IP Library Granted Patent US 11,722,517
Granted Patent B1
US 11,722,517 · App. 17/746,173 · Granted Aug 8, 2023

Predictive modeling for anti-malware solutions

Inventors: Ryan B. Benskin (Charlotte, NC); Lawrence T. Belton, Jr. (Charlotte, NC); Christopher Houser (Mt. Holly, NC); Peter A. Makohon (Huntersville, NC); Timothy Morris (Lexington, NC); Omar S. Bracey (Glen Allen, VA)
Assignee: Wells Fargo Bank, N.A.
H04L63/145G06N5/04G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,722,517
App. No.
17/746,173
Granted
Aug 8, 2023
Kind
B1
Abstract

Provided is predictive modeling for anti-malware solutions. A profile for a device is determined based on at least one characteristic identified from a successful attempt by the device to access a network. An expected characteristic for a next access attempt by the device to access the network is determined based on the profile. The characteristic of the next access attempt is matched to the expected characteristic. In response to determining that at least one characteristic of the next access attempt matches the expected characteristic, the next access attempt by the device to the network is automatically granted.

Claims (56)

1. A method comprising:

creating a profile for a device based on at least one characteristic identified from a successful attempt by the device to access a network;

determining an expected characteristic for a next access attempt by the device to access the network based, at least in part, on the profile;

matching at least one characteristic of the next access attempt to the expected characteristic; and

in response to determining that the at least one characteristic of the next access attempt matches the expected characteristic, automatically granting the next access attempt by the device to the network.

2. The method of claim 1 , wherein the next access attempt is granted without requiring a supplicant to be installed on the device.

3. The method of claim 1 , wherein determining the expected characteristic for the next access attempt by the device to access the network comprises:

accessing historical data associated with the device;

predicting a port connection for the next attempt to access the network; and

determining a path the device uses to connect with the network.

4. The method of claim 3 , wherein the historical data comprises one or more of profile data generated during one or more previous access attempts, information regarding use history associated with the device, previous login locations or geographic coordinates or IP addresses, data indicative of an operations system at the device, a hardware class associated with the device, or a path behavior of the device.

5. The method of claim 1 , further comprising:

determining a first manner of authenticating the device for a first access attempt of the device based on the profile; and

determining a second manner of authenticating the device for a second access attempt of the device based on the profile, wherein the second manner is different from the first manner.

6. The method of claim 1 , further comprising:

in response to determining that the at least one characteristic of the next access attempt does not match the expected characteristic, requesting additional information from the device or automatically denying the next access attempt, wherein the additional information comprises re-authentication to a port based on a state change between the device and the network.

7. The method of claim 1 , wherein determining an expected characteristic for a next access attempt is performed using a machine learning procedure.

8. The method of claim 1 , wherein the expected characteristic for the next access attempt comprises a prediction of a characteristic of a next attempt to log in from the device to a port in an 802.1X network.

9. The method of claim 1 , further comprising:

detecting a state change between the device and the network requiring re-authentication to a port;

based on the detected state change, accessing the profile and a prediction model configured to predict a way the device uses to connect to the port;

determining that an access attempt is in conformance with expected characteristics; and

granting or denying the access attempt based on the determination.

10. A system, comprising:

a processing device; and

a non-transitory computer-readable medium communicatively coupled to the processing device, wherein the processing device is configured to execute program code stored in the non-transitory computer-readable medium and thereby perform operations comprising:

creating a profile for a device based on at least one characteristic identified from a successful attempt by the device to access a network;

determining an expected characteristic for a next access attempt by the device to access the network based, at least in part, on the profile;

matching at least one characteristic of the next access attempt to the expected characteristic; and

in response to determining that the at least one characteristic of the next access attempt matches the expected characteristic, automatically granting the next access attempt by the device to the network.

11. The system of claim 10 , wherein determining the expected characteristic for the next access attempt by the device to access the network comprises:

accessing historical data associated with the device;

predicting a port connection for the next attempt to access the network; and

determining a path the device uses to connect with the network.

12. The system of claim 11 , wherein the historical data comprises one or more of profile data generated during one or more previous access attempts, information regarding use history associated with the device, previous login locations or geographic coordinates or IP addresses, data indicative of an operations system at the device, a hardware class associated with the device, or a path behavior of the device.

13. The system of claim 10 , wherein the operations further comprise:

determining a first manner of authenticating the device for a first access attempt of the device based on the profile; and

determining a second manner of authenticating the device for a second access attempt of the device based on the profile, wherein the second manner is different from the first manner.

14. The system of claim 10 , wherein the operations further comprise:

in response to determining that the at least one characteristic of the next access attempt does not match the expected characteristic, requesting additional information from the device or automatically denying the next access attempt, wherein the additional information comprises re-authentication to a port based on a state change between the device and the network.

15. The system of claim 10 , wherein the expected characteristic for the next access attempt comprises a prediction of a characteristic of a next attempt to log in from the device to a port in an 802.1X network.

16. A non-transitory computer-readable medium having program code that is stored thereon, the program code executable by one or more processing devices for performing operations comprising:

creating a profile for a device based on at least one characteristic identified from a successful attempt by the device to access a network;

determining an expected characteristic for a next access attempt by the device to access the network based, at least in part, on the profile;

matching at least one characteristic of the next access attempt to the expected characteristic; and

in response to determining that the at least one characteristic of the next access attempt matches the expected characteristic, automatically granting the next access attempt by the device to the network.

17. The non-transitory computer-readable medium of claim 16 , wherein determining the expected characteristic for the next access attempt by the device to access the network comprises:

accessing historical data associated with the device;

predicting a port connection for the next attempt to access the network; and

determining a path the device uses to connect with the network.

18. The non-transitory computer-readable medium of claim 16 , wherein the operations further comprise:

determining a first manner of authenticating the device for a first access attempt of the device based on the profile; and

determining a second manner of authenticating the device for a second access attempt of the device based on the profile, wherein the second manner is different from the first manner.

19. The non-transitory computer-readable medium of claim 16 , wherein the operations further comprise:

in response to determining that the at least one characteristic of the next access attempt does not match the expected characteristic, requesting additional information from the device or automatically denying the next access attempt, wherein the additional information comprises re-authentication to a port based on a state change between the device and the network.

20. The non-transitory computer-readable medium of claim 16 , wherein the expected characteristic for the next access attempt comprises a prediction of a characteristic of a next attempt to log in from the device to a port in an 802.1X network.

Assignments (2)
ADDRESS CHANGE Recorded Jun 2, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071769/0143 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2022
From: BENSKIN, RYAN B.; BELTON, LAWRENCE T., JR.; HOUSER, CHRISTOPHER; MAKOHON, PETER A.; MORRIS, TIMOTHY; BRACEY, OMAR
To: WELLS FARGO BANK, N.A.
Reel/Frame 059931/0975 →
Continuity (4)
Continuation 16905522 · Jun 18, 2020
Continuation 15907916 · Feb 28, 2018
Continuation 15661907 · Jul 27, 2017
Continuation 14658378 · Mar 16, 2015