IP Library Granted Patent US 11,588,836
Granted Patent B2
US 11,588,836 · App. 17/360,198 · Granted Feb 21, 2023

Systems and methods relating to neural network-based API request pattern analysis for real-time insider threat detection

Inventors: William Anthony Alford (Durham, NC); Megan Amberly Thornton (Provo, UT); Andrew Tyler Harwood (Yulee, FL); Danny Rappleyea (Durham, NC)
Assignee: Genesys Cloud Services, Inc.
H04L63/1416H04L41/16H04L67/133
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,588,836
App. No.
17/360,198
Granted
Feb 21, 2023
Kind
B2
Abstract

A method of neural network-based pattern analysis for real-time threat detection according to an embodiment includes receiving a real-time request for a system resource from a user of the system, determining a user identifier associated with the user of the system, retrieving a set of recent requests associated with the user identifier from a short-term buffer, analyzing, using machine learning, the real-time request based on the set of recent requests and a neural network model to determine whether the real-time request is suspicious, and flagging the real-time request as a suspicious request in response to a determination that the real-time request is suspicious.

Claims (34)

1. A method of neural network-based pattern analysis for real-time threat detection, the method comprising:

receiving, by a system, a real-time request for a system resource from a user of the system;

determining, by the system, a user identifier associated with the user of the system;

retrieving, by the system, a set of recent requests associated with the user identifier from a short-term buffer;

analyzing, by the system using machine learning, the real-time request based on the set of recent requests and a neural network model to determine whether the real-time request is suspicious;

flagging, by the system, the real-time request as a suspicious request in response to a determination that the real-time request is suspicious; and

automatically disabling, by the system, the user's ability to submit requests to the system in response to flagging at least a threshold number of real-time requests as suspicious requests.

2. The method of claim 1 , wherein flagging the real-time request as the suspicious request comprises storing data associated with the real-time request in a suspicious request history database.

3. The method of claim 1 , wherein the set of recent requests comprises up to twenty most recent requests by the user.

4. The method of claim 1 , wherein receiving the real-time request for the system resource comprises receiving real-time request metadata via an application programming interface (API) of the system.

5. The method of claim 4 , further comprising transmitting, by the system, the real-time request metadata to a message bus; and

wherein analyzing the real-time request comprises extracting the real-time request metadata from the message bus.

6. The method of claim 4 , further comprising training, by the system, the neural network model based on the real-time request metadata.

7. The method of claim 1 , wherein analyzing the real-time request based on the set of recent requests and the neural network model comprises determining, for each system resource of a plurality of system resources, a probability that a next real-time request is associated with the corresponding system resource.

8. The method of claim 7 , wherein determining that the real-time request is suspicious comprises determining that a probability of the real-time request is the next real-time request is below a threshold probability.

9. The method of claim 7 , wherein determining that the real-time request is suspicious comprises: determining a set of the next real-time requests having greatest corresponding probabilities; and determining that the real-time request is suspicious in response to determining that the real-time request is not included in the set of the next real-time requests having the greatest corresponding probabilities.

10. The method of claim 9 , wherein the set of the next real-time requests comprises a configurable number of requests.

11. A system for neural network-based pattern analysis for real-time threat detection, the system comprising:

at least one processor; and

at least one memory comprising a plurality of instructions stored thereon that, in response to execution by the plurality of instructions, causes the system to:

receive a real-time request for a system resource from a user of the system via an application programming interface (API) of the system;

determine a user identifier associated with the user of the system;

retrieve a set of recent requests associated with the user identifier from a short-term buffer;

analyze, using machine learning, the real-time request based on the set of recent requests and a neural network model to determine whether the real-time request is suspicious;

flag the real-time request as a suspicious request in response to a determination that the real-time request is suspicious; and

automatically disable the user's ability to submit requests to the system in response to a determination that at least a threshold number of real-time requests have been flagged as suspicious requests.

12. The system of claim 11 , wherein the at least one memory comprises a suspicious request history database; and wherein to flag the real-time request as the suspicious request comprises to store data associated with the real-time request in the suspicious request history database.

13. The system of claim 11 , wherein the plurality of instructions further causes the system to transmit the real-time request to a message bus; and wherein to analyze the real-time request comprises to extract the real-time request from the message bus.

14. The system of claim 11 , wherein the plurality of instructions further causes the system to train the neural network model based on the real-time request.

15. The system of claim 11 , wherein the set of recent requests comprises up to twenty most recent requests by the user.

16. The system of claim 11 , wherein to analyze the real-time request based on the set of recent requests and the neural network model comprises to determine, for each system resource of a plurality of system resources, a probability that a next real-time request is associated with the corresponding system resource.

17. The system of claim 16 , wherein to determine that the real-time request is suspicious comprises to: determine a set of the next real-time requests having greatest corresponding probabilities; and

determine that the real-time request is suspicious in response to a determination that the real-time request is not included in the set of the next real-time requests having the greatest corresponding probabilities.

18. The system of claim 16 , wherein to determine that the real-time request is suspicious comprises to determine that a probability of the real-time request is the next real-time request is below a threshold probability.

Assignments (4)
NOTICE OF SUCCESSION OF SECURITY INTERESTS AT REEL/FRAME 064367/0879 Recorded Feb 4, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: GOLDMAN SACHS BANK USA, AS SUCCESSOR AGENT
Reel/Frame 070098/0287 →
SECURITY AGREEMENT Recorded Jul 24, 2023
From: GENESYS CLOUD SERVICES, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 064367/0879 →
CHANGE OF NAME Recorded Sep 28, 2022
From: GENESYS TELECOMMUNICATIONS LABORATORIES, INC.
To: GENESYS CLOUD SERVICES, INC.
Reel/Frame 061570/0555 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2021
From: ALFORD, WILLIAM ANTHONY; THORNTON, MEGAN AMBERLY; HARWOOD, ANDREW TYLER; RAPPLEYEA, DANNY
To: GENESYS TELECOMMUNICATIONS LABORATORIES, INC.
Reel/Frame 056687/0659 →