IP Library › Granted Patent US 12,524,294
Granted Patent B2
US 12,524,294 · App. 18/242,077 · Granted Jan 13, 2026

Remediation action system

Inventors: Matthew Louis Nowak (Midlothian, VA); Keith D. Greene (Mechanicsville, VA); Catherine Barnes (Glen Allen, VA); David Walter Peters (Richmond, VA)
Assignee: Capital One Services, LLC
G06F11/0793G06F11/0787G06F16/288G06F18/22G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,524,294
App. No.
18/242,077
Granted
Jan 13, 2026
Kind
B2
Abstract

Aspects described herein may use machine learning models to predict one or more remediation actions to mitigate reoccurrence of an incident that has become restored based upon previous incidents of an entity. Historical incident data is compiled into two incident datasets: one representative of incidents that were assigned a remediation action to mitigate reoccurrence of the incident, and a second representative of incidents that were not assigned a remediation action. A machine learning model matches relationships between data in the two datasets and outputs scores representative of similarities. Based on the scores, one or more remediation actions are mapped to an incident in the second dataset and the remediation action is performed for the incident.

Claims (49)

1 . A method comprising:

compiling, by a first computing device, historical incident data maintained in a database, the historical incident data representative of data of assets of an entity previously involved in one or more incidents, into:

a first incident dataset representative of the one or more incidents that were assigned at least one remediation action, wherein each remediation action was assigned to mitigate reoccurrence of a corresponding incident, and

a second incident dataset representative of the one or more incidents that were not assigned at least one remediation action; and

inputting the first incident dataset into a first machine learning model trained to:

classify, based on the first incident dataset, each of the one or more incidents into different categories; and

determine, based on the classification, at least one trend between the different categories;

inputting the second incident dataset into a second machine learning model trained to:

output, based on semantically matching, at least based on the classification and based on determining the at least one trend, one or more first descriptions of the one or more incidents in the first incident dataset with a second description of a first incident in the second incident dataset by utilizing at least one text similarity algorithm, a score representative of a similarity of the one or more first descriptions and the second description; and

causing, based on the score representative of a similarity of the one or more first descriptions and the second description, performance of the at least one remediation action associated with the one or more incidents of the first incident dataset.

2 . The method of claim 1 , further comprising receiving the historical incident data.

3 . The method of claim 1 , wherein the one or more first descriptions of the one or more incidents in the first incident dataset is a text entry describing a cause of the one or more incidents.

4 . The method of claim 1 , wherein the one or more first descriptions are words from a textual data field of the first incident dataset.

5 . The method of claim 1 , wherein the one or more first descriptions is one or more named entity recognition terms in the first incident dataset.

6 . The method of claim 1 , wherein the one or more first descriptions is a part of speech of a textual data field of the first incident dataset.

7 . The method of claim 1 , wherein the second machine learning model is further trained to semantically match the one or more first descriptions of the one or more incidents in the first incident dataset with a second description of a first incident in the second incident dataset by utilizing at least one text similarity algorithm.

8 . The method of claim 1 , further comprising mapping, based on the score for each of the one or more first descriptions, one of the at least one remediation action to the first incident.

9 . The method of claim 8 , further comprising providing the mapped one of the at least one remediation action.

10 . The method of claim 9 , wherein performance of the at least one remediation action further comprises the mapped one of the at least one remediation action.

11 . The method of claim 10 , further comprising, after the mapping, determining whether a new remediation action is assigned to the first incident.

12 . The method of claim 1 , further comprising adding data of the first incident into the first incident dataset and removing data of the first incident from the second incident dataset.

13 . One or more non-transitory media storing instructions that, when executed by one or more processors, cause the one or more processors to:

compile historical incident data maintained in a database, the historical incident data representative of data of assets of an entity previously involved in one or more incidents, into:

a first incident dataset representative of the one or more incidents that were assigned at least one remediation action, wherein each remediation action was assigned to mitigate reoccurrence of a corresponding incident, and

a second incident dataset representative of the one or more incidents that were not assigned at least one remediation action; and

input the first incident dataset into a first machine learning model trained to:

classify, based on the first incident dataset, each of the one or more incidents into different categories; and

determine, based on the classification, at least one trend between the different categories;

input the second incident dataset into a second machine learning model trained to:

output, based on semantically matching, at least based on the classification and based on determining at least one trend, one or more first descriptions of the one or more incidents in the first incident dataset with a second description of a first incident in the second incident dataset by utilizing at least one text similarity algorithm, a score representative of a similarity of the one or more first descriptions and the second description; and

cause, based on the score representative of a similarity of the one or more first descriptions and the second description, performance of the at least one remediation action associated with the one or more incidents of the first incident dataset.

14 . The one or more non-transitory media storing instructions of claim 13 , wherein the second machine learning model is further trained to semantically match the one or more first descriptions of the one or more incidents in the first incident dataset with a second description of a first incident in the second incident dataset by utilizing at least one text similarity algorithm.

15 . The one or more non-transitory media storing instructions of claim 13 , that, when executed by the one or more processors, further cause the one or more processors to map, based on the score for each of the one or more first descriptions, one of the at least one remediation action to the first incident.

16 . The one or more non-transitory media storing instructions of claim 15 , that, when executed by the one or more processors, further cause the one or more processors to provide the mapped one of the at least one remediation action.

17 . The one or more non-transitory media storing instructions of claim 16 , wherein performance of the at least one remediation action further comprises the mapped one of the at least one remediation action associated with the one or more incidents of the first incident dataset.

18 . The one or more non-transitory media storing instructions of claim 13 , that, when executed by the one or more processors, further cause the one or more processors to add data of the first incident into the first incident dataset and removing data of the first incident from the second incident dataset.

19 . The one or more non-transitory media storing instructions of claim 13 , wherein the one or more first descriptions of the one or more incidents in the first incident dataset is a text entry describing a cause of the one or more incidents.

20 . A computing device, comprising:

at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing device to:

compile historical incident data maintained in a database, the historical incident data representative of data of assets of an entity previously involved in one or more incidents, into:

a first incident dataset representative of the one or more incidents that were assigned at least one remediation action, wherein each remediation action was assigned to mitigate reoccurrence of a corresponding incident, and

a second incident dataset representative of the one or more incidents that were not assigned at least one remediation action; and

input the first incident dataset into a first machine learning model trained to:

classify, based on the first incident dataset, each of the one or more incidents into different categories; and

determine, based on the classification, at least one trend between the different categories;

input the second incident dataset into a second machine learning model trained to:

output, based on semantically matching, at least based on the classification and based on determining at least one trend, one or more first descriptions of the one or more incidents in the first incident dataset with a second description of a first incident in the second incident dataset by utilizing at least one text similarity algorithm, a score representative of a similarity of the one or more first descriptions and the second description; and

cause, based on the score representative of a similarity of the one or more first descriptions and the second description, performance of the at least one remediation action associated with the one or more incidents of the first incident dataset.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2023
From: NOWAK, MATTHEW LOUIS; GREENE, KEITH D.; BARNES, CATHERINE; PETERS, DAVID WALTER
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 064815/0896 →
Continuity (2)
Continuation 17509483 · Oct 25, 2021
Related Publication 20230409424A1 · Dec 21, 2023
References Cited (22)
US 8751421B2 · Anderson et al. · 2014 [cited by applicant]
US 10375098B2 · Oliner et al. · 2019 [cited by applicant]
US 12169794B1 · Goodwin et al. · 2024 [cited by applicant]
US 20040153823A1 · Ansari · 2004 [cited by examiner]
US 20140180738A1 · Phillipps et al. · 2014 [cited by applicant]
US 20160330219A1 · Hasan · 2016 [cited by applicant]
US 20190095821A1 · Pourmohammad · 2019 [cited by applicant]
US 20190130310A1 · Madhava Rao et al. · 2019 [cited by applicant]
US 20190180172A1 · Baughman et al. · 2019 [cited by applicant]
US 20190213509A1 · Burleson et al. · 2019 [cited by applicant]
US 20190378073A1 · Lopez et al. · 2019 [cited by applicant]
US 20200026632A1 · Brinkmann · 2020 [cited by examiner]
US 20200104401A1 · Burnett et al. · 2020 [cited by applicant]
US 20200293946A1 · Sachan et al. · 2020 [cited by applicant]
US 20200322361A1 · Ravindra et al. · 2020 [cited by applicant]
US 20210075814A1 · Bulut et al. · 2021 [cited by applicant]
US 20220343081A1 · Gnanasambandam et al. · 2022 [cited by applicant]
US 20230061264A1 · Mohanty et al. · 2023 [cited by applicant]
CA 2947936A1 · 2014 [cited by applicant]
Wikipedia string metric page, retrieved from https://en.wikipedia.org/wiki/String_metric (Year: 2024). [cited by examiner]
Wikipedia “machine learning” page, retrieved from https://en.wikipedia.org/wiki/Machine_learning (Year: 2024). [cited by examiner]
Wikipedia “search string algorithm” page, retieved from https://en.wikipedia.org/wiki/String-searching_algorithm (Year: 2025). [cited by examiner]