IP Library Granted Patent US 11,799,879
Granted Patent B2
US 11,799,879 · App. 17/323,590 · Granted Oct 24, 2023

Real-time anomaly detection for network security

Inventors: Shailendra Singh (Thane West, IN); Satyajeet Priyadarshi (Pune, IN)
Assignee: Bank of America Corporation
H04L63/1416G06N20/00H04L63/1441H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,799,879
App. No.
17/323,590
Granted
Oct 24, 2023
Kind
B2
Abstract

A device configured to obtain group information from a database, to identify a first set of clusters based on the group information, and to determine a first cluster quantity that identifies a number of clusters within the first set of clusters. The device is further configured to obtain user interaction data for user devices, to input the user interaction data into a machine learning model, to receive a second set of clusters from the machine learning model based on the user interaction data, and to determine a second cluster quantity that identifies a number of clusters within the second set of clusters. The device is further configured to determine the second cluster quantity is greater than the first cluster quantity, to identify a cluster that is not present in the first set of clusters, and to modify settings on a user device from within the cluster.

Claims (96)

1. A network security system, comprising:

a plurality of user devices, wherein:

each user device is associated with a user; and

each user device is configured to output user interaction data, wherein the user interaction data identifies activities performed by a user that is associated with a user device;

a database configured to store group information that is associated with the plurality of user devices, wherein:

the group information identifies a plurality of work groups; and

each work group comprises one or more user devices from among the plurality of user devices; and

a processor in signal communication with the plurality of user devices and the database, and configured to:

obtain the group information from the database;

identify a first set of clusters based on the group information, wherein each cluster corresponds with a work group from among the plurality of workgroups;

determine a first cluster quantity that identifies a number of clusters within the first set of clusters;

obtain user interaction data for the plurality of user devices;

input the user interaction data into a machine learning model, wherein the machine learning model is configured to:

receive the user interaction data; and

output a second set of clusters for the plurality of user devices based on the user interaction data;

determine a second cluster quantity that identifies a number of clusters within the second set of clusters;

compare the first cluster quantity to the second cluster quantity;

determine the second cluster quantity is greater than the first cluster quantity;

identify a first cluster from the second set of clusters that is not present in the first set of clusters;

identify a first user device within the first cluster; and

modify one or more device settings on the first user device.

2. The system of claim 1 , wherein modifying the one or more settings on the first user device comprises:

identifying a second user device within the first cluster; and

enabling communications between the first user device and the second user device.

3. The system of claim 1 , wherein modifying the one or more settings on the first user device comprises:

identifying a second user device within the first cluster; and

restricting communications between the first user device and the second user device.

4. The system of claim 1 , wherein:

the user interaction data identifies an application that was accessed using the first user device; and

modifying the one or more settings on the first user device comprises restricting access to the application.

5. The system of claim 1 , wherein:

the user interaction data identifies a website that was accessed using the first user device; and

modifying the one or more settings on the first user device comprises restricting access to the website.

6. The system of claim 1 , wherein:

the user interaction data identifies a physical location that was accessed by a user associated with the first user device; and

modifying the one or more settings on the first user device comprises restricting access to the physical location for the user.

7. The system of claim 1 , wherein the processor is further configured to monitor communications sent by the first user device after identifying the first user device.

8. The system of claim 1 , wherein modifying the one or more settings on the first user device comprises modifying network settings on the first user device.

9. The system of claim 1 , wherein the user interaction data comprises information associated with incoming and outgoing communications for each user device.

10. An anomaly detection method, comprising:

obtaining group information from a database, wherein:

the group information identifies a plurality of work groups; and

each work group comprises one or more user devices from among a plurality of user devices;

identifying a first set of clusters based on the group information, wherein each cluster corresponds with a work group from among the plurality of workgroups;

determining a first cluster quantity that identifies a number of clusters within the first set of clusters;

obtaining user interaction data for the plurality of user devices, wherein the user interaction data identifies activities performed by a user that is associated with a user device;

inputting the user interaction data into a machine learning model;

receiving a second set of clusters for the plurality of user devices from the machine learning model based on the user interaction data;

determining a second cluster quantity that identifies a number of clusters within the second set of clusters;

comparing the first cluster quantity to the second cluster quantity;

determining the second cluster quantity is greater than the first cluster quantity;

identifying a first cluster from the second set of clusters that is not present in the first set of clusters;

identifying a first user device within the first cluster; and

modifying one or more device settings on the first user device.

11. The method of claim 10 , wherein modifying the one or more settings on the first user device comprises:

identifying a second user device within the first cluster; and

enabling communications between the first user device and the second user device.

12. The method of claim 10 , wherein modifying the one or more settings on the first user device comprises:

identifying a second user device within the first cluster; and

restricting communications between the first user device and the second user device.

13. The method of claim 10 , wherein:

the user interaction data identifies an application that was accessed using the first user device; and

modifying the one or more settings on the first user device comprises restricting access to the application.

14. The method of claim 10 , wherein:

the user interaction data identifies a website that was accessed using the first user device; and

modifying the one or more settings on the first user device comprises restricting access to the website.

15. The method of claim 10 , wherein:

the user interaction data identifies a physical location that was accessed by a user associated with the first user device; and

modifying the one or more settings on the first user device comprises restricting access to the physical location for the user.

16. The method of claim 10 , further comprising monitoring communications sent by the first user device after identifying the first user device.

17. The method of claim 10 , wherein modifying the one or more settings on the first user device comprises modifying network settings on the first user device.

18. The method of claim 10 , wherein the user interaction data comprises information associated with incoming and outgoing communications for each user device.

19. A network security system, comprising:

a plurality of user devices, wherein:

each user device is associated with a user; and

each user device is configured to output user interaction data, wherein the user interaction data identifies activities performed by a user that is associated with a user device;

a network security monitoring device in signal communication with the plurality of user devices, and comprising:

a memory operable to store group information that is associated with the plurality of user devices, wherein:

the group information identifies a plurality of work groups; and

each work group comprises one or more user devices from among the plurality of user devices; and

a processor operably coupled to the memory, and configured to:

identify a first set of clusters based on the group information, wherein each cluster corresponds with a work group from among the plurality of workgroups;

determine a first cluster quantity that identifies a number of clusters within the first set of clusters;

obtain user interaction data for the plurality of user devices;

input the user interaction data into a machine learning model, wherein the machine learning model is configured to:

receive the user interaction data; and

output a second set of clusters for the plurality of user devices based on the user interaction data;

determine a second cluster quantity that identifies a number of clusters within the second set of clusters;

compare the first cluster quantity to the second cluster quantity;

determine the second cluster quantity is greater than the first cluster quantity;

identify a first cluster from the second set of clusters that is not present in the first set of clusters;

identify a first user device within the first cluster; and

modify one or more device settings on the first user device.

20. The system of claim 19 , wherein modifying the one or more settings on the first user device comprises:

identifying a second user device within the first cluster; and

restricting communications between the first user device and the second user device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: SINGH, SHAILENDRA; PRIYADARSHI, SATYAJEET
To: BANK OF AMERICA CORPORATION
Reel/Frame 056277/0248 →
Continuity (1)
Related Publication 20220377085A1 · Nov 24, 2022
Cited By (1)
US 12,556,539