IP Library › Granted Patent US 12,483,587
Granted Patent B2
US 12,483,587 · App. 18/604,262 · Granted Nov 25, 2025

Automated vulnerability exception process

Inventors: Mohamed Seck (Aubrey, TX); Sesha Sowmya Nadiminti (Glen Allen, VA); Krystan R. Franzen (Mechanicsville, VA); Grant Michael Iwan (Montpelier, VA); Shannon Reid (Richmond, VA)
Assignee: Capital One Services, LLC
H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,483,587
App. No.
18/604,262
Filed
Mar 13, 2024
Granted
Nov 25, 2025
Kind
B2
Examiner
SU, SARAH
Art Unit
2431
USPC
726/25
Abstract

In some implementations, an exception system may receive an indication of a security vulnerability associated with a cloud environment. The exception system may provide a data structure that represents the security vulnerability to a machine learning model in order to receive a suggested exception justification. The exception system may output, to a user device associated with a user assigned to the security vulnerability, a draft exception request that includes the suggested exception justification. The exception system may receive, from the user device, a request to submit an exception request based on the draft exception request. The exception system may transmit a command to tag the security vulnerability as excepted.

Claims (57)

1 . A system for automating a vulnerability exception process, the system comprising:

one or more memories; and

one or more processors, communicatively coupled to the one or more memories, configured to:

receive an indication of a security vulnerability associated with a cloud environment;

provide a data structure, representing the security vulnerability, to a machine learning model in order to receive a suggested exception justification;

output a draft exception request, including the suggested exception justification, to a user associated with the security vulnerability;

receive a request to submit an exception request based on the draft exception request;

receive, from the machine learning model, a list of repeat offenders;

output the exception request, with the list of repeat offenders, to an administrator associated with the security vulnerability;

receive an approval of the exception request; and

transmit a command, in response to the approval, to tag the security vulnerability as excepted.

2 . The system of claim 1 , wherein the one or more processors, to receive the indication of the security vulnerability, are configured to:

receive, from a tracking system, a ticket including the indication of the security vulnerability associated with the cloud environment.

3 . The system of claim 1 , wherein the one or more processors, to receive the indication of the security vulnerability, are configured to:

receive, from the cloud environment, the indication of the security vulnerability.

4 . The system of claim 1 , wherein the one or more processors are configured to:

receive, from a communication system, an identifier associated with the security vulnerability,

wherein the draft exception request is output via the communication system.

5 . The system of claim 1 , wherein the one or more processors, to output the exception request, are configured to:

output the exception request via a communication system.

6 . The system of claim 5 , wherein the one or more processors, to receive the approval, are configured to:

receive the approval via the communication system.

7 . The system of claim 1 , wherein the exception request is further output with a risk score associated with excepting the security vulnerability or at least one indication of at least one related security vulnerability.

8 . A method of automating a vulnerability exception process, comprising:

receiving, at an exception system, an indication of a security vulnerability associated with a cloud environment;

providing, by the exception system, a data structure that represents the security vulnerability to a machine learning model in order to receive a suggested exception justification;

outputting, to a user device associated with a user assigned to the security vulnerability, a draft exception request that includes the suggested exception justification;

receiving, from the user device and at the exception system, a request to submit an exception request based on the draft exception request; and

transmitting, by the exception system, a command to tag the security vulnerability as excepted.

9 . The method of claim 8 , further comprising:

outputting, to an administrator device associated with an administrator assigned to the security vulnerability, the exception request; and

receiving, from the administrator device and at the exception system, an approval of the exception request,

wherein the command is transmitted in response to the approval.

10 . The method of claim 9 , wherein the exception request is output in an email message.

11 . The method of claim 8 , wherein the exception request is output in a chat message.

12 . The method of claim 8 , wherein the draft exception request further includes a suggested expiry date received from the machine learning model.

13 . The method of claim 8 , further comprising:

receiving, from a vulnerability database, additional information associated with the security vulnerability,

wherein the additional information is further provided to the machine learning model.

14 . The method of claim 8 , further comprising:

receiving, from a communication system, an identifier associated with the security vulnerability,

wherein the draft exception request is output via the communication system.

15 . A non-transitory computer-readable medium storing a set of instructions for user interfaces (UIs) for a vulnerability exception process, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

receive instructions for a UI including:

an exception request, indicating at least one requestor and a justification, associated with a security vulnerability;

a list of repeat offenders;

a risk score associated with excepting the security vulnerability; and

at least one indication of at least one related security vulnerability;

receive an indication of an interaction with the UI; and

transmit a command to except the security vulnerability in response to the interaction.

16 . The non-transitory computer-readable medium of claim 15 , wherein the risk score includes an initial score associated with the security vulnerability and an updated score associated with excepting the security vulnerability.

17 . The non-transitory computer-readable medium of claim 15 , wherein the UI further includes a severity level associated with the security vulnerability.

18 . The non-transitory computer-readable medium of claim 15 , wherein the UI further includes a recommendation regarding whether to except the security vulnerability.

19 . The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions, when executed by the one or more processors, cause the device to:

output the UI within a larger UI associated with a communication application.

20 . The non-transitory computer-readable medium of claim 15 , wherein the UI includes a button, and the interaction is with the button.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2024
From: SECK, MOHAMED; NADIMINTI, SESHA SOWMYA; FRANZEN, KRYSTAN R.; IWAN, GRANT MICHAEL; REID, SHANNON
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 066774/0567 →
Continuity (1)
Related Publication 20250294046A1 · Sep 18, 2025
References Cited (18)
US 10708292B2 · Gerrick · 2020 [cited by examiner]
US 11509677B2 · Yadav · 2022 [cited by examiner]
US 12368745B1 · Guo · 2025 [cited by examiner]
US 20190245881A1 · Ward · 2019 [cited by examiner]
US 20200236129A1 · Barkovic · 2020 [cited by examiner]
US 20200372154A1 · Bacher · 2020 [cited by examiner]
US 20230308472A1 · Boyer · 2023 [cited by examiner]
US 20240073234A1 · Hulick, Jr. · 2024 [cited by examiner]
US 20240414190A1 · Lal · 2024 [cited by examiner]
CN 107204869B · 2020 [cited by examiner]
CN 113923037A · 2022 [cited by examiner]
CN 115130111A · 2022 [cited by examiner]
CN 116112259A · 2023 [cited by examiner]
CN 118054939A · 2024 [cited by examiner]
CN 119011244A · 2024 [cited by examiner]
CN 119420559A · 2025 [cited by examiner]
JP 2005135239A · 2005 [cited by examiner]
WO WO2022096574A1 · 2022 [cited by examiner]