IP Library Granted Patent US 12,395,502
Granted Patent B2
US 12,395,502 · App. 17/955,098 · Granted Aug 19, 2025

System and method for identifying and preventing misappropriation using normalized request sequences

Inventors: Brady Prentice Merkel (Jacksonville Beach, FL); Wayne Georges (Somerset, NJ)
Assignee: BANK OF AMERICA CORPORATION
H04L63/1416H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,395,502
App. No.
17/955,098
Granted
Aug 19, 2025
Kind
B2
Abstract

Systems, computer program products, and methods are described herein for identifying and preventing misappropriation using normalized request sequences. The method includes receiving a sequence of two or more requests associated with a user. The method also includes comparing the sequence of two or more requests with one or more past sequence of two or more past requests. The method further includes determining whether the sequence of two or more requests were carried out by the user or the malfeasant actor. The determination is made based on a comparison of the sequence of two or more requests with at least one of the one or more past sequence of two or more past requests. The method also includes causing an escalation action to be executed in an instance in which the sequence of two or more requests was carried out by the malfeasant actor.

Claims (34)

1. A system for identifying and preventing misappropriation using normalized request sequences, the system comprising:

at least one non-transitory storage device; and

at least one processing device coupled to the at least one non-transitory storage device, wherein the at least one processing device is configured to:

receive a sequence of two or more requests associated with a user;

compare the sequence of two or more requests with one or more past sequence of two or more past requests, wherein the one or more past sequence of two or more past requests were associated with one of the user or a malfeasant actor;

determine whether the sequence of two or more requests were carried out by the user or the malfeasant actor, wherein the determination is made based on a comparison of the sequence of two or more requests with at least one of the one or more past sequence of two or more past requests;

in an instance in which the sequence of two or more requests was carried out by the malfeasant actor, cause an escalation action to be executed, wherein the escalation action comprises limited access to computing devices associated with the malfeasant actor; and

update a training set for a machine learning model for the normalized request sequences with the sequence of two or mor requests associated with the user.

2. The system of claim 1 , wherein the escalation action comprises a notification that the sequence of two or more requests was carried out by the malfeasant actor.

3. The system of claim 1 , wherein the at least one processing device is configured to train a training set for the user based on the one or more past sequence of two or more past requests.

4. The system of claim 3 , wherein the training set is updated based on the determination that the sequence of two or more requests were carried out by the user.

5. The system of claim 1 , wherein the one or more past sequence of two or more past requests were carried out by the user.

6. The system of claim 1 , wherein the one or more past sequence of two or more past requests were carried out by the malfeasant actor.

7. A computer program product for identifying and preventing misappropriation using normalized request sequences, the computer program product comprising at least one non-transitory computer-readable medium having computer-readable program code portions embodied therein, the computer-readable program code portions comprising:

an executable portion configured to receive a sequence of two or more requests associated with a user,

an executable portion configured to compare the sequence of two or more requests with one or more past sequence of two or more past requests, wherein the one or more past sequence of two or more past requests were associated with one of the user or a malfeasant actor;

an executable portion configured to determine whether the sequence of two or more requests were carried out by the user or the malfeasant actor, wherein the determination is made based on a comparison of the sequence of two or more requests with at least one of the one or more past sequence of two or more past requests;

an executable portion configured to cause an escalation action to be executed in an instance in which the sequence of two or more requests was carried out by the malfeasant actor, wherein the escalation action comprises limited access to computing devices associated with the malfeasant actor; and

update a training set for a machine learning model for the normalized request sequences with the sequence of two or mor requests associated with the user.

8. The computer program product of claim 7 , wherein the escalation action comprises a notification that the sequence of two or more requests was carried out by the malfeasant actor.

9. The computer program product of claim 7 , wherein the computer program product further comprises an executable portion configured to train a training set for the user using the one or more past sequence of two or more past requests.

10. The computer program product of claim 9 , wherein the training set is updated based on the determination that the sequence of two or more requests were carried out by the user.

11. The computer program product of claim 7 , wherein the one or more past sequence of two or more past requests were carried out by the user.

12. The computer program product of claim 7 , wherein the one or more past sequence of two or more past requests were carried out by the malfeasant actor.

13. A computer-implemented method for identifying and preventing misappropriation using normalized request sequences, the method comprising:

receiving a sequence of two or more requests associated with a user;

comparing the sequence of two or more requests with one or more past sequence of two or more past requests, wherein the one or more past sequence of two or more past requests were associated with one of the user or a malfeasant actor;

determining whether the sequence of two or more requests were carried out by the user or the malfeasant actor, wherein the determination is made based on a comparison of the sequence of two or more requests with at least one of the one or more past sequence of two or more past requests;

in an instance in which the sequence of two or more requests was carried out by the malfeasant actor, causing an escalation action to be executed, wherein the escalation action comprises limited access to computing devices associated with the malfeasant actor; and

updating a training set for a machine learning model for the normalized request sequences with the sequence of two or mor requests associated with the user.

14. The method of claim 13 , wherein the escalation action comprises a notification that the sequence of two or more requests was carried out by the malfeasant actor.

15. The method of claim 13 , further comprising training a training set for the user using the one or more past sequence of two or more past requests.

16. The method of claim 15 , wherein the training set is updated based on the determination that the sequence of two or more requests were carried out by the user.

17. The method of claim 13 , wherein the one or more past sequence of two or more past requests were carried out by the user or the malfeasant actor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2022
From: MERKEL, BRADY PRENTICE; GEORGES, WAYNE
To: BANK OF AMERICA CORPORATION
Reel/Frame 061246/0257 →
Continuity (1)
Related Publication 20240106840A1 · Mar 28, 2024
References Cited (24)
US 5991411A · Kaufman · 1999 [cited by applicant]
US 8479983B1 · Block · 2013 [cited by applicant]
US 8612340B1 · Yan · 2013 [cited by applicant]
US 8775805B2 · Von Mueller · 2014 [cited by applicant]
US 8931692B2 · Sancak · 2015 [cited by applicant]
US 9342717B2 · Claessen · 2016 [cited by applicant]
US 9552470B2 · Turgeman · 2017 [cited by applicant]
US 9639838B2 · McNelley · 2017 [cited by applicant]
US 9767422B2 · Ray · 2017 [cited by applicant]
US 10477156B2 · Paliga · 2019 [cited by applicant]
US 10565595B2 · Lam · 2020 [cited by applicant]
US 11004050B2 · Hayhow · 2021 [cited by applicant]
US 11062316B2 · Bizarro · 2021 [cited by examiner]
US 11094142B2 · Hammad · 2021 [cited by applicant]
US 11132659B2 · Bilhan · 2021 [cited by applicant]
US 20060131389A1 · Kwon · 2006 [cited by applicant]
US 20070159882A1 · Liardet · 2007 [cited by applicant]
US 20090085761A1 · Buer · 2009 [cited by applicant]
US 20130132275A1 · Enzaldo · 2013 [cited by examiner]
US 20170243183A1 · Soeder · 2017 [cited by applicant]
US 20200137084A1 · Roy · 2020 [cited by examiner]
US 20220292510A1 · Guise · 2022 [cited by examiner]
US 20220405701A1 · Joy · 2022 [cited by examiner]
Dae-Ki Kang; Learning Classifiers for Misuse and Anomaly Detection Using a Bag of System Calls Represent ation; IEEE:2005; pp. 118-125. [cited by examiner]