IP Library › Granted Patent US 11,711,393
Granted Patent B2
US 11,711,393 · App. 17/073,686 · Granted Jul 25, 2023

Methods and systems for managing website access through machine learning

Inventors: Ibrahim Uthman Assiry (Al Khobar, SA); Sultan Saadaldean Alsharif (Al Khobar, SA); John A. Gwilliams (Dhahran Hills, SA); Nada Essa Alnoaimi (Dhahran, SA)
Assignee: SAUDI ARABIAN OIL COMPANY
H04L63/1433G06F18/24155G06N7/01H04L61/4511H04L63/0236H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,711,393
App. No.
17/073,686
Granted
Jul 25, 2023
Kind
B2
Abstract

A method may include obtaining a request to unblock a predetermined website in a network and that is associated with a predetermined list. The predetermined list may be used to determine whether a respective user device among various user devices can access one or more websites. The method may further include determining an impact level of the predetermined website for an organization using a machine-learning algorithm and website gateway data. The method may further include determining a probability of a security breach using the machine-learning algorithm and threat data. The method may further include determining whether to unblock the predetermined website based on the impact level and the probability of a security breach. The method may further include transmitting, in response to determining that the predetermined website should be unblocked, a command that modifies the predetermined list to enable the respective user device to access the predetermined website.

Claims (99)

1. A method, comprising:

obtaining, by a computer processor, a request to unblock a predetermined website in a network and that is associated with a predetermined list, wherein the predetermined list is used to determine whether a respective user device among a plurality of user devices can access one or more websites;

determining a number of user connection attempts to access the predetermined website using end user data, wherein the end user data is obtained from a plurality of end user logs that are located on the plurality of user devices;

determining, by the computer processor, an impact level of the predetermined website for an organization using a machine-learning algorithm and web gateway data,

wherein the impact level is further determined based on the number of user connection attempts;

determining, by the computer processor, a probability of a security breach using the machine-learning algorithm and threat data;

determining, by the computer processor, whether to unblock the predetermined website based on the impact level and the probability of a security breach; and

transmitting, by the computer processor and in response to determining that the predetermined website should be unblocked, a command that modifies the predetermined list to enable at least the respective user device of the plurality of user devices to access the predetermined website.

2. The method of claim 1 ,

wherein the predetermined list is a blacklist stored in a domain name system (DNS) server that manages DNS records for a network, and

wherein the command removes the predetermined website from the blacklist.

3. The method of claim 1 , further comprising:

obtaining, from a threat intelligence server, external threat data regarding one or more security vulnerabilities; and

obtaining, from within the network, internal threat data based on one or more cybersecurity attacks against the network, and

wherein the threat data comprises the external threat data and the internal threat data.

4. The method of claim 1 ,

wherein the web gateway data comprise website reputation data and website category data, and

wherein the web gateway data is obtained from a URL category database located outside the network.

5. The method of claim 1 , further comprising:

obtaining, from a plurality of antivirus engines disposed on the plurality of user devices, antivirus engine data,

wherein the antivirus engine data is used by the machine-learning algorithm to determine the impact level and the probability of the security breach.

6. The method of claim 1 ,

wherein the request is transmitted to a server by a user device among the plurality of user devices,

wherein the computer processor is located on the server, and

wherein the server stores the web gateway data and the threat data.

7. A method, comprising:

obtaining, by a computer processor, a request to unblock a predetermined website in a network and that is associated with a predetermined list, wherein the predetermined list is used to determine whether a respective user device among a plurality of user devices can access one or more websites;

determining, by the computer processor, an impact level of the predetermined website for an organization using a machine-learning algorithm and web gateway data;

determining, by the computer processor, a probability of a security breach using the machine-learning algorithm and threat data;

determining, by the computer processor, whether to unblock the predetermined website based on the impact level and the probability of a security breach; and

transmitting, by the computer processor and in response to determining that the predetermined website should be unblocked, a command that modifies the predetermined list to enable at least the respective user device of the plurality of user devices to access the predetermined website,

wherein the machine-learning algorithm is Naive Bayes algorithm that uses the web gateway data and the threat data as inputs to a learned Naive Bayes model,

wherein the learned Naive Bayes model comprises a plurality of attributes, a plurality of class probabilities, and a plurality of conditional probabilities based on the web gateway data and the threat data, and

wherein the plurality of attributes comprise a cyberattack campaign attribute, a secure website reputation attribute, a secure website category attribute, and a malicious content presence attribute.

8. A server, comprising:

a computer processor; and

a memory coupled to the computer processor, wherein the memory comprises functionality for:

obtaining, from a user device, a request to unblock a predetermined website in a network and that is associated with a predetermined list, wherein the predetermined list is used to determine whether a respective user device among a plurality of user devices can access one or more websites;

determining a number of user connection attempts to access the predetermined website using end user data, wherein the end user data is obtained from a plurality of end user logs that are located on the plurality of user devices;

determining an impact level of the predetermined website for an organization using a machine-learning algorithm and web gateway data,

wherein the impact level is further determined based on the number of user connection attempts;

determining a probability of a security breach using the machine-learning algorithm and threat data;

determining whether to unblock the predetermined website based on the impact level and the probability of a security breach; and

transmitting, in response to determining that the predetermined website should be unblocked, a command that modifies the predetermined list to enable the respective user device of the plurality of user devices to access the predetermined website.

9. The server of claim 8 ,

wherein the predetermined list is a whitelist stored in a web gateway server, and

wherein the command adds the predetermined website to the whitelist.

10. The server of claim 8 , wherein the memory further comprises functionality for:

obtaining, from a threat intelligence server, external threat data regarding one or more security vulnerabilities; and

obtaining, from within the network, internal threat data based on one or more cybersecurity attacks against the network, and

wherein the threat data comprises the external threat data and the internal threat data.

11. The server of claim 8 ,

wherein the web gateway data comprise website reputation data and website category data, and

wherein the web gateway data is obtained from a URL category database located outside the network.

12. The server of claim 8 , wherein the memory further comprises functionality for:

obtaining, from a plurality of antivirus engines disposed on the plurality of user devices, antivirus engine data,

wherein the antivirus engine data is used by the machine-learning algorithm to determine the impact level and the probability of the security breach.

13. A server, comprising:

a computer processor; and

a memory coupled to the computer processor, wherein the memory comprises functionality for:

obtaining, from a user device, a request to unblock a predetermined website in a network and that is associated with a predetermined list, wherein the predetermined list is used to determine whether a respective user device among a plurality of user devices can access one or more websites;

determining an impact level of the predetermined website for an organization using a machine-learning algorithm and web gateway data;

determining a probability of a security breach using the machine-learning algorithm and threat data;

determining whether to unblock the predetermined website based on the impact level and the probability of a security breach; and

transmitting, in response to determining that the predetermined website should be unblocked, a command that modifies the predetermined list to enable the respective user device of the plurality of user devices to access the predetermined website,

wherein the machine-learning algorithm is Naive Bayes algorithm that uses the web gateway data and the threat data as inputs to a learned Naive Bayes model,

wherein the learned Naive Bayes model comprises a plurality of attributes, a plurality of class probabilities, and a plurality of conditional probabilities based on the web gateway data and the threat data, and

wherein the plurality of attributes comprise a cyberattack campaign attribute, a secure website reputation attribute, a secure website category attribute, and a malicious content presence attribute.

14. A system, comprising:

a network comprising a plurality of user devices;

a web gateway comprising a predetermined list and coupled to the plurality of user devices; and

a server coupled to the plurality of user devices and the web gateway, wherein the server comprises a computer processor and is configured to:

obtain a request to unblock a predetermined website in the network and that is associated with a predetermined list, wherein the predetermined list is used by the web gateway to determine whether a respective user device among the plurality of user devices can access one or more websites;

determine a number of user connection attempts to access the predetermined website using end user data, wherein the end user data is obtained from a plurality of end user logs that are located on the plurality of user devices;

determine an impact level of the predetermined website for an organization using a machine-learning algorithm and web gateway data that is obtained from the web gateway,

wherein the impact level is further determined based on the number of user connection attempts;

determine a probability of a security breach using the machine-learning algorithm and threat data;

determine whether to unblock the predetermined website based on the impact level and the probability of a security breach; and

transmit, to the web gateway and in response to determining that the predetermined website should be unblocked, a command that modifies the predetermined list to enable the respective user device of the plurality of user devices to access the predetermined website.

15. The system of claim 14 , further comprising:

a threat intelligence server coupled to the server,

wherein the server obtains external threat data from the threat intelligence server regarding one or more security vulnerabilities; and

wherein the server obtains internal threat data from the network based on one or more cybersecurity attacks against the network, and

wherein the threat data comprises the external threat data and the internal threat data.

16. The system of claim 14 ,

wherein the web gateway data comprise website reputation data and website category data, and

wherein the web gateway data is obtained from a URL category database located outside the network.

17. A system, comprising:

a network comprising a plurality of user devices;

a web gateway comprising a predetermined list and coupled to the plurality of user devices; and

a server coupled to the plurality of user devices and the web gateway, wherein the server comprises a computer processor and is configured to:

obtain a request to unblock a predetermined website in the network and that is associated with a predetermined list, wherein the predetermined list is used by the web gateway to determine whether a respective user device among the plurality of user devices can access one or more websites;

determine an impact level of the predetermined website for an organization using a machine-learning algorithm and web gateway data that is obtained from the web gateway;

determine a probability of a security breach using the machine-learning algorithm and threat data;

determine whether to unblock the predetermined website based on the impact level and the probability of a security breach; and

transmit, to the web gateway and in response to determining that the predetermined website should be unblocked, a command that modifies the predetermined list to enable the respective user device of the plurality of user devices to access the predetermined website,

wherein the machine-learning algorithm is Naive Bayes algorithm that uses the web gateway data and the threat data as inputs to a learned Naive Bayes model,

wherein the learned Naive Bayes model comprises a plurality of attributes, a plurality of class probabilities, and a plurality of conditional probabilities based on the web gateway data and the threat data, and

wherein the plurality of attributes comprise a cyberattack campaign attribute, a secure website reputation attribute, a secure website category attribute, and a malicious content presence attribute.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2021
From: ASSIRY, IBRAHIM UTHMAN; ALSHARIF, SULTAN SAADALDEAN; GWILLIAMS, JOHN A.; ALNOAIMI, NADA ESSA
To: SAUDI ARABIAN OIL COMPANY
Reel/Frame 056935/0417 →
Continuity (1)
Related Publication 20220124114A1 · Apr 21, 2022