IP Library › Granted Patent US 12,483,574
Granted Patent B1
US 12,483,574 · App. 18/344,640 · Granted Nov 25, 2025

System and method of identifying malicious activity in a network

Inventors: Sara Saperstein (Springfield, MA); John H. Ring, IV (Springfield, MA); Kevin Sopuch (Springfield, MA); James Hefferman (Springfield, MA); Lindsey Basara (Springfield, MA); Evan Moore (Springfield, MA)
Assignee: Massachusetts Mutual Life Insurance Company
H04L63/1425H04L41/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,483,574
App. No.
18/344,640
Granted
Nov 25, 2025
Kind
B1
Abstract

Disclosed herein are methods and systems for identifying malicious network activity. In an embodiment, a method comprises monitoring, by a computer, network activity of a user having a baseline network activity; executing, by the computer, a machine learning model to determine a network activity score indicating a likelihood of the network activity being malicious activity for the baseline network activity, the machine learning model having been previously trained based on malicious activity and corresponding baseline network activity; and displaying, by the computer, the network activity score.

Claims (33)

1 . A method comprising:

monitoring, by a computer, network activity of a user having a baseline network activity corresponding to historic network activity of the user;

executing, by the computer, a machine learning model to determine a network activity score indicating a likelihood of the network activity being malicious activity for the baseline network activity, the machine learning model having been previously trained based on malicious activity and corresponding baseline network activity;

generating, by the computer, a similarity score based upon a distance between the network activity score and a centroid of a cluster of network activity scores, the cluster of network activity scores formed based on similarities between one or more network activity scores;

evaluating, by the computer, the network activity score based on the similarity score; and

displaying, by the computer, the network activity score.

2 . The method according to claim 1 , wherein evaluating, by the computer, the network activity score based on the similarity score further comprises:

determining, by the computer, that the network activity score is a strong network activity score based on the similarity score satisfying a high similarity threshold, the strong network activity score indicating that the network activity score is accurate.

3 . The method according to claim 1 , wherein evaluating, by the computer, the network activity score based on the similarity score further comprises:

determining, by the computer, that the network activity score is not a strong network activity score based on the similarity score not satisfying a low similarity threshold, the not strong network activity score indicating that the network activity score is not accurate.

4 . The method according to claim 1 , wherein the cluster of network activity scores is determined by associating one or more historic network activity scores with the centroid of the cluster of network activity scores.

5 . The method according to claim 1 , wherein the baseline network activity is based at least on average network activity of the user generating the network activity.

6 . The method according to claim 5 , wherein the baseline network activity is further based on at least on one of historic network activity of a group of similar users, average network activity of the group of similar users, historic network activity of another user, or average network activity of the another user.

7 . The method according to claim 6 , wherein the machine learning model is based on executing one or more computer models to evaluate the network activity using at least one of a binary decision, the baseline of network activity, or a statistical model.

8 . The method according to claim 7 , wherein determining the network activity score comprises mapping a difference between the network activity and the baseline network activity to the network activity score.

9 . The method according to claim 7 , wherein determining the network activity score comprises mapping a decision of the binary decision to the network activity score.

10 . The method according to claim 7 , wherein determining the network activity score comprises generating a weighted sum of one or more network activity scores determined by the one or more computer models.

11 . A system comprising:

A server comprising a processor and a non-transitory computer-readable medium containing instructions that when executed by the processor cause the processor to preform operations comprising:

monitoring network activity of a user having a baseline network activity corresponding to historic network activity of the user;

executing a machine learning model to determine a network activity score indicating a likelihood of the network activity being malicious activity for the baseline network activity, the machine learning model having been previously trained based on malicious activity and corresponding baseline network activity;

generating a similarity score based upon a distance between the network activity score and a centroid of a cluster of network activity scores, the cluster of network activity scores formed based on similarities between one or more network activity scores;

evaluating the network activity score based on the similarity score; and

displaying the network activity score.

12 . The system according to claim 11 , wherein evaluating the network activity score based on the similarity score further comprises:

determining that the network activity score is a strong network activity score based on the similarity score satisfying a high similarity threshold, the strong network activity score indicating that the network activity score is accurate.

13 . The system according to claim 11 , wherein evaluating the network activity score based on the similarity score further comprises:

determining that the network activity score is not a strong network activity score based on the similarity score not satisfying a low similarity threshold, the not strong network activity score indicating that the network activity score is not accurate.

14 . The system according to claim 11 , wherein the cluster of network activity scores is determined by associating one or more historic network activity scores with the centroid of the cluster of network activity scores.

15 . The system according to claim 11 , wherein the baseline network activity is based at least on average network activity of the user generating the network activity.

16 . The system according to claim 15 , wherein the baseline network activity is further based on at least on one of historic network activity of a group of similar users, average network activity of the group of similar users, historic network activity of another user, or average network activity of the another user.

17 . The system according to claim 16 , wherein the machine learning model is based on executing one or more computer models to evaluate the network activity using at least one of a binary decision, the baseline network activity, or a statistical model.

18 . The system according to claim 17 , wherein determining the network activity score comprises mapping a difference between the network activity and the baseline network activity to the network activity score.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2023
From: SAPERSTEIN, SARA; RING, JOHN H., IV; HEFFERNAN, JAMES; BASARA, LINDSEY; MOORE, EVAN
To: MASSACHUSETTS MUTUAL LIFE INSURANCE COMPANY
Reel/Frame 065224/0163 →
Continuity (1)
Provisional Application 63356836 · Jun 29, 2022
References Cited (9)
US 10911477B1 · Kharraz · 2021 [cited by examiner]
US 20200021607A1 · Muddu · 2020 [cited by examiner]
US 20200027089A1 · Kuchar · 2020 [cited by examiner]
US 20200356676A1 · Gorlamandala · 2020 [cited by examiner]
US 20210126938A1 · Trost · 2021 [cited by examiner]
US 20210136089A1 · Costea · 2021 [cited by examiner]
US 20220027916A1 · Abreu · 2022 [cited by examiner]
US 20230308464A1 · Dong · 2023 [cited by examiner]
US 20240073241A1 · Beard · 2024 [cited by examiner]