IP Library › Patent Application 19425490
Patent Application
App. No. 19/425,490

OPTIMIZING APPLICATION SECURITY BASED ON MALICIOUS USER INTENT

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/425,490
Abstract

An example method identifying a request to access or modify a data resource. The request is made by a user. The example method further includes authenticating the user. Based on authenticating the user, the example method includes determining that the request is associated with a malicious intent based on a characteristic of the user. Further, based on determining that the request is associated with the malicious intent, the example method includes blocking the user from accessing or modifying the data resource.

Claims (60)

1 . A method, comprising:

identifying a request, made by a user, to access or modify a data resource controlled by an organization and associated with an application runtime;

authenticating the user;

subsequent to authenticating the user, determining that the request is an anomalous request based at least in part on the anomalous request including a transaction associated with the application runtime;

subsequent to determining that the request is the anomalous request, determining runtime application self-protection (RASP) data, the RASP data indicating application performance behavior associated with the anomalous request and the application runtime;

determining, based on the application performance behavior indicated by the RASP data, that the anomalous request is associated with a malicious intent; and

based on determining that the anomalous request is associated with the malicious intent, blocking the user from accessing or modifying the data resource.

2 . The method of claim 1 , wherein authenticating the user comprises:

receiving, from a primary device associated with the user, at least one first authentication factor;

receiving, from the primary device or a secondary device associated with the user, at least one second authentication factor; and

determining that the at least one first authentication factor and the at least one second authentication factor match predetermined authentication factors associated with an authorized user.

3 . The method of claim 1 , wherein determining that the anomalous request is associated with the malicious intent comprises:

determining that the anomalous request is anomalous with respect to previous behavior of the user or with respect to behavior of other users sharing a role with the user, and

wherein the previous behavior of the user comprises at least one of the user accessing a previous data resource, the user modifying the previous data resource, a web service call of an application utilized by the user, or a line of code of the application called during utilization by the user.

4 . The method of claim 1 , wherein determining that the anomalous request is associated with the malicious intent further comprises determining that a date at which the user is departing the organization is within a threshold time period.

5 . The method of claim 1 , wherein determining that the anomalous request is associated with the malicious intent further comprises determining that the data resource comprises sensitive data, the sensitive data comprising at least one of confidential information or information with a high business value.

6 . The method of claim 1 , wherein determining that the anomalous request is associated with the malicious intent further comprises determining that a previous transaction of the user triggered a runtime security event.

7 . The method of claim 1 , further comprising:

based on determining that the anomalous request is associated with the malicious intent:

blocking the user from operating an application; or

transmitting, to an administrator device, an alert indicating the user is attempting to modify or access the data resource.

8 . A system, comprising:

at least one processor; and

memory storing instructions that, when executed by the at least one processor, cause the system to perform operations comprising:

identifying a request, made by a user, to access or modify a data resource controlled by an organization and associated with an application runtime;

authenticating the user;

subsequent to authenticating the user, determining that the request is an anomalous request based at least in part on the anomalous request including a transaction associated with the application runtime;

subsequent to determining that the request is the anomalous request, determining runtime application self-protection (RASP) data, the RASP data indicating application performance behavior associated with the anomalous request and the application runtime;

determining, based on the application performance behavior indicated by the RASP data, that the anomalous request is associated with a malicious intent; and

based on determining that the anomalous request is associated with the malicious intent, performing a protective action.

9 . The system of claim 8 , wherein authenticating the user comprises:

receiving, from a primary device associated with the user, at least one first authentication factor;

receiving, from the primary device or a secondary device associated with the user, at least one second authentication factor; and

determining that the at least one first authentication factor and the at least one second authentication factor match predetermined authentication factors associated with an authorized user.

10 . The system of claim 8 , wherein determining that the anomalous request is associated with the malicious intent further comprises:

determining that the anomalous request is anomalous with respect to previous behavior of the user or with respect to behavior of other users sharing a role with the user, and

wherein the previous behavior of the user comprises at least one of the user accessing a previous data resource, the user modifying the previous data resource, a web service call of an application utilized by the user, or a line of code of the application called during utilization by the user.

11 . The system of claim 8 , determining that the anomalous request is associated with the malicious intent further comprises determining that a date at which the user is departing the organization is within a threshold time period.

12 . The system of claim 8 , wherein determining that the anomalous request is associated with the malicious intent is further based at least in part on determining that the data resource comprises sensitive data, and wherein the sensitive data comprises at least one of confidential information or information with a high business value.

13 . The system of claim 8 , wherein determining that the anomalous request is associated with the malicious intent further comprises determining that a previous transaction of the user triggered a runtime security event.

14 . The system of claim 8 , wherein performing the protective action comprises preventing the user from accessing or modifying the data resource.

15 . The system of claim 8 , wherein performing the protective action comprises blocking the user from operating an application.

16 . The system of claim 8 , wherein performing the protective action comprises transmitting, to an administrator device, an alert indicating the user is attempting to modify or access the data resource.

17 . A system, comprising:

at least one processor; and

memory storing instructions that, when executed by the at least one processor, cause the system to perform operations comprising:

receiving, from a user device, a request to access or modify a data resource controlled by an organization and associated with an application runtime;

authenticating a user of the user device, the user being a member of an organization;

subsequent to authenticating the user, determining that the request is an anomalous request based at least in part on the anomalous request including a transaction associated with the application runtime;

subsequent to determining that the request is the anomalous request, determining runtime application self-protection (RASP) data, the RASP data indicating application performance behavior associated with the anomalous request and the application runtime;

determining, based on the application performance behavior indicated by the RASP data, that the anomalous request is associated with a malicious intent; and

based on determining that the anomalous request is associated with the malicious intent, performing at least one protective action.

18 . The system of claim 17 , the user device being a first user device, wherein authenticating the user comprises:

receiving, from the first user device, at least one first authentication factor;

receiving, from the first user device or a second user device associated with the user, at least one second authentication factor; and

determining that the at least one first authentication factor and the at least one second authentication factor match predetermined authentication factors associated with an authorized user.

19 . The system of claim 17 , the user device being a first user device, wherein determining that the anomalous request is associated with a malicious intent further comprises determining that the anomalous request is anomalous with respect to previous behavior associated with second user devices, the second user devices being associated with other members of the organization.

20 . The system of claim 17 , wherein performing the at least one protective action comprises:

preventing the user device from accessing or modifying the data resource; and

transmitting, to an administrator device, an alert indicating at least one of the user, the user device, or the data resource.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2025
From: SZIGETI, THOMAS; ZACKS, DAVID J.; HULICK, WALTER T., JR.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 073263/0493 →