IP Library Granted Patent US 12,609,956
Granted Patent B2
US 12,609,956 · App. 18/476,488 · Granted Apr 21, 2026

Security information capture and distribution

Inventors: Todd Michael Foulks (Harrisburg, NC); Patrick Kelly O'Donnell (Denver, NC)
Assignee: Wells Fargo Bank, N.A.
H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,956
App. No.
18/476,488
Granted
Apr 21, 2026
Kind
B2
Abstract

An example computer system for capturing security information can include: one or more processors; and non-transitory computer-readable storage media encoding instructions which, when executed by the one or more processors, causes the computer system to create: a dashboard engine programmed to generate a dashboard with the security information thereon; a remediation engine programmed to track remediation of one or more security vulnerabilities; and a report generator engine programmed to generate a report including the security information and the one or more security vulnerabilities, wherein dissemination of the report is controlled.

Claims (22)

1 . A computer system for capturing security information, comprising:

one or more processors; and

non-transitory computer-readable storage media encoding instructions which, when executed by the one or more processors, causes the computer system to create:

a tactics, techniques, and procedures library engine that provides information about security vulnerabilities to generate the security information, wherein the tactics, techniques, and procedures library engine automatically accesses the security vulnerabilities from a third party through execution of an Application Programming Interface call and stores the security vulnerabilities in a tactics, techniques, and procedures database;

a dashboard engine programmed to generate a dashboard with the security information thereon, wherein the dashboard engine tailors the security information based upon a role of a user to provide the security information and wherein the dashboard engine allows the user to drill down on the security information;

a remediation engine programmed to track remediation of one or more of the security vulnerabilities;

an extraction engine programmed to query the tactics, techniques, and procedures database to extract data for inclusion in a report, wherein the extraction engine uses database query constructs to extract data based on a type of the security vulnerabilities and a line of business associated with the security vulnerabilities;

a report generator engine programmed to generate the report including the security information and the one or more of the security vulnerabilities, wherein dissemination of the report is controlled by document rights management limitations that include location-based and time-based limitations on access; and

an administration engine programmed to manage access to the dashboard and the report, wherein the administration engine is further programmed to automatically revoke credentials when individuals move to other responsibilities and to log activity associated with access to reports for auditing purposes.

2 . The computer system of claim 1 , wherein the dashboard includes a list of the one or more of the security vulnerabilities and a heat map of the one or more of the security vulnerabilities.

3 . The computer system of claim 1 , wherein the report generator engine limits an ability of the report to be shared.

4 . The computer system of claim 1 , further comprising instructions which, when executed by the one or more processors, causes the computer system to create a workbench engine programmed to manage a security assessment of an entity.

5 . A method for capturing security information, comprising:

providing information about security vulnerabilities to generate the security information by automatically accessing the security vulnerabilities from a third party through execution of an Application Programming Interface call and storing the security vulnerabilities in a tactics, techniques, and procedures database;

generating a dashboard with the security information thereon, wherein the dashboard tailors the security information based upon a role of a user to provide the security information and wherein the dashboard allows the user to drill down on the security information;

tracking remediation of one or more of the security vulnerabilities;

querying the tactics, techniques, and procedures database to extract data for inclusion in a report, wherein database query constructs are used to extract data based on a type of the security vulnerabilities and a line of business associated with the security vulnerabilities;

generating the report including the security information and the one or more of the security vulnerabilities, wherein dissemination of the report is controlled by document rights management limitations that include location-based and time-based limitations on access; and

managing access to the dashboard and the report by automatically revoking credentials when individuals move to other responsibilities and logging activity associated with access to reports for auditing purposes.

6 . The method of claim 5 , wherein the dashboard includes a list of the one or more of the security vulnerabilities and a heat map of the one or more of the security vulnerabilities.

7 . The method of claim 5 , further comprising limiting an ability of the report to be shared.

8 . The method of claim 5 , further comprising managing a security assessment of an entity.

Assignments (2)
STATEMENT OF CHANGE OF ADDRESS OF ASSIGNEE Recorded Jun 17, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071644/0971 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2024
From: FOULKS, TODD MICHAEL; O’DONNELL, PATRICK KELLY
To: WELLS FARGO BANK, N.A.
Reel/Frame 067030/0809 →
Continuity (2)
Provisional Application 63379088 · Oct 11, 2022
Related Publication 20240121260A1 · Apr 11, 2024
References Cited (8)
US 6185689B1 · Todd, Sr. · 2001 [cited by examiner]
US 20060075503A1 · Bunker · 2006 [cited by examiner]
US 20210344703A1 · Barajas · 2021 [cited by examiner]
US 20210367961A1 · Kuppa · 2021 [cited by examiner]
US 20230319062A1 · Bushey · 2023 [cited by examiner]
PlexTrac, “Automate Your Pentest Planning, Reporting, and Findings Delivery with PlexTrac,” https://plextrac.com/, copyright 2023, 8 pages. [cited by applicant]
The MITRE Corporation, “ATT&CK Matrix for Enterprise,” https://attack.mitre.org/, copyright 2015-2023, 2 pages. [cited by applicant]
IBM, “IBM OpenPages: Simplify how you manage risk and regulatory compliance with a unified GRC platform fueled by AI and all your data,” https://www.ibm.com/products/openpages, accessed Sep. 28, 2023, 13 pages. [cited by applicant]