IP Library › Granted Patent US 11,777,992
Granted Patent B1
US 11,777,992 · App. 17/129,767 · Granted Oct 3, 2023

Security model utilizing multi-channel data

Inventors: Shane Cross (Matthews, NC); Daniel Fricano (San Francisco, CA); Thomas Gilheany (San Francisco, CA); Peter Anatole Makohon (San Francisco, CA); Dale Miller (San Francisco, CA); Charles Steven Edison (San Francisco, CA); Kodzo Wegba (San Francisco, CA); James Bonk (San Francisco, CA)
Assignee: Wells Fargo Bank, N.A.
H04L63/20G06F16/128G06F16/2379H04L43/0811H04L61/4511H04L61/5007H04L63/0876H04L63/1433H04L2101/37H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,777,992
App. No.
17/129,767
Filed
Dec 21, 2020
Granted
Oct 3, 2023
Kind
B1
Examiner
SU, SARAH
Art Unit
2431
USPC
726/5
Abstract

Systems, methods and computer-readable storage media are utilized dynamically discovering components of a computer network environment. The processing circuit of a data acquisition engine configured determine a domain name associated with an entity profile, determine an IP range, validate at the domain name, the IP range, and the IP address, collect additional device connectivity data, and provide the additional device connectively data.

Claims (60)

1. A method of dynamically discovering new components of a computer network environment, the method comprising:

determining, by a processing circuit of a data acquisition engine, a domain name associated with an entity profile, the entity profile comprising previously stored device connectivity data for an entity, the device connectivity data comprising the domain name;

determining, by the processing circuit, internet protocol (IP) address data based on the domain name;

determining, by the processing circuit, an IP range based on the IP address data, wherein the IP range comprises an IP address and indicates an internet service provider (ISP) of the IP range;

validating, by the processing circuit, the domain name, the IP range, and the IP address, comprising determining whether the IP address is included in the previously stored device connectivity data;

collecting, by the processing circuit, additional device connectivity data associated with the IP address; and

providing, by the processing circuit, the additional device connectivity data to a security model.

2. The method of claim 1 , further comprising:

analyzing, by the processing circuit, the IP address to identify port data and vulnerability data.

3. The method of claim 2 , further comprising:

generating, by the processing circuit, a cyber hygiene score based on historical data of the entity profile, wherein the historical data comprises previously collected vulnerability data and remediation data.

4. The method of claim 2 , wherein identifying vulnerability data comprises cross-referencing the vulnerability data with a plurality of security parameters, and wherein the vulnerability data comprises subsets of vulnerability data associated with the IP address.

5. The method of claim 2 , wherein the port data comprises at least one port number and a target computer network environment associated with the entity profile, wherein each port number comprises a designation of an open state or a closed state.

6. The method of claim 2 , wherein the at least one of the port data or the vulnerability data comprises virus data, threat data, and source data.

7. The method of claim 2 , wherein a plurality of cybersecurity scores is generated utilizing at least the port data and the vulnerability data.

8. The method of claim 2 , further comprising:

updating, by the processing circuits, a database table associated with an entity dataset and to comprise the port data, the vulnerability data, and a first time stamp associated with both the port data and the vulnerability data, wherein the first time stamp comprises a first moment in time and a first expiration time.

9. The method of claim 8 , further comprising:

determining, by the processing circuits, the first expiration time of the first time stamp is lapsed;

analyzing, by the processing circuits, a domain name system zone of the domain name to identify updated IP address data and updated subdomain data;

determining, by the processing circuits, an updated IP range based on the updated IP address data, wherein the IP range comprises an updated IP address;

analyzing, by the processing circuits, the IP address to identify updated port data and updated vulnerability data;

updating, by the processing circuits, the database table to comprise the updated port data, the updated vulnerability data, and a second time stamp associated with both the updated port data and the updated vulnerability data, wherein the second time stamp comprises a second moment in time and a second expiration time; and

providing, by the processing circuits, the updated port data and the updated vulnerability data to the security model.

10. The method of claim 9 , further comprising:

storing, by the processing circuits, a first entity snapshot in the entity dataset, the first entity snapshot comprising the port data, the vulnerability data, and the first time stamp;

storing, by the processing circuits, a second entity snapshot into the entity dataset comprising the updated port data, the updated vulnerability data, and the second time stamp;

receiving, by the processing circuits, a request for entity snapshots associated with a period of time;

analyzing, by the processing circuits, the entity dataset to determine which time stamps of the plurality of entity snapshots occur within the period of time; and

providing, by the processing circuits, the entity snapshots that occur within the period of time.

11. The method of claim 1 , further comprising:

determining, by the processing circuits, the IP address data and subdomain data is consistent with previously collected IP address data and previously collected subdomain data based on cross-referencing the IP address data and subdomain data with the previously collected IP address data and the previously collected subdomain data.

12. The method of claim 11 , wherein matching the ISP of the IP range to the particular domain further comprises validating the particular domain of the plurality of domains utilizing at least one of a reverse lookup comparison, an IP address data comparison, an ISP comparison, an ISP to ISP comparison.

13. The method of claim 1 , further comprising:

matching, by the processing circuits, the ISP of the IP range to a particular domain of a plurality of domains; and

determining, by the processing circuits, a magnitude of association between the ISP and the domain name associated with the entity profile, wherein a strong magnitude of association or a weak magnitude of association is based on a relationship between the ISP and the domain name associated with the entity profile.

14. The method of claim 1 , wherein the entity profile comprises an entity dataset and is associated with a plurality of cybersecurity scores and a multi-dimensional score.

15. The method of claim 1 , wherein determining the domain name comprises parsing out the domain name from an email address identifier.

16. A system comprising:

a processing circuit configured to:

determine a domain name associated with an entity profile, the entity profile comprising previously stored device connectivity data for an entity, the device connectivity data comprising the domain name;

determine internet protocol (IP) address data based on the domain name;

determine an IP range based on the IP address data, wherein the IP range comprises an IP address and indicates an internet service provider (ISP) of the IP range;

validate at least one of the domain name, the IP range, and the IP address, comprising determining whether the IP address is included in the previously stored device connectivity data;

collect additional device connectivity data associated with the IP address; and

provide the additional device connectivity data to a security model.

17. The system of claim 16 , wherein the processing circuit is further configured to:

analyze the IP address to identify port data and vulnerability data.

18. The system of claim 17 , wherein the processing circuit is further configured to:

update a database table associated with an entity dataset and to comprise the port data, the vulnerability data, and a first time stamp associated with both the port data and the vulnerability data, wherein the first time stamp comprises a first moment in time and a first expiration time.

19. The system of claim 17 , wherein the processing circuit is further configured to:

match the ISP of the IP range to a particular domain of a plurality of domains; and

determine a magnitude of association between the ISP and the domain name associated with the entity profile, wherein a strong magnitude of association or a weak magnitude of association is based on a relationship between the ISP and the domain name associated with the entity profile.

20. One or more non-transitory computer-readable storage media having instructions stored thereon that, when executed by a processing circuit, cause the processing circuit to:

determine a domain name associated with an entity profile, the entity profile comprising previously stored device connectivity data for an entity, the device connectivity data comprising the domain name;

determine internet protocol (IP) address data based on the domain name;

determine an IP range based on the IP address data, wherein the IP range comprises an IP address and indicates an internet service provider (ISP) of the IP range;

validate at least one of the domain name, the IP range, and the IP address, comprising determining whether the IP address is included in the previously stored device connectivity data;

collect additional device connectivity data associated with the IP address; and

provide the additional device connectivity data to a security model.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2023
From: CROSS, SHANE; FRICANO, DANIEL; GILHEANY, THOMAS; MAKOHON, PETER ANATOLE; MILLER, DALE; EDISON, CHARLES STEVEN; WEGBA, KODZO; BONK, JAMES
To: WELLS FARGO BANK, N.A.
Reel/Frame 063796/0108 →
Continuity (2)
Continuation In Part 17081275 · Oct 27, 2020
Provisional Application 63007045 · Apr 8, 2020
Cited By (37)
US 12,189,787 US 12,206,688 US 12,212,543 US 12,229,275 US 12,231,460 US 12,236,491 US 12,244,703 US 12,299,133 US 12,316,665 US 12,328,324 US 12,333,612 US 12,335,282 US 12,341,816 US 12,363,156 US 12,368,718 US 12,373,572 US 12,380,218 US 12,395,505 US 12,432,244 US 12,452,257 US 12,452,290 US 12,489,746 US 12,493,695 US 12,513,167 US 12,531,854 US 12,568,138 US 12,579,229 US 12,592,938 US 12,609,940 US 12,676,879 US 12,683,980 US 12,688,305 US 12,694,104 US 12,719,914 US 12,732,507 US 12,739,107 US 12,750,351