IP Library Granted Patent US 12,452,313
Granted Patent B2
US 12,452,313 · App. 18/582,933 · Granted Oct 21, 2025

Cyberthreat remediation using a zero trust engine

Inventor: Timucin Ozugur (Fairview, TX)
Assignee: Bank of America Corporation
H04L63/205H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,313
App. No.
18/582,933
Granted
Oct 21, 2025
Kind
B2
Abstract

Aspects related to cyberthreat remediation using a zero trust engine are provided. A cyberthreat remediation platform may receive information of cyberthreats and vulnerabilities for application associated with a network. The platform may train a zero trust engine to generate cyberthreat mappings comprising vulnerability-cyberthreat pairings based on the information. The platform may generate a cyberthreat record for an application based on a cyberthreat mapping. The platform may generate a cyberthreat level indicator for the application based on the cyberthreat record. The platform may compare the cyberthreat level indicator to a threshold to identify whether remediation actions should be initiated. Based on the comparison, the platform may initiate one or more remediation actions to resolve one or more cyberthreats.

Claims (76)

1. A computing platform comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, configure the computing platform to:

receive, based on cyberthreat modeling and vulnerability scanning of one or more applications corresponding to a network, information of cyberthreats and vulnerabilities corresponding to the one or more applications;

train, based on the information of cyberthreats and vulnerabilities, a zero trust model, wherein training the zero trust model configures the zero trust model to generate cyberthreat mappings for applications based on input of information of cyberthreats and vulnerabilities;

identify, based on one or more parameters, a first application, of the one or more applications, for cyberthreat testing;

generate, based on a subset of information, of the information of cyberthreats and vulnerabilities and corresponding to the first application, a cyberthreat mapping for the first application, wherein the cyberthreat mapping comprises a plurality of vulnerability-cyberthreat pairings and wherein the generating the cyberthreat mapping is further based on inputting the subset of information into the zero trust model;

generate, based on the cyberthreat mapping, a cyberthreat record, wherein the cyberthreat record comprises a representation of the cyberthreat mapping;

generate, by comparing the cyberthreat record to one or more trigger criteria, a cyberthreat level indicator for the first application, wherein the cyberthreat level indicator indicates a likelihood of a cyberthreat affecting the first application;

identify, by comparing the cyberthreat level indicator to a threshold, whether the cyberthreat level indicator satisfies the threshold;

initiate, based on identifying that the cyberthreat level indicator satisfies the threshold, one or more cyberthreat remediation actions for the application;

update, based on identifying whether the cyberthreat level indicator satisfies the threshold, the information of cyberthreats and vulnerabilities; and

update, based on the updated information of cyberthreats and vulnerabilities, the zero trust model.

2. The computing platform of claim 1 , wherein the updating the zero trust model is further based on the initiating the one or more cyberthreat remediation actions.

3. The computing platform of claim 1 , wherein the cyberthreat modeling comprises identifying, based on a design of the first application, one or more potential cyberthreats to the network and the vulnerability scanning comprises identifying whether the one or more potential cyberthreats are resolved.

4. The computing platform of claim 1 , wherein the identifying the first application for cyberthreat testing comprises:

identifying whether a threshold amount of time corresponding to cyberthreat testing of the first application is satisfied, or

identifying whether an update time corresponding to the first application antedates a cyberthreat testing time corresponding to the first application.

5. The computing platform of claim 1 , wherein the trigger criteria comprises one or more of:

a ratio of incorrectly closed cyberthreats to correctly closed cyberthreats,

a negative divergence between vulnerability scans of the first application, or

a divergence between a ratio of unverified cyberthreats and a ratio of verified cyberthreats.

6. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, further configure the computing platform to:

cause, based on identifying that the cyberthreat level indicator satisfies the threshold and prior to the initiating the one or more cyberthreat remediation actions, display of a cyberthreat remediation interface.

7. The computing platform of claim 1 , wherein the one or more cyberthreat remediation actions comprise one or more of:

identifying, for each of the plurality of vulnerability-cyberthreat pairings, whether an associated cyberthreat is resolved, or

resolving, based on the plurality of vulnerability-cyberthreat pairings, one or more cyberthreats.

8. A method comprising:

at a computing device comprising at least one processor, a communication interface, and memory:

receiving, based on cyberthreat modeling and vulnerability scanning of one or more applications corresponding to a network, information of cyberthreats and vulnerabilities corresponding to the one or more applications;

training, based on the information of cyberthreats and vulnerabilities, a zero trust model, wherein training the zero trust model configures the zero trust model to generate cyberthreat mappings for applications based on input of information of cyberthreats and vulnerabilities;

identifying, based on one or more parameters, a first application, of the one or more applications, for cyberthreat testing;

generating, based on a subset of information, of the information of cyberthreats and vulnerabilities and corresponding to the first application, a cyberthreat mapping for the first application, wherein the cyberthreat mapping comprises a plurality of vulnerability-cyberthreat pairings and wherein the generating the cyberthreat mapping is based on inputting the subset of information into the zero trust model;

generating, based on the cyberthreat mapping, a cyberthreat record, wherein the cyberthreat record comprises a representation of the cyberthreat mapping;

generating, by comparing the cyberthreat record to one or more trigger criteria, a cyberthreat level indicator for the first application, wherein the cyberthreat level indicator indicates a likelihood of a cyberthreat affecting the first application;

identifying, by comparing the cyberthreat level indicator to a threshold, whether the cyberthreat level indicator satisfies the threshold;

initiating, based on identifying that the cyberthreat level indicator satisfies the threshold, one or more cyberthreat remediation actions for the application;

updating, based on identifying whether the cyberthreat level indicator satisfies the threshold, the information of cyberthreats and vulnerabilities; and

updating, based on the updated information of cyberthreats and vulnerabilities, the zero trust model.

9. The method of claim 8 , wherein the updating the zero trust model is further based on the initiating the one or more cyberthreat remediation actions.

10. The method of claim 8 , wherein the cyberthreat modeling comprises identifying, based on a design of the first application, one or more potential cyberthreats to the network and the vulnerability scanning comprises identifying whether the one or more potential cyberthreats are resolved.

11. The method of claim 8 , wherein the identifying the first application for cyberthreat testing comprises:

identifying whether a threshold amount of time corresponding to cyberthreat testing of the first application is satisfied, or

identifying whether an update time corresponding to the first application antedates a cyberthreat testing time corresponding to the first application.

12. The method of claim 8 , further comprising:

cause, based on identifying that the cyberthreat level indicator satisfies the threshold and prior to the initiating the one or more cyberthreat remediation actions, display of a cyberthreat remediation interface.

13. The method of claim 8 , wherein the trigger criteria comprises one or more of:

a ratio of incorrectly closed cyberthreats to correctly closed cyberthreats,

a negative divergence between vulnerability scans of the first application, or

a divergence between a ratio of unverified cyberthreats and a ratio of verified cyberthreats.

14. The method of claim 8 , wherein the one or more cyberthreat remediation actions comprise one or more of:

identifying, for each of the plurality of vulnerability-cyberthreat pairings, whether an associated cyberthreat is resolved, or

resolving, based on the plurality of vulnerability-cyberthreat pairings, one or more cyberthreats.

15. One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

receive, based on cyberthreat modeling and vulnerability scanning of one or more applications corresponding to a network, information of cyberthreats and vulnerabilities corresponding to the one or more applications;

train, based on the information of cyberthreats and vulnerabilities, a zero trust model, wherein training the zero trust model configures the zero trust model to generate cyberthreat mappings for applications based on input of information of cyberthreats and vulnerabilities;

identify, based on one or more parameters, a first application, of the one or more applications, for cyberthreat testing;

generate, based on a subset of information, of the information of cyberthreats and vulnerabilities and corresponding to the first application, a cyberthreat mapping for the first application, wherein the cyberthreat mapping comprises a plurality of vulnerability-cyberthreat pairings and wherein the generating the cyberthreat mapping is based on inputting the subset of information into the zero trust model;

generate, based on the cyberthreat mapping, a cyberthreat record, wherein the cyberthreat record comprises a representation of the cyberthreat mapping;

generate, by comparing the cyberthreat record to one or more trigger criteria, a cyberthreat level indicator for the first application, wherein the cyberthreat level indicator indicates a likelihood of a cyberthreat affecting the first application;

identify, by comparing the cyberthreat level indicator to a threshold, whether the cyberthreat level indicator satisfies the threshold;

initiate, based on identifying that the cyberthreat level indicator satisfies the threshold, one or more cyberthreat remediation actions for the application;

update, based on identifying whether the cyberthreat level indicator satisfies the threshold, the information of cyberthreats and vulnerabilities; and

update, based on the updated information of cyberthreats and vulnerabilities, the zero trust model.

16. The one or more non-transitory computer-readable media of claim 15 , wherein the updating the zero trust model is further based on the initiating the one or more cyberthreat remediation actions.

17. The one or more non-transitory computer-readable media of claim 15 , wherein the cyberthreat modeling comprises identifying, based on a design of the first application, one or more potential cyberthreats to the network and the vulnerability scanning comprises identifying whether the one or more potential cyberthreats are resolved.

18. The one or more non-transitory computer-readable media of claim 15 , wherein the identifying the first application for cyberthreat testing comprises:

identifying whether a threshold amount of time corresponding to cyberthreat testing of the first application is satisfied, or

identifying whether an update time corresponding to the first application antedates a cyberthreat testing time corresponding to the first application.

19. The one or more non-transitory computer-readable media of claim 15 , storing instructions that, when executed, further cause the computing platform to:

cause, based on identifying that the cyberthreat level indicator satisfies the threshold and prior to the initiating the one or more cyberthreat remediation actions, display of a cyberthreat remediation interface.

20. The one or more non-transitory computer-readable media of claim 15 , wherein the trigger criteria comprises one or more of:

a ratio of incorrectly closed cyberthreats to correctly closed cyberthreats,

a negative divergence between vulnerability scans of the first application, or

a divergence between a ratio of unverified cyberthreats and a ratio of verified cyberthreats.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2024
From: OZUGUR, TIMUCIN
To: BANK OF AMERICA CORPORATION
Reel/Frame 066514/0253 →
Continuity (1)
Related Publication 20250267175A1 · Aug 21, 2025
References Cited (32)
US 10277622B2 · DiGiambattista et al. · 2019 [cited by applicant]
US 11489863B1 · Shua · 2022 [cited by examiner]
US 11616803B2 · Shua · 2023 [cited by examiner]
US 11769577B1 · Dods et al. · 2023 [cited by applicant]
US 11829510B2 · Dods et al. · 2023 [cited by applicant]
US 11848953B1 · Chernick et al. · 2023 [cited by applicant]
US 11848956B2 · Shua · 2023 [cited by examiner]
US 11888890B2 · Maheve et al. · 2024 [cited by applicant]
US 20180063181A1 · Jones · 2018 [cited by examiner]
US 20200068031A1 · Kursun · 2020 [cited by examiner]
US 20210273698A1 · Ding et al. · 2021 [cited by applicant]
US 20210314338A1 · Howe · 2021 [cited by applicant]
US 20220027431A1 · Zheng et al. · 2022 [cited by applicant]
US 20220201009A1 · Dhoble et al. · 2022 [cited by applicant]
US 20220224724A1 · Bazalgette · 2022 [cited by examiner]
US 20220272117A1 · Maheve et al. · 2022 [cited by applicant]
US 20220272119A1 · Camerinesi · 2022 [cited by examiner]
US 20230123781A1 · Kaimal et al. · 2023 [cited by applicant]
US 20230156032A1 · Andriani · 2023 [cited by applicant]
US 20230179613A1 · Andrews et al. · 2023 [cited by applicant]
US 20230208828A1 · Kolodziej · 2023 [cited by applicant]
US 20230216947A1 · Bernardi · 2023 [cited by applicant]
US 20230229787A1 · Mahdavipour et al. · 2023 [cited by applicant]
US 20230254330A1 · Singh et al. · 2023 [cited by applicant]
US 20230275917A1 · Karmali et al. · 2023 [cited by applicant]
US 20230308433A1 · Katyal et al. · 2023 [cited by applicant]
US 20230336592A1 · Narayanaswamy et al. · 2023 [cited by applicant]
US 20230353587A1 · Bui et al. · 2023 [cited by applicant]
US 20230370495A1 · Desai et al. · 2023 [cited by applicant]
US 20230388278A1 · Crabtree et al. · 2023 [cited by applicant]
US 20240039954A1 · Shete et al. · 2024 [cited by applicant]
US 20250047695A1 · Xu · 2025 [cited by examiner]