IP Library Granted Patent US 12,287,877
Granted Patent B1
US 12,287,877 · App. 18/048,324 · Granted Apr 29, 2025

Determining false positives of file change events detected by file integrity monitoring tools

Inventors: Christopher Sean Michael Stamp (Austin, TX); Daniel Fricano (Round Hill, VA); Kevin Michael Wurzer (Richfield, MN)
Assignee: Wells Fargo Bank, N.A.
G06F21/565G06F16/2358G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,287,877
App. No.
18/048,324
Granted
Apr 29, 2025
Kind
B1
Abstract

A system comprises a memory and one or more processors in communication with the memory. The one or more processors may be configured to obtain information associated with one or more authorized file changes and store the information associated with one or more authorized file changes in a first index. The processors may be further configured to obtain one or more file change events and enrich the one or more file change events with the information associated with one or more authorized file changes from the first index. The processors may also be configured to store the one or more file change events enriched with the information associated with one or more authorized file changes in a second index, and based on the enriched data stored in the second index, output an indication that the one or more file change events are false positives.

Claims (55)

1. A system comprising:

a memory;

one or more processors in communication with the memory, the one or more processors configured to:

obtain information associated with one or more authorized file changes;

store the information associated with one or more authorized file changes in a first index;

obtain one or more file change events;

integrate the one or more file change events with the information associated with one or more authorized file changes from the first index, one or more incident tasks associated with the one or more file change events, and one or more assets associated with the one or more file change events or the one or more incident tasks to generate integrated data,

wherein integrating the one or more file change events is based on a determination that one or more fields of the one or more file change events match one or more fields of the information associated with one or more authorized file changes, the one or more incident tasks, or the one or more assets, and

wherein the one or more assets comprise a device associated with the one or more file change events or the one or more task incidents;

store the integrated data in a second index; and

output, based on the integrated data stored in the second index, an indication that the one or more file change events are false positives.

2. The system of claim 1 , wherein the information associated with one or more authorized file changes comprises information associated with at least one or more change requests, one or more task incidents, one or more assets associated with the one or more change requests, and one or more assets associated with the one or more task incidents.

3. The system of claim 1 , wherein the one or more fields of the information associated with one or more authorized file changes comprises at least one of a start time of a change request, an end time of the change request, and a description of a phase of the change request.

4. The system of claim 1 , wherein the one or more fields of the information associated with one or more authorized file changes comprises at least one of an open time of an incident task, a close time of the incident task, and a description of a phase of the task incident.

5. The system of claim 4 , wherein the one or more fields of the information associated with one or more authorized file changes comprises at least one of a start time of a change request, an end time of the change request, business information, user information, or confidentiality of data.

6. The system of claim 1 , wherein to integrate the one or more file change events with the information associated with one or more authorized change requests from the first index, the one or more incident tasks associated with the one or more file change events, and the one or more assets associated with the one or more file change events or the one or more incident tasks to generate integrated data, the one or more processors are further configured to:

determine a time of a file change event of the one or more file change events is within a start time or an end time of a change request.

7. The system of claim 1 , wherein to integrate the one or more file change events with the information associated with one or more authorized change requests from the first index, the one or more incident tasks associated with the one or more file change events, and the one or more assets associated with the one or more file change events or the one or more incident tasks to generate integrated data, the one or more processors are further configured to:

determine a time of a file change event of the one or more file change events is within an open time or a close time of an incident task.

8. The system of claim 1 ,

wherein to integrate the one or more change requests with the one or more assets, the one or more processors are further configured to integrate the one or more change requests with the one or more assets based on a ticket identifier of a ticket associated with at least one of the one or more change requests; and

wherein to integrate the one or more change requests with the one or more incident tasks, the one or more processors are further configured to integrate the one or more change requests with the one or more incident tasks based on a ticket associated with at least one of the one or more incident tasks.

9. The system of claim 1 , further comprising:

a cache configured to store a subset of the information associated with one or more authorized file changes stored in the first index, and

wherein to integrate the one or more file change events with the information associated with one or more authorized file changes from the first index, the one or more incident tasks associated with the one or more file change events, and the one or more assets associated with the one or more file change events or the one or more incident tasks to generate integrated data, the one or more processors are further configured to:

obtain, from the cache, the subset of the information associated with one or more authorized file changes stored in the first index.

10. The system of claim 9 , wherein the subset of the information associated with one or more authorized file changes stored in the first index comprises the information for a current day.

11. The system of claim 1 , wherein the subset of the information associated with one or more authorized file changes stored in the first index comprises the information for a period of time.

12. A method comprising:

obtaining information associated with one or more authorized file changes from a computer management system;

storing the information associated with one or more authorized file changes in a first index;

obtaining one or more file change events;

integrating the one or more file change events with the information associated with the one or more authorized file changes from the first index, one or more incident tasks associated with the one or more file change events, and one or more assets associated with the one or more file change events or the one or more incident tasks to generate integrated data,

wherein integrating the one or more file change events is based on a determination that one or more fields of the one or more file change events match one or more fields of the information associated with one or more authorized file changes, the one or more incident tasks, or the one or more assets,

wherein the one or more assets comprise a device associated with the one or more file change events or the one or more incident tasks;

storing the integrated data in a second index; and

outputting, based on the integrated data stored in the second index, an indication that the one or more file change events are false positives.

13. The method of claim 12 , wherein the information associated with one or more authorized file changes comprises information associated with at least one or more change requests, one or more task incidents, one or more assets associated with the one or more change requests, and one or more assets associated with the one or more task incidents.

14. The method of claim 12 , wherein the one or more fields of the information associated with one or more authorized file changes comprises at least one of a start time of a change request, an end time of the change request, and a description of a phase of the change request.

15. The method of claim 12 , wherein the one or more fields of the information associated with one or more authorized file changes comprises at least one of an open time of an incident task, a close time of the incident task, and a description of a phase of the task incident.

16. The method of claim 12 , wherein the one or more fields of the information associated with one or more authorized file changes comprises at least one of a start time of a change request, an end time of the change request, business information, user information, or confidentiality of data.

17. The method of claim 12 , wherein integrating the one or more file change events with the information associated with the one or more authorized file changes from the first index, the one or more incident tasks associated with the one or more file change events, and the one or more assets associated with the one or more file change events or the one or more incident tasks to generate integrated data comprises determining a time of a file change event of the one or more file change events is within a start time or an end time of a task incident.

18. The method of claim 12 , wherein integrating the one or more file change events with the information associated with the one or more authorized file changes from the first index, the one or more incident tasks associated with the one or more file change events, and the one or more assets associated with the one or more file change events or the one or more incident tasks to generate integrated data comprises determining a time of a file change event of the one or more file change events is within an open time or a close time of a change request.

19. The method of claim 12 ,

wherein integrating the one or more change requests with the one or more assets is based on a ticket identifier of a ticket associated with at least one of the one or more change requests; and

wherein integrating the one or more change requests with the one or more incident tasks is based on a ticket associated with at least one of the one or more task incidents.

20. Non-transitory computer readable media comprising instructions that when executed cause one or more processors to:

obtain the information associated with one or more authorized file changes;

store the information associated with one or more authorized file changes in a first index;

obtain one or more file change events;

integrate the one or more file change events with the information associated with one or more authorized file changes from the first index, one or more incident tasks associated with the one or more file change events, and one or more assets associated with the one or more file change events or the one or more incident tasks to generate integrated data,

wherein integrating the one or more file change events with the information associated with one or more authorized file changes from the first index is based on a determination that one or more fields of the one or more file change events match one or more fields of the information associated with one or more authorized file changes, the one or more incident tasks, or the one or more assets, and

wherein the one or more assets comprise a device associated with the one or more file change events or the one or more incident tasks;

store the integrated data in a second index; and

output, based on the integrated data stored in the second index, an indication that the one or more file change events are false positives.

Assignments (2)
REQUEST FOR ADDRESS CHANGE Recorded Dec 5, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 073895/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2023
From: STAMP, CHRISTOPHER SEAN MICHAEL; FRICANO, DANIEL; WURZER, KEVIN MICHAEL
To: WELLS FARGO BANK, N.A.
Reel/Frame 065481/0780 →
Continuity (1)
Provisional Application 63368229 · Jul 12, 2022
References Cited (16)
US 7032114B1 · Moran · 2006 [cited by applicant]
US 8060889B2 · Sim-Tang · 2011 [cited by applicant]
US 8978137B2 · Friedrichs et al. · 2015 [cited by applicant]
US 8997201B2 · Wotring · 2015 [cited by applicant]
US 9166994B2 · Ward et al. · 2015 [cited by applicant]
US 9519775B2 · Sridhara et al. · 2016 [cited by applicant]
US 10554678B2 · Miller et al. · 2020 [cited by applicant]
US 10581851B1 · File · 2020 [cited by examiner]
US 11153333B1 · Hermoni · 2021 [cited by examiner]
US 20090094462A1 · Madduri · 2009 [cited by examiner]
US 20100228750A1 · Solin · 2010 [cited by applicant]
Abela, “How to eliminate false positives in file integrity monitoring on WordPress”, Security Boulevard, Jan. 16, 2020, 8 pp., URL: https://securityboulevard.com/2020/01/how-to-eliminate-false-positives-in-file-integrit… [cited by applicant]
Breier et al., “A Dynamic Rule Creation Based Anomaly Detection Method for Identifying Security Breaches in Log Records”, vol. 94, Springer Science+Business Media New York, Nov. 16, 2015, pp. 497-511. [cited by applicant]
Cisco, “Cisco Advanced Malware Protection”, 2016, 6 pp., Retrieved from the Internet on Jan. 19, 2023 from URL: https://www.connection.com/˜/media/pdfs/brands/c/cisco/cisco-security-amp-solution-overview.pdf?la=en. [cited by applicant]
Kim et al., “Experiences with Tripwire: Using Integrity Checkers for Intrusion Detection”, Department of Computer Science Technical Reports, Feb. 21, 1994, p. 13. [cited by applicant]
Lakhani, “Applying Retrospective Network Analysis to Disrupt the Cyber Kill Chain”, SS8, 5 pp., Retrieved from the Internet on Jan. 19, 2023 from URL: https://www.nist.gov/system/files/documents/2016/09/16/ss8_rfi_respo… [cited by applicant]