IP Library Granted Patent US 12,299,155
Granted Patent B2
US 12,299,155 · App. 17/697,157 · Granted May 13, 2025

Performing retroactive threshold reduction control review using artificial intelligence

Inventors: George Albero (Charlotte, NC); Olga Kocharyan (Matthews, NC)
Assignee: Bank of America Corporation
G06F21/6218G06F21/53G06N5/022G06Q10/105G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,299,155
App. No.
17/697,157
Granted
May 13, 2025
Kind
B2
Abstract

Aspects of the disclosure relate to adjustable control thresholds. A computing platform may monitor employee activity within an enterprise organization. The computing platform may generate, for each employee of the plurality of employees, employee control thresholds. The computing platform may generate, based on an indication from an employee computing device, modified employee control thresholds associated with the employee. The computing platform may generate, based on the indication, test data including a subset of the employee activity associated with the employee. The computing platform may analyze, within a sandbox environment, the test data, and may determine, based on the analysis, whether to: transmit a notification to an enterprise computing device indicating the test data complies with the employee control thresholds associated with the employee; or transmit a notification to the enterprise computing device indicating the test data does not comply with the employee control thresholds associated with the employee.

Claims (126)

1. A computing platform comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

memory storing computer-readable instructions that, when executed by the processor, cause the computing platform to:

monitor, for a plurality of employees, employee activity within an enterprise organization;

generate, for each employee of the plurality of employees, employee control thresholds;

generate, based on an indication from an employee computing device of an employee of the plurality of employees, modified employee control thresholds associated with the employee; and

generate data that is used to train a machine learning model, wherein the training data comprises the employee activity associated with the employee, the employee control thresholds associated with the employee, and the modified employee control thresholds associated with the employee;

train, based on the data and using one or more supervised learning techniques, the machine learning model, wherein training the machine learning model configures the machine learning model to perform anomaly detection in analysis of employee activity information;

generate, based on the indication, test data, wherein the test data comprises a subset of the employee activity associated with the employee;

analyze, within a sandbox environment, the test data;

determine, based on the analysis, whether to:

transmit a notification to an enterprise computing device indicating the test data complies with the employee control thresholds associated with the employee; or

transmit a notification to the enterprise computing device indicating the test data does not comply with the employee control thresholds associated with the employee; and

refine, using a dynamic feedback loop and based on the modified employee control thresholds, the machine learning model, wherein the refining continuously improves accuracy of the machine learning model.

2. The computing platform of claim 1 , wherein:

the enterprise computing device is further configured to receive, from the computing platform, a notification indicating one of:

test data compliance with the employee control thresholds associated with the employee; or

test data non-compliance with the employee control thresholds associated with the employee.

3. The computing platform of claim 1 , wherein the employee activity indicates at least one of:

enterprise databases accessed by the employee;

enterprise applications accessed by the employee;

a ledger indicating a date and a time that the employee entered the enterprise organization;

human resources records associated with the employee;

an IP address associated with the employee computing device;

a multi-factor authentication process associated with the employee computing device; or

keyword searches performed by the employee.

4. The computing platform of claim 1 , wherein the generating the employee control thresholds comprises:

determining a role within the enterprise organization associated with the employee and a line of business associated with the employee;

determining an access level associated with the employee based on the role and the line of business;

comparing the access level associated with the employee to access levels associated with other employees, within the plurality of employees, in a same role and a same line of business as the employee; and

modifying the access level associated with the employee based on the comparison.

5. The computing platform of claim 4 , wherein the analyzing the test data comprises:

comparing the test data to employee activity associated with other employees, within the plurality of employees, in the same role and the same line of business as the employee;

determining whether the test data matches the employee activity associated with the other employees, within the plurality of employees, in the same role and the same line of business as the employee; and

determining:

based on the test data matching the employee activity associated with the other employees, that the test data is not an outlier; or

based on the test data failing to match the employee activity associated with the other employees, that the test data is an outlier.

6. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the processor, further cause the computing platform to:

implement, based on the indication from the employee computing device, the modified employee control thresholds; and

initiate, based on the notification indicating the test data does not comply with the employee control thresholds associated with the employee, a security review of the employee activity associated with the employee.

7. The computing platform of claim 1 , wherein the indication from the employee computing device comprises at least one of:

a letter of resignation;

suspicious activity flagged within the employee activity associated with the employee; or

reduced employee presence within the enterprise organization.

8. A method comprising:

at a computing device comprising at least one processor, a communication interface, and memory:

monitoring, for a plurality of employees, employee activity within an enterprise organization;

generating, for each employee of the plurality of employees, employee control thresholds;

generating, based on an indication from an employee computing device of an employee of the plurality of employees, modified employee control thresholds associated with the employee;

generating training data for training a machine learning model, wherein the training data comprises the employee activity associated with the employee, the employee control thresholds associated with the employee, and the modified employee control thresholds associated with the employee;

training, based on the data and using one or more supervised learning techniques, the machine learning model, wherein training the machine learning model configures the machine learning model to perform anomaly detection in analysis of employee activity information;

generating, based on the indication, test data, wherein the test data comprises a subset of the employee activity associated with the employee;

analyzing, within a sandbox environment, the test data;

determining, based on the analysis, whether to:

transmit a notification to the enterprise organization indicating the test data complies with the employee control thresholds associated with the employee; or

transmit a notification to the enterprise organization indicating the test data does not comply with the employee control thresholds associated with the employee; and

refining, using a dynamic feedback loop and based on the modified employee control thresholds, the machine learning model, wherein the refining continuously improves accuracy of the machine learning model.

9. The method of claim 8 , wherein:

the enterprise computing device is further configured to receive, from the computing device, a notification indicating one of:

test data compliance with the employee control thresholds associated with the employee; or

test data non-compliance with the employee control thresholds associated with the employee.

10. The method of claim 8 , wherein the employee activity indicates at least one of:

enterprise databases accessed by the employee;

enterprise applications accessed by the employee;

a ledger indicating a date and a time that the employee entered the enterprise organization;

human resources records associated with the employee;

an IP address associated with the employee computing device;

a multi-factor authentication process associated with the employee computing device; or

keyword searches performed by the employee.

11. The method of claim 8 , wherein the generating the employee control thresholds comprises:

determining a role within the enterprise organization associated with the employee and a line of business associated with the employee;

determining an access level associated with the employee based on the role and the line of business;

comparing the access level associated with the employee to access levels associated with other employees, within the plurality of employees, in a same role and a same line of business as the employee; and

modifying the access level associated with the employee based on the comparison.

12. The method of claim 11 , wherein the analyzing the test data comprises:

comparing the test data to employee activity associated with other employees, within the plurality of employees, in the same role and the same line of business as the employee;

determining whether the test data matches the employee activity associated with the other employees, within the plurality of employees, in the same role and the same line of business as the employee; and

determining:

based on the test data matching the employee activity associated with the other employees, that the test data is not an outlier; or

based on the test data failing to match the employee activity associated with the other employees, that the test data is an outlier.

13. The method of claim 8 , further comprising:

implementing, based on the indication from the employee computing device, the modified employee control thresholds; and

initiating, based on the notification indicating the test data does not comply with the employee control thresholds associated with the employee, a security review of the employee activity associated with the employee.

14. The method of claim 8 , wherein the indication from the employee computing device comprises at least one of:

a letter of resignation;

suspicious activity flagged within the employee activity associated with the employee; or

reduced employee presence within the enterprise organization.

15. One or more non-transitory computer-readable media storing instructions that, when executed by a computing device comprising at least one processor, a communication interface, and memory, cause the computing device to:

monitor, for a plurality of employees, employee activity within an enterprise organization;

generate, for each employee of the plurality of employees, employee control thresholds;

generate, based on an indication from an employee computing device of an employee of the plurality of employees, modified employee control thresholds associated with the employee; and

generate data that is used to train a machine learning model, wherein the training data comprises the employee activity associated with the employee, the employee control thresholds associated with the employee, and the modified employee control thresholds associated with the employee;

train, based on the data and using one or more supervised learning techniques, the machine learning model, wherein training the machine learning model configures the machine learning model to perform anomaly detection in analysis of employee activity information;

generate, based on the indication, test data, wherein the test data comprises a subset of the employee activity associated with the employee;

analyze, within a sandbox environment, the test data; and

determine, based on the analysis, whether to:

transmit a notification to an enterprise computing device indicating the test data complies with the employee control thresholds associated with the employee; or

transmit a notification to the enterprise computing device indicating the test data does not comply with the employee control thresholds associated with the employee; and

refine, using a dynamic feedback loop and based on the modified employee control thresholds, the machine learning model, wherein the refining continuously improves accuracy of the machine learning model.

16. The one or more non-transitory computer-readable media of claim 15 , wherein:

the enterprise computing device is further configured to receive, from the computing device, a notification indicating one of:

test data compliance with the employee control thresholds associated with the employee; or

test data non-compliance with the employee control thresholds associated with the employee.

17. The one or more non-transitory computer-readable media of claim 15 , wherein the employee activity indicates at least one of:

enterprise databases accessed by the employee;

enterprise applications accessed by the employee;

a ledger indicating a date and a time that the employee entered the enterprise organization;

human resources records associated with the employee;

an IP address associated with the employee computing device;

a multi-factor authentication process associated with the employee computing device; or

keyword searches performed by the employee.

18. The one or more non-transitory computer-readable media of claim 15 , wherein the generating the employee control thresholds comprises:

determining a role within the enterprise organization associated with the employee and a line of business associated with the employee;

determining an access level associated with the employee based on the role and the line of business;

comparing the access level associated with the employee to access levels associated with other employees, within the plurality of employees, in a same role and a same line of business as the employee; and

modifying the access level associated with the employee based on the comparison.

19. The one or more non-transitory computer-readable media of claim 18 , wherein the analyzing the test data comprises:

comparing the test data to employee activity associated with other employees, within the plurality of employees, in the same role and the same line of business as the employee;

determining whether the test data matches the employee activity associated with the other employees, within the plurality of employees, in the same role and the same line of business as the employee; and

determining:

based on the test data matching the employee activity associated with the other employees, that the test data is not an outlier; or

based on the test data failing to match the employee activity associated with the other employees, that the test data is an outlier.

20. The one or more non-transitory computer-readable media of claim 15 , wherein the memory stores additional computer-readable instructions that, when executed by the processor, further cause the computing device to:

implement, based on the indication from the employee computing device, the modified employee control thresholds; and

initiate, based on the notification indicating the test data does not comply with the employee control thresholds associated with the employee, a security review of the employee activity associated with the employee.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2022
From: ALBERO, GEORGE; KOCHARYAN, OLGA
To: BANK OF AMERICA CORPORATION
Reel/Frame 059294/0014 →
Continuity (1)
Related Publication 20230297707A1 · Sep 21, 2023
References Cited (37)
US 8769684B2 · Stolfo et al. · 2014 [cited by applicant]
US 8868728B2 · Margolies et al. · 2014 [cited by applicant]
US 9641544B1 · Treat · 2017 [cited by examiner]
US 9727821B2 · Lin et al. · 2017 [cited by applicant]
US 10104100B1 · Bogorad · 2018 [cited by applicant]
US 10142391B1 · Brisebois et al. · 2018 [cited by applicant]
US 10270790B1 · Jackson · 2019 [cited by applicant]
US 10326748B1 · Brisebois et al. · 2019 [cited by applicant]
US 10505825B1 · Bettaiah · 2019 [cited by examiner]
US 10986121B2 · Stockdale et al. · 2021 [cited by applicant]
US 11050793B2 · Jeyakumar · 2021 [cited by examiner]
US 11126467B2 · Gray et al. · 2021 [cited by applicant]
US 11170029B2 · Pradjinata · 2021 [cited by applicant]
US 11178509B2 · Wang et al. · 2021 [cited by applicant]
US 11194915B2 · Stolfo et al. · 2021 [cited by applicant]
US 11200969B2 · Lyman et al. · 2021 [cited by applicant]
US 11216317B1 · Shibayama et al. · 2022 [cited by applicant]
US 11277661B2 · Inoue et al. · 2022 [cited by applicant]
US 11757890B1 · Kearney · 2023 [cited by examiner]
US 20150235152A1 · Eldardiry et al. · 2015 [cited by applicant]
US 20160142399A1 · Pace · 2016 [cited by examiner]
US 20190044963A1 · Rajasekharan et al. · 2019 [cited by applicant]
US 20190052659A1 · Weingarten · 2019 [cited by examiner]
US 20190238604A1 · Sundaram et al. · 2019 [cited by applicant]
US 20190238605A1 · Patel et al. · 2019 [cited by applicant]
US 20190243967A1 · Sonoda · 2019 [cited by examiner]
US 20190373031A1 · Patel et al. · 2019 [cited by applicant]
US 20190385175A1 · Chamberlain · 2019 [cited by examiner]
US 20200175152A1 · Xu · 2020 [cited by examiner]
US 20200259852A1 · Wolff · 2020 [cited by examiner]
US 20210084063A1 · Triantafillos · 2021 [cited by examiner]
US 20220224716A1 · Salji · 2022 [cited by examiner]
US 20220294765A1 · Frendo · 2022 [cited by examiner]
US 20230177934A1 · Reddy · 2023 [cited by examiner]
US 20240356959A1 · Jeyakumar · 2024 [cited by examiner]
US 20240406210A1 · Sellars · 2024 [cited by examiner]
CN 117786079A · 2024 [cited by examiner]