IP Library › Granted Patent US 12,250,241
Granted Patent B2
US 12,250,241 · App. 17/886,832 · Granted Mar 11, 2025

Electronic system for dynamic adapted security analysis of network resource components

Inventor: Pierre Jacques Bouchard (Davidson, NC)
Assignee: BANK OF AMERICA CORPORATION
H04L63/1433H04L63/0281
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,250,241
App. No.
17/886,832
Granted
Mar 11, 2025
Kind
B2
Abstract

Embodiments of the present invention relate to apparatuses, systems, methods and computer program products for dynamic adapted security analysis of network resource components. Specifically, the system is typically structured for providing proactive network security by dynamically analyzing entering network resource components for vulnerabilities, establishing adapted validation thresholds and mitigation actions, and preventing unsuccessfully validated network resource components in a distributed network. In some aspects, in response to determining that a file attribute data element of the first network program resource component is of a predetermined file type, the system blocks the incoming file transfer associated with the first network program resource component. The system subsequently initiates, via a network quarantine component, dynamic validation of the first network program resource component based on at least one or more categorical network program resource component records associated with the dynamic validated network resource library.

Claims (85)

1. A system for dynamic adapted security analysis of network resource components, wherein the system is structured for providing proactive network security by dynamically analyzing entering network resource components for vulnerabilities, establishing adapted validation thresholds and mitigation actions, and preventing unsuccessfully validated network resource components in a distributed network, the system comprising:

at least one memory device with computer-readable program code stored thereon;

at least one communication device;

at least one processing device operatively coupled to the at least one memory device and the at least one communication device, wherein executing the computer-readable code is configured to cause the at least one processing device to:

detect, via a network proxy component, an incoming file transfer associated with a first network program resource component at a first distributed network initiated by a first user at first network device of the first distributed network;

in response to determining, via the network proxy component, that a file attribute data element associated with the first network program resource component is associated with a predetermined file type, (i) block the incoming file transfer associated with the first network program resource component at the first distributed network, and (ii) automatically redirect a current interface displayed at the first network device to a dynamic validated network resource library interface associated with a dynamic validated network resource library, wherein the file attribute data element is associated with a file name of the first network program resource component;

receive, via the dynamic validated network resource library interface, a request for the first network program resource component from the first user via the first network device;

download the first network program resource component to a network quarantine component associated with the first distributed network;

initiate, via the network quarantine component, dynamic validation of the first network program resource component based on at least one or more categorical network program resource component records associated with the dynamic validated network resource library;

in response to a successful validation of the first network program resource component, construct a transmission of the downloaded first network program resource component to the first network device such that the first network program resource component cannot be executed at the first network device when the dynamic validated network resource library does not comprise the first network program resource component; and

initiate the transmission of the downloaded first network program resource component to the first network device.

2. The system of claim 1 , wherein executing the computer-readable code is configured to cause the at least one processing device to:

construct a retrieval rule associated with the first network program resource component based on determining one or more data fields associated with the network program resource component;

retrieve one or more first categorical network program resource component records of a plurality of categorical network program resource component records based on the retrieval rule from the dynamic validated network resource library;

parse the one or more first categorical network program resource component records to determine whether the one or more first categorical network program resource component records match the first network program resource component; and

in response to determining that the one or more first categorical network program resource component records match the first network program resource component, allow installation of the first network program resource component at the first network device.

3. The system of claim 1 , wherein executing the computer-readable code is configured to cause the at least one processing device to:

construct a retrieval rule associated with the first network program resource component based on determining one or more data fields associated with the network program resource component;

retrieve one or more first categorical network program resource component records of a plurality of categorical network program resource component records based on the retrieval rule from the dynamic validated network resource library;

parse the one or more first categorical network program resource component records to determine whether the one or more first categorical network program resource component records match the first network program resource component; and

in response to determining that the one or more first categorical network program resource component records do not match the first network program resource component, prevent installation of the first network program resource component at the first network device.

4. The system of claim 1 , wherein the dynamic validation of the first network program resource component further comprises:

determining whether a version associated with the first network program resource component is associated with a critical security vulnerability record; and

determining an unsuccessful validation of the first network program resource component in response to determining that the version of the first network program resource component is associated with the critical security vulnerability record.

5. The system of claim 1 , wherein the dynamic validation of the first network program resource component further comprises:

determining whether a version associated with the first network program resource component is associated with one or more critical security vulnerability records;

determining a successful validation of the first network program resource component at a first time interval, in response to determining that the version of the first network program resource component is not associated with the one or more critical security vulnerability records;

initiating an update of the one or more critical security vulnerability records; and

determining, dynamically, an unsuccessful validation of the first network program resource component at a second time interval succeeding the first time interval, in response to determining that the version of the first network program resource component is associated with the updated one or more critical security vulnerability records.

6. The system of claim 1 , wherein the dynamic validation of the first network program resource component further comprises:

determining whether a scan of a version associated with the first network program resource component is successful; and

determining an unsuccessful validation of the first network program resource component in response to determining that the scan of the version of the first network program resource component is unsuccessful.

7. The system of claim 1 , wherein the dynamic validation of the first network program resource component further comprises:

determining whether a source entity associated with the first network program resource component is associated with the one or more categorical network program resource component records of the dynamic validated network resource library; and

determining an unsuccessful validation of the first network program resource component in response to determining that the source entity of the first network program resource component does not match the one or more categorical network program resource component records of the dynamic validated network resource library.

8. The system of claim 1 , wherein the dynamic validation of the first network program resource component further comprises:

determining whether a version of the first network program resource component is associated with a component file; and

determining an unsuccessful validation of the first network program resource component in response to determining that the version of the first network program resource component does not match the component file.

9. The system of claim 1 , wherein determining that the file attribute data element associated with the first network program resource component is associated with the predetermined file type comprises determining that the first network program resource component is an executable type file.

10. The system of claim 1 , wherein executing the computer-readable code is configured to cause the at least one processing device to:

determine whether the first user is associated with a download permission at the first network device;

determine whether the first user is associated with an install permission at the first network device; and

in response to determining that the first user is associated with the download permission and the install permission at the first network device, revoke the download permission or the install permission of the first user at the first network device.

11. The system of claim 1 , wherein executing the computer-readable code is configured to cause the at least one processing device to:

in response to determining, via the network proxy component, that a file attribute data element associated with a second network program resource component is associated with the predetermined file type, block the incoming file transfer associated with the second network program resource component at the first distributed network;

in response to a request for the second network program resource component from a second network device, download the second network program resource component to the network quarantine component associated with the first distributed network; and

in response to an unsuccessful validation of the first network program resource component, prevent transmission of the second network program resource into the first distributed network.

12. A computer program product for dynamic adapted security analysis of network resource components, wherein the computer program product is configured for providing proactive network security by dynamically analyzing entering network resource components for vulnerabilities, establishing adapted validation thresholds and mitigation actions, and preventing unsuccessfully validated network resource components in a distributed network, the computer program product comprising a non-transitory computer-readable storage medium having computer-executable instructions for causing a computer processor to:

detect, via a network proxy component, an incoming file transfer associated with a first network program resource component at a first distributed network initiated by a first user at first network device of the first distributed network;

in response to determining, via the network proxy component, that a file attribute data element associated with the first network program resource component is associated with a predetermined file type, (i) block the incoming file transfer associated with the first network program resource component at the first distributed network, and (ii) automatically redirect a current interface displayed at the first network device to a dynamic validated network resource library interface associated with a dynamic validated network resource library, wherein the file attribute data element is associated with a file name of the first network program resource component;

receive, via the dynamic validated network resource library interface, a request for the first network program resource component from the first user via the first network device;

download the first network program resource component to a network quarantine component associated with the first distributed network;

initiate, via the network quarantine component, dynamic validation of the first network program resource component based on at least one or more categorical network program resource component records associated with the dynamic validated network resource library;

in response to a successful validation of the first network program resource component, construct a transmission of the downloaded first network program resource component to the first network device such that the first network program resource component cannot be executed at the first network device when the dynamic validated network resource library does not comprise the first network program resource component; and

initiate the transmission of the downloaded first network program resource component to the first network device.

13. The computer program product of claim 12 , the non-transitory computer-readable storage medium further comprises computer-executable instructions for causing the computer processor to:

construct a retrieval rule associated with the first network program resource component based on determining one or more data fields associated with the network program resource component;

retrieve one or more first categorical network program resource component records of a plurality of categorical network program resource component records based on the retrieval rule from the dynamic validated network resource library;

parse the one or more first categorical network program resource component records to determine whether the one or more first categorical network program resource component records match the first network program resource component; and

in response to determining that the one or more first categorical network program resource component records match the first network program resource component, allow installation of the first network program resource component at the first network device.

14. The computer program product of claim 12 , the non-transitory computer-readable storage medium further comprises computer-executable instructions for causing the computer processor to:

construct a retrieval rule associated with the first network program resource component based on determining one or more data fields associated with the network program resource component;

retrieve one or more first categorical network program resource component records of a plurality of categorical network program resource component records based on the retrieval rule from the dynamic validated network resource library;

parse the one or more first categorical network program resource component records to determine whether the one or more first categorical network program resource component records match the first network program resource component; and

in response to determining that the one or more first categorical network program resource component records do not match the first network program resource component, prevent installation of the first network program resource component at the first network device.

15. The computer program product of claim 12 , wherein determining that the file attribute data element associated with the first network program resource component is associated with the predetermined file type comprises determining that the first network program resource component is an executable type file.

16. A method for dynamic adapted security analysis of network resource components, wherein the method is configured for providing proactive network security by dynamically analyzing entering network resource components for vulnerabilities, establishing adapted validation thresholds and mitigation actions, and preventing unsuccessfully validated network resource components in a distributed network, the method comprising:

detecting, via a network proxy component, an incoming file transfer associated with a first network program resource component at a first distributed network initiated by a first user at first network device of the first distributed network;

in response to determining, via the network proxy component, that a file attribute data element associated with the first network program resource component is associated with a predetermined file type, (i) blocking the incoming file transfer associated with the first network program resource component at the first distributed network, and (ii) automatically redirecting a current interface displayed at the first network device to a dynamic validated network resource library interface associated with a dynamic validated network resource library, wherein the file attribute data element is associated with a file name of the first network program resource component;

receiving, via the dynamic validated network resource library interface, a request for the first network program resource component from the first user via the first network device;

downloading the first network program resource component to a network quarantine component associated with the first distributed network;

initiating, via the network quarantine component, dynamic validation of the first network program resource component based on at least one or more categorical network program resource component records associated with the dynamic validated network resource library;

in response to a successful validation of the first network program resource component, constructing a transmission of the downloaded first network program resource component to the first network device such that the first network program resource component cannot be executed at the first network device when the dynamic validated network resource library does not comprise the first network program resource component; and

initiating the transmission of the downloaded first network program resource component to the first network device.

17. The method of claim 16 , wherein the method further comprises:

constructing a retrieval rule associated with the first network program resource component based on determining one or more data fields associated with the network program resource component;

retrieving one or more first categorical network program resource component records of a plurality of categorical network program resource component records based on the retrieval rule from the dynamic validated network resource library;

parsing the one or more first categorical network program resource component records to determine whether the one or more first categorical network program resource component records match the first network program resource component; and

in response to determining that the one or more first categorical network program resource component records match the first network program resource component, allowing installation of the first network program resource component at the first network device.

18. The method of claim 16 , wherein the method further comprises:

constructing a retrieval rule associated with the first network program resource component based on determining one or more data fields associated with the network program resource component;

retrieving one or more first categorical network program resource component records of a plurality of categorical network program resource component records based on the retrieval rule from the dynamic validated network resource library;

parsing the one or more first categorical network program resource component records to determine whether the one or more first categorical network program resource component records match the first network program resource component; and

in response to determining that the one or more first categorical network program resource component records do not match the first network program resource component, preventing installation of the first network program resource component at the first network device.

19. The method of claim 16 , wherein determining that the file attribute data element associated with the first network program resource component is associated with the predetermined file type comprises determining that the first network program resource component is an executable type file.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2022
From: BOUCHARD, PIERRE JACQUES
To: BANK OF AMERICA CORPORATION
Reel/Frame 060794/0675 →
Continuity (1)
Related Publication 20240056468A1 · Feb 15, 2024
References Cited (57)
US 5247575A · Sprague et al. · 1993 [cited by applicant]
US 5646997A · Barton · 1997 [cited by applicant]
US 6259801B1 · Wakasu · 2001 [cited by applicant]
US 7073059B2 · Worely, Jr. et al. · 2006 [cited by applicant]
US 7152165B1 · Maheshwari et al. · 2006 [cited by applicant]
US 7581103B2 · Home et al. · 2009 [cited by applicant]
US 8065712B1 · Cheng et al. · 2011 [cited by applicant]
US 8621610B2 · Oberheide et al. · 2013 [cited by applicant]
US 8806639B2 · Mohler · 2014 [cited by applicant]
US 9367701B2 · Merchan et al. · 2016 [cited by applicant]
US 9753844B2 · Kripalani · 2017 [cited by applicant]
US 9813450B1 · Wasiq · 2017 [cited by applicant]
US 10129222B2 · Maheshwari et al. · 2018 [cited by applicant]
US 10324690B2 · Ouali · 2019 [cited by applicant]
US 10462251B2 · O'Connell, Jr. et al. · 2019 [cited by applicant]
US RE47704E · Briggs et al. · 2019 [cited by applicant]
US 10554475B2 · Weinstein et al. · 2020 [cited by applicant]
US 10848557B2 · Kaplan et al. · 2020 [cited by applicant]
US 10984041B2 · Sanur et al. · 2021 [cited by applicant]
US 11030318B1 · Shavro · 2021 [cited by applicant]
US 11349865B1 · Satpathy et al. · 2022 [cited by applicant]
US 20030028803A1 · Bunker, V et al. · 2003 [cited by applicant]
US 20030056116A1 · Bunker, V et al. · 2003 [cited by applicant]
US 20040260818A1 · Valois et al. · 2004 [cited by applicant]
US 20060048209A1 · Shelest et al. · 2006 [cited by applicant]
US 20060059253A1 · Goodman et al. · 2006 [cited by applicant]
US 20070074149A1 · Ognev et al. · 2007 [cited by applicant]
US 20080313733A1 · Kramer et al. · 2008 [cited by applicant]
US 20090125875A1 · Schmitter et al. · 2009 [cited by applicant]
US 20100251369A1 · Grant · 2010 [cited by applicant]
US 20110219205A1 · Wright · 2011 [cited by applicant]
US 20130097711A1 · Basavapatna et al. · 2013 [cited by applicant]
US 20150074281A1 · Vendrow · 2015 [cited by applicant]
US 20150244795A1 · Cantwell et al. · 2015 [cited by applicant]
US 20150363481A1 · Haynes · 2015 [cited by applicant]
US 20160134491A1 · Cordray et al. · 2016 [cited by applicant]
US 20170039218A1 · Prahlad et al. · 2017 [cited by applicant]
US 20170075719A1 · Scallan et al. · 2017 [cited by applicant]
US 20180144106A1 · Cholas et al. · 2018 [cited by applicant]
US 20180302373A1 · Ezell et al. · 2018 [cited by applicant]
US 20190114435A1 · Bhalla et al. · 2019 [cited by applicant]
US 20190265971A1 · Behzadi et al. · 2019 [cited by applicant]
US 20190273760A1 · Jacobs · 2019 [cited by applicant]
US 20190317944A1 · Deremigio et al. · 2019 [cited by applicant]
US 20200012779A1 · Chandrasekaran et al. · 2020 [cited by applicant]
US 20200285742A1 · Sawas · 2020 [cited by applicant]
US 20210124830A1 · Dinh et al. · 2021 [cited by applicant]
US 20210182975A1 · Neag et al. · 2021 [cited by applicant]
US 20210211438A1 · Trim et al. · 2021 [cited by applicant]
US 20210226981A1 · Huffman et al. · 2021 [cited by applicant]
US 20220108020A1 · Dang et al. · 2022 [cited by applicant]
US 20220286476A1 · Carroll · 2022 [cited by examiner]
US 20230120174A1 · Seck et al. · 2023 [cited by applicant]
US 20230281005A1 · Groenewegen et al. · 2023 [cited by applicant]
US 20240045971A1 · Ben Salem et al. · 2024 [cited by applicant]
Zhang et al., “A Vulnerability Detection System for Power Internet of Things Equipment,” 2023 IEEE 3rd International Conference on Information Technology, Big Data and Artificial Intelligence (ICIBA) Year: 2023 | Confer… [cited by applicant]
Doynikova et al., “Analytical attack modeling and security assessment based on the common vulnerability scoring system,” 2017 20th Conference of Open Innovations Association (FRUCT) Year: 2017 | Conference Paper | Publi… [cited by applicant]