IP Library Patent Application 18756854
Patent Application
App. No. 18/756,854

DETECTING SECURITY THREATS FROM LOGON DATA

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/756,854
Abstract

This disclosure describes techniques for analyzing network traffic to generate an actionable insight pertaining to a security threat to a network. In one example, this disclosure describes a method that includes obtaining, by a computing system, historical network activity data that includes information about authentication traffic within a network; determining, by the computing system and based on the historical network activity, a baseline of network activity; collecting, by the computing system, a set of network activity data; applying, by the computing system, an unsupervised algorithm to identify the set of network activity data as anomalous relative to the baseline of network activity; classifying, by the computing system, the network activity data into an identified threat category from among a plurality of threat categories; and taking action, by the computing system and based on the identified threat category, to mitigate a security threat posed by the network activity data.

Claims (74)

1 . A method comprising:

obtaining, by a computing system, historical network activity data that includes information about authentication traffic within a network;

determining, by the computing system and based on the historical network activity, a baseline of network activity;

collecting, by the computing system, a set of network activity data;

applying, by the computing system, an unsupervised algorithm to identify the set of network activity data as anomalous relative to the baseline of network activity;

classifying, by the computing system, the network activity data into an identified threat category from among a plurality of threat categories; and

taking action, by the computing system and based on the identified threat category, to mitigate a security threat posed by the network activity data.

2 . The method of claim 1 , wherein classifying the network activity data into the identified threat category includes:

enabling a subject matter expert to create rules for each of the plurality of threat categories; and

applying the rules to classify the network activity data into the identified threat category.

3 . The method of claim 2 , wherein the set of network activity data is a first set of network activity data, and wherein the method further comprises:

collecting, by the computing system, a second set of network activity data;

applying, by the computing system, the unsupervised algorithm to identify the second set of network activity data as anomalous relative to the baseline of network activity;

determining, by the computing system, that the second set of network activity data is not classifiable into any of the plurality of threat categories; and

taking action, by the computing system and based on identifying the second set of recent network activity data as anomalous, to mitigate a security threat posed by the second set of network activity data.

4 . The method of claim 3 , wherein determining that the second set of network activity data is not classifiable into any of the plurality of threat categories includes:

applying the rules to the second set of network activity data; and

determining that applying the rules does not classify the second set of network activity data into any of the plurality of threat categories.

5 . The method of claim 2 , wherein enabling the subject matter expert to create rules includes:

receiving an indication of input from a subject matter expert computing system operated by the subject matter expert; and

creating, based on the indication of input, tagging rules for each of the plurality of threat categories.

6 . The method of claim 1 , wherein the unsupervised algorithm is an unsupervised machine learning model, and wherein the method further comprises:

training, by the computing system, the unsupervised machine learning model using the historical network activity data.

7 . The method of claim 1 , wherein classifying the network activity data into the identified threat category includes:

labeling at least some of the historical network activity data with one or more of the plurality of threat categories;

training a supervised machine learning model to classify network activity data into at least one of the plurality of threat categories; and

applying the supervised machine learning model to the network activity data to classify the network activity data into the identified threat category.

8 . The method of claim 1 , wherein determining the baseline of network activity includes:

identifying normal logon behavior of each of a plurality of network users; and

identifying normal logon behavior of each of a plurality of types of network users.

9 . The method of claim 8 , wherein determining the baseline of network activity further includes:

identifying attributes of login behavior of each of the plurality of network users relative to other users.

10 . The method of claim 9 , wherein at least some aspects of the network are controlled by an organization, and wherein determining the baseline of network activity further includes:

identifying contextual information associated with the organization;

determining the baseline of network activity by taking into account the contextual information associated with the organization.

11 . The method of claim 1 , wherein taking action includes:

sending control signals to a controlled system instructing the controlled system to modify configurations of the network to mitigate the security threat.

12 . A computing system comprising processing circuitry and a storage device, wherein the processing circuitry has access to the storage device and is configured to:

obtain historical network activity data that includes information about authentication traffic within a network;

determine based on the historical network activity, a baseline of network activity;

collect a set of network activity data;

apply an unsupervised algorithm to identify the set of network activity data as anomalous relative to the baseline of network activity;

classify the network activity data into an identified threat category from among a plurality of threat categories; and

take action, based on the identified threat category, to mitigate a security threat posed by the network activity data.

13 . The computing system of claim 12 , wherein to classify the network activity data into the identified threat category includes:

enable a subject matter expert to create rules for each of the plurality of threat categories; and

apply the rules to classify the network activity data into the identified threat category.

14 . The computing system of claim 13 , wherein the set of network activity data is a first set of network activity data, and wherein the processing circuitry is further configured to:

collect a second set of network activity data;

apply the unsupervised algorithm to identify the second set of network activity data as anomalous relative to the baseline of network activity;

determine that the second set of network activity data is not classifiable into any of the plurality of threat categories; and

take action, based on identifying the second set of recent network activity data as anomalous, to mitigate a security threat posed by the second set of network activity data.

15 . The computing system of claim 14 , wherein to determine that the second set of network activity data is not classifiable into any of the plurality of threat categories includes:

apply the rules to the second set of network activity data; and

determine that applying the rules does not classify the second set of network activity data into any of the plurality of threat categories.

16 . The computing system of claim 13 , wherein to enable the subject matter expert to create rules includes:

receive an indication of input from a subject matter expert computing system operated by the subject matter expert; and

create, based on the indication of input, tagging rules for each of the plurality of threat categories.

17 . The computing system of claim 12 , wherein the unsupervised algorithm is an unsupervised machine learning model, and wherein the processing circuitry is further configured to:

train the unsupervised machine learning model using the historical network activity data.

18 . The computing system of claim 12 , wherein to classify the network activity data into the identified threat category includes:

label at least some of the historical network activity data with one or more of the plurality of threat categories;

train a supervised machine learning model to classify network activity data into at least one of the plurality of threat categories; and

apply the supervised machine learning model to the network activity data to classify the network activity data into the identified threat category.

19 . The computing system of claim 12 , wherein to determine the baseline of network activity includes:

identify normal logon behavior of each of a plurality of network users; and

identify normal logon behavior of each of a plurality of types of network users.

20 . Non-transitory computer-readable media configured with instructions that, when executed, cause one or more processors to:

obtain historical network activity data that includes information about authentication traffic within a network;

determine, based on the historical network activity, a baseline of network activity;

collect a set of network activity data;

apply an unsupervised algorithm to identify the set of network activity data as anomalous relative to the baseline of network activity;

classify the network activity data into an identified threat category from among a plurality of threat categories; and

take action, based on the identified threat category, to mitigate a security threat posed by the network activity data.

Assignments (2)
REQUEST FOR ADDRESS CHANGE Recorded Dec 5, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 073896/0195 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 6, 2024
From: LAKKARAJU, SAIBALA; CHAVA, SRINIVAS; WETCH, KRISTINE; GHANTASALA, NAGA LAKSHMI SUBHA PAVAN KUMAR; VAN BERG, MOSHE ADAM; DANG, ELVIS; KADIYALA, VAMSI; KATAKAM, SATISH RAJ
To: WELLS FARGO BANK, N.A.
Reel/Frame 068199/0207 →