IP Library › Granted Patent US 11,899,808
Granted Patent B2
US 11,899,808 · App. 17/961,515 · Granted Feb 13, 2024

Machine learning for identity access management

Inventors: Wyatt O'Neill Cobb (Mission Hills, KS); Zachary Lewis Jovic Misic (Overland Park, KS)
Assignee: SoftWarfare, LLC
G06F21/6218G06F21/554G06N3/04G06N3/084H04L63/0861H04L63/14G06Q50/265
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,899,808
App. No.
17/961,515
Granted
Feb 13, 2024
Kind
B2
Abstract

A computer readable medium, a system, and a method for providing data security through identity access management using a transaction classifier to classify transactions according to a set of transaction data associated with the transaction and mitigate abnormal transactions. The transaction classifier is trained using a set of training data and updated after each transaction. The identity access management may also include a mitigation policy that is used to determine a mitigation technique for each transaction.

Claims (64)

1. A method of updating a mitigation policy of an identity access management system, the method comprising:

receiving transaction data relating to a transaction for an authorized user account;

determining a transaction type of the transaction based on the transaction data;

identifying an abnormality associated with the transaction based on the transaction data using a machine learning model trained with user data;

determining a threat level associated with the transaction based on the transaction data and the transaction type;

responsive to identifying the abnormality, determining a mitigation procedure from the mitigation policy based on the transaction type of the transaction and the threat level associated with the transaction;

applying the mitigation procedure to the transaction based on the transaction type;

storing the transaction data, an indication of the mitigation procedure, and an indication of the threat level associated with the transaction in a transaction data store; and

updating the mitigation policy based on the transaction data and the transaction type of the transaction.

2. The method of claim 1 , wherein the mitigation procedure comprises:

identifying a lockout time period based on the threat level associated with the transaction, the lockout time period indicating a time period for which the authorized user account is locked.

3. The method of claim 1 , wherein the mitigation procedure comprises:

generating a transaction ticket based on the transaction type of the transaction and the threat level associated with the transaction; and

presenting the transaction ticket to an administrator user.

4. The method of claim 1 , wherein the mitigation procedure comprises:

accessing a Common Vulnerabilities and Exposure (CVE) registry including information relating to a plurality of common threats; and

identifying, using the CVE registry, a common threat corresponding to the transaction type of the transaction.

5. The method of claim 1 , wherein the mitigation procedure comprises:

flagging the transaction and the authorized user account based on the transaction type of the transaction and the threat level associated with the transaction.

6. The method of claim 5 , wherein the mitigation procedure further comprises:

performing a multifactor authentication routine of the authorized user account to authenticate the transaction.

7. The method of claim 6 , wherein the multifactor authentication routine comprises a biometric authentication of the authorized user account.

8. An identity access management system comprising:

at least one processor; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the at least one processor, perform a method of updating a mitigation policy of the identity access management system, the method comprising:

receiving transaction data relating to a transaction for a user account;

determining a transaction type of the transaction based on the transaction data;

identifying an abnormality associated with the transaction based on the transaction data using a machine learning model trained with user data;

determining a threat level associated with the transaction based on the transaction data and the transaction type;

responsive to identifying the abnormality, determining a mitigation procedure from the mitigation policy based on the transaction type of the transaction and the threat level associated with the transaction;

applying the mitigation procedure to the transaction based on the transaction type; and

updating the mitigation policy based on the transaction data and the transaction type of the transaction.

9. The identity access management system of claim 8 , the method further comprising:

storing the transaction data, an indication of the mitigation procedure, and an indication of the threat level associated with the transaction in a transaction data store.

10. The identity access management system of claim 9 , wherein the user data used to train the machine learning model comprises historic transaction data.

11. The identity access management system of claim 8 , the method further comprising:

retraining the machine learning model with updated transaction data.

12. The identity access management system of claim 8 , wherein the mitigation procedure comprises:

identifying a lockout time period based on the threat level associated with the transaction, the lockout time period indicating a time period for which the user account is locked.

13. The identity access management system of claim 12 , the method further comprising:

updating the lockout time period based on previous transaction data.

14. The identity access management system of claim 8 , further comprising:

an authentication database comprising authentication data corresponding to a plurality of user accounts;

an identity database comprising identity data corresponding to a plurality of users;

an authorization database comprising authorization data; and

an identity access management database bidirectionally connected to the authentication database, the identity database, and the authorization database.

15. One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by at least processor, perform a method of updating a mitigation policy of an identity access management system, the method comprising:

receiving transaction data relating to a transaction for a user account;

determining a transaction type of the transaction based on the transaction data;

identifying an abnormality associated with the transaction based on the transaction data using a machine learning model trained with user data;

determining a threat level associated with the transaction based on the transaction data and the transaction type;

responsive to identifying the abnormality, determining a mitigation procedure from the mitigation policy based on the transaction type of the transaction and the threat level associated with the transaction;

applying the mitigation procedure to the transaction based on the transaction type;

flagging the transaction and the user account based on the transaction type of the transaction and the threat level associated with the transaction;

storing the transaction data, an indication of the mitigation procedure, and an indication of the threat level associated with the transaction in a transaction data store; and

updating the mitigation policy based on the transaction data and the transaction type of the transaction.

16. The non-transitory computer-readable media of claim 15 , wherein the machine learning model comprises an artificial neural network-based transaction classifier for classifying the transaction as either normal or abnormal based on the transaction data.

17. The non-transitory computer-readable media of claim 15 , wherein the transaction is a login attempt requesting access to the user account.

18. The non-transitory computer-readable media of claim 17 , wherein the mitigation procedure comprises:

preventing access to the user account; and

locking the user account for a predetermined lockout time period based on the threat level associated with the transaction.

19. The non-transitory computer-readable media of claim 15 , wherein the threat level is a high threat level associated with a potentially harmful transaction.

20. The non-transitory computer-readable media of claim 19 , wherein the mitigation procedure comprises:

quarantining the user account for a predetermined quarantine time period.

Assignments (2)
SECURITY INTEREST Recorded Mar 20, 2025
From: SOFTWARFARE, LLC
To: OUTDOOR BANK
Reel/Frame 070583/0259 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2022
From: COBB, WYATT O'NEILL; MISIC, ZACHARY LEWIS JOVIC
To: SOFTWARFARE, LLC
Reel/Frame 061341/0458 →
Continuity (2)
Continuation 16696257 · Nov 26, 2019
Related Publication 20230032660A1 · Feb 2, 2023