IP Library Granted Patent US 12,737,488
Granted Patent B2
US 12,737,488 · App. 18/383,727 · Granted Sep 15, 2026

Disconnected database data structure protection

Inventor: Matthew McDonald (Callahan, FL)
Assignee: ServiceNow, Inc.
G06F21/6218G06F21/552
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,737,488
App. No.
18/383,727
Granted
Sep 15, 2026
Kind
B2
Abstract

Online interaction data between one or more clients and a database server communicating via a network is received. The online interaction data is used to train a data protection machine learning model for detecting a malicious attack. An offline interface for accessing a database data structure is provided, wherein the offline interface is configured to apply the data protection machine learning model trained using the online interaction data to protect the database data structure accessed via the offline interface.

Claims (32)

1 . A method, comprising:

receiving, by way of an offline interface provided as part of a disconnected database in an offline mode, a plurality of local calls from one or more application clients, wherein the offline interface, the disconnected database, and the application clients are executing on a same computing device;

generating, via a data protection machine learning model trained using at least online interaction data captured from a network-accessible database, predictions regarding the plurality of local calls, wherein the data protection machine learning model has been trained to predict whether a call is a malicious call or a non-malicious call; and

based on the predictions from the data protection machine learning model, blocking a local call of the plurality of local calls that is predicted to be malicious from accessing the disconnected database, and allowing a local call of the plurality of local calls that is predicted to be non-malicious to access the disconnected database, wherein blocking the local call that is predicted to be malicious from accessing the disconnected database comprises quarantining an application client associated with the local call.

2 . The method of claim 1 , wherein the data protection machine learning model has been trained to predict whether calls to offline interface are malicious calls or non-malicious calls using known malicious attacks.

3 . The method of claim 1 , wherein the data protection machine learning model has been trained to predict whether calls to offline interface are malicious calls or non-malicious calls using interactions corresponding to structure query language (SQL) injection attacks, denial-of-service (DOS) attacks, data modification attacks, or data theft attacks.

4 . The method of claim 1 , wherein the disconnected database initially includes data from a network-accessible database server.

5 . The method of claim 1 , wherein the offline interface comprises an application programming interface (API) accessible only to applications executing on the same computing device as the disconnected database.

6 . The method of claim 1 , wherein application support for the offline interface is provided via a software development kit (SDK).

7 . A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory is configured to provide the one or more processors with instructions which when executed cause the one or more processors to:

receive, by way of an offline interface provided as part of a disconnected database in an offline mode, a plurality of local calls from one or more application clients, wherein the offline interface, the disconnected database and the application clients are executing on a same computing device;

generate, via a data protection machine learning model trained using at least online interaction data captured from a network-accessible database, predictions regarding the plurality of local calls, wherein the data protection machine learning model has been trained to predict whether a call is a malicious call or a non-malicious call; and

based on the predictions from the data protection machine learning model, block a local call of the plurality of local calls that is predicted to be malicious from accessing the disconnected database, and allowing a local call of the plurality of local calls that is predicted to be non-malicious to access the disconnected database, wherein blocking the local call that is predicted to be malicious from accessing the disconnected database comprises quarantining an application client associated with the local call.

8 . The system of claim 7 , wherein the data protection machine learning model has been trained to predict whether calls to the offline interface are malicious calls or non-malicious calls using known malicious attacks.

9 . The system of claim 7 , wherein the data protection machine learning model has been trained to predict whether calls to the offline interface are malicious calls or non-malicious calls using interactions corresponding to structure query language (SQL) injection attacks, denial-of-service (DOS) attacks, data modification attacks, or data theft attacks.

10 . The system of claim 7 , wherein the disconnected database initially includes data from a network-accessible database server.

11 . The system of claim 7 , wherein the offline interface comprises an application programming interface (API) accessible only to applications executing on the same computing device as the disconnected database.

12 . A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving, by way of an offline interface provided as part of a disconnected database in an offline mode, a plurality of local calls from one or more application clients, wherein the offline interface, the disconnected database, and the application clients are running on a same computing device;

generating, via a data protection machine learning model trained using at least online interaction data captured from a network-accessible database, predictions regarding the plurality of local calls, wherein the data protection machine learning model has been trained to predict whether a call is a malicious call or a non-malicious call; and

based on the predictions from the data protection machine learning model, blocking a local call of the plurality of local calls that is predicted to be malicious from accessing the disconnected database, and allowing a local call of the plurality of local calls that is predicted to be non-malicious to access the disconnected database, wherein blocking the local call that is predicted to be malicious from accessing the disconnected database comprises quarantining an application client associated with the local call.

13 . The method of claim 1 , wherein the online interaction data are based at least in part on a source property, a location context, a time context, one or more targeted data fields, or changes in connectivity.

14 . The method of claim 1 , wherein using the online interaction data to train the data protection machine learning model includes extracting machine learning features from the online interaction data, wherein the machine learning features correspond to one or more source properties of the online interaction data, one or more destination properties of the online interaction data, or one or more database queries of the online interaction data.

15 . The method of claim 1 , wherein the online interaction data includes anomalous database interaction behavior.

16 . The system of claim 7 , wherein the online interaction data are based at least in part on a source property, a location context, a time context, one or more targeted data fields, or changes in connectivity.

17 . The system of claim 7 , wherein using the online interaction data to train the data protection machine learning model includes extracting machine learning features from the online interaction data, wherein the machine learning features correspond to one or more source properties of the online interaction data, one or more destination properties of the online interaction data, or one or more database queries of the online interaction data.

18 . The system of claim 7 , wherein the online interaction data includes anomalous database interaction behavior.

19 . The method of claim 1 , wherein the disconnected database is a copy of the network-accessible database.

20 . The method of claim 1 , wherein the disconnected database is a version of the network-accessible database.

21 . The method of claim 1 , wherein the disconnected database in the offline mode cannot be accessed via a network operation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2024
From: MCDONALD, MATTHEW
To: SERVICENOW, INC.
Reel/Frame 066164/0551 →
Continuity (1)
Related Publication 20250139266A1 · May 1, 2025
References Cited (30)
US 6959329B2 · Thakor · 2005 [cited by applicant]
US 7426512B1 · Ben-Natan · 2008 [cited by examiner]
US 8799448B2 · Yan · 2014 [cited by applicant]
US 10523689B2 · Decenzo · 2019 [cited by applicant]
US 10798165B2 · Srinivasan · 2020 [cited by applicant]
US 10992746B2 · Lucas · 2021 [cited by applicant]
US 11032131B1 · Franceschetti · 2021 [cited by applicant]
US 20050125589A1 · Feng · 2005 [cited by applicant]
US 20050203892A1 · Wesley · 2005 [cited by applicant]
US 20120151036A1 · Detro · 2012 [cited by applicant]
US 20160057211A1 · Thapliyal · 2016 [cited by examiner]
US 20160134595A1 · Lavinio · 2016 [cited by applicant]
US 20160241583A1 · Kowalczyk · 2016 [cited by applicant]
US 20170364700A1 · Goldfarb · 2017 [cited by applicant]
US 20180026956A1 · Caffary, Jr. · 2018 [cited by applicant]
US 20180357304A1 · Balasubrahmanian · 2018 [cited by examiner]
US 20190166029A1 · Abrams · 2019 [cited by applicant]
US 20190297078A1 · Davis, III · 2019 [cited by applicant]
US 20200097587A1 · Klein · 2020 [cited by examiner]
US 20200387833A1 · Kursun · 2020 [cited by applicant]
US 20200389532A1 · Lisac · 2020 [cited by examiner]
US 20200404007A1 · Singh · 2020 [cited by examiner]
US 20210328969A1 · Gaddam · 2021 [cited by examiner]
US 20220012134A1 · Chatterjee · 2022 [cited by applicant]
US 20220156395A1 · Bednash · 2022 [cited by applicant]
US 20220286804A1 · Danducci, II · 2022 [cited by applicant]
CN 115859273A · 2023 [cited by examiner]
WO 2021148461A1 · 2021 [cited by applicant]
Tang et al. “Detection of SQL Injection based on Artificial Neural Network”, Feb. 20, 2020, Knowledge-Based Systems, vol. 190, https://doi.org/10.1016/j.knosys.2020.105528. (Year: 2020). [cited by examiner]
Agent-Based Offline Discovery, downloaded from <https://docs.device42.com/auto-discovery/~gent-based-offline-discovery/> on Feb. 26, 2021 (via the Internet Archive). [cited by applicant]