amit · 2020 [cited by examiner]
US 11516222B1 · Srinivasan · 2022 [cited by examiner]
US 11706241B1 · Cross · 2023 [cited by examiner]
US 11822915B2 · Kwon · 2023 [cited by examiner]
US 12182269B2 · Babic · 2024 [cited by examiner]
US 20140089193A1 · Boding · 2014 [cited by examiner]
US 20180219899A1 · Joy · 2018 [cited by examiner]
US 20200074471A1 · Adjaoute · 2020 [cited by applicant]
US 20210273968A1 · Shaieb · 2021 [cited by examiner]
US 20210352095A1 · Cam · 2021 [cited by examiner]
US 20210374753A1 · Kramme · 2021 [cited by examiner]
US 20210390187A1 · Ahmed · 2021 [cited by examiner]
US 20220046031A1 · Kaidi · 2022 [cited by examiner]
US 20220083450A1 · Geddes · 2022 [cited by examiner]
US 20230252157A1 · Pieczul · 2023 [cited by examiner]
Cited By (1)
US 12,602,486