IP Library Granted Patent US 12,518,005
Granted Patent B2
US 12,518,005 · App. 18/079,733 · Granted Jan 6, 2026

Threat detection and mitigation in a networked environment

Inventors: Kristina Dzeparoska (Toronto, CA); Rachel L. Clark (Gravenhurst, CA)
Assignee: The Toronto-Dominion Bank
G06F21/554G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,518,005
App. No.
18/079,733
Granted
Jan 6, 2026
Kind
B2
Abstract

One example method includes determining, by a threat detection system and at a first time interval, for an object and based on a first risk score computed for the object, that the object poses a threat to the networked environment. Analyzing threat events used for calculating the first risk score by a trained machine learning model for determining the likelihood that the object poses an actual threat and generating actual threat data based on the likelihood that the object poses an actual threat. In response to receiving the actual threat data, a value of a first counter can be computed based on prior incorrect identification of the object as a threat. A counterweight can be identified based on the value of the first counter. A second risk score for the object can be downscaled, using the identified counterweight to obtain an updated risk score for the object.

Claims (69)

1 . A computer-implemented method, comprising:

determining, by a threat detection system and at a first time interval, for an object that is deployed within a networked environment and based on a first risk score computed for the object, that the object poses a threat to the networked environment;

receiving actual threat data indicating that the object does not pose an actual threat to the networked environment;

in response to receiving the actual threat data, computing a value of a first counter based on prior incorrect identification of the object as a threat to the networked environment;

identifying, based on the value of the first counter, a counterweight comprising, in response to receiving the actual threat data, incrementing (1) a value of a second counter and (2) a value of a historical counter that indicates a number of times that the object has been incorrectly identified by the threat detection system as a threat to the networked environment;

downscaling, using the identified counterweight and at a second time interval, a second risk score for the object to obtain an updated risk score for the object;

controlling access of the object to system resources based on whether the updated risk score satisfies a predetermined risk threshold value;

computing the value of the first counter by scaling the value of the historical counter by a predetermined value; and

determining whether the value of the second counter satisfies a first threshold and whether the value of the first counter satisfies a second threshold.

2 . The computer-implemented method of claim 1 , comprising:

determining that the value of the second counter satisfies the first threshold and that the value of the first counter satisfies the second threshold; and

in response to determining that the value of the second counter satisfies the first threshold and that the value of the first counter satisfies the second threshold, generating a dynamic value as the counterweight.

3 . The computer-implemented method of claim 1 , comprising:

determining that the value of the second counter satisfies the first threshold and that the value of the first counter does not satisfy the second threshold; and

in response to determining that the value of the second counter satisfies the first threshold and that the value of the first counter does not satisfy the second threshold, generating a static value as the counterweight.

4 . The computer-implemented method of claim 1 , comprising:

after identifying the counterweight, resetting the second counter to zero.

5 . The computer-implemented method of claim 1 , wherein controlling access of the object to the system resources based on whether the updated risk score satisfies the predetermined risk threshold value comprises:

determining that the updated risk score satisfies the predetermined risk threshold value; and

in response to determining that the updated risk score satisfies the predetermined risk threshold value, granting, to the object, access to system resources.

6 . The computer-implemented method of claim 1 , wherein controlling access of the object to the system resources based on whether the updated risk score satisfies the predetermined risk threshold value comprises:

determining that the updated risk score does not satisfy the predetermined risk threshold value; and

in response to determining that the updated risk score does not satisfy the predetermined risk threshold value, denying the object access to the system resources.

7 . The computer-implemented method of claim 1 , wherein downscaling, using the identified counterweight, the second risk score for the object to obtain the updated risk score for the object comprises:

obtaining, from the threat detection system and at the second time interval, the second risk score for the object; and

scaling the second risk score by the identified counterweight to obtain the updated risk score for the object.

8 . A system comprising:

at least one memory storing instructions; and

at least one hardware processor interoperably coupled with the at least one memory, wherein execution of the instructions by the at least one hardware processor causes performance of operations comprising:

determining, by a threat detection system and at a first time interval, for an object that is deployed within a networked environment and based on a first risk score computed for the object, that the object poses a threat to the networked environment;

receiving actual threat data indicating that the object does not pose an actual threat to the networked environment;

in response to receiving the actual threat data, computing a value of a first counter based on prior incorrect identification of the object as a threat to the networked environment;

identifying, based on the value of the first counter, a counterweight comprising, in response to receiving the actual threat data, incrementing (1) a value of a second counter and (2) a value of a historical counter that indicates a number of times that the object has been incorrectly identified by the threat detection system as a threat to the networked environment;

downscaling, using the identified counterweight and at a second time interval, a second risk score for the object to obtain an updated risk score for the object;

controlling access of the object to system resources based on whether the updated risk score satisfies a predetermined risk threshold value;

computing the value of the first counter by scaling the value of the historical counter by a predetermined value; and

determining whether the value of the second counter satisfies a first threshold and whether the value of the first counter satisfies a second threshold.

9 . The system of claim 8 , the operations comprising:

determining that the value of the second counter satisfies the first threshold and that the value of the first counter satisfies the second threshold; and

in response to determining that the value of the second counter satisfies the first threshold and that the value of the first counter satisfies the second threshold, generating a dynamic value as the counterweight.

10 . The system of claim 8 , the operations comprising:

determining that the value of the second counter satisfies the first threshold and that the value of the first counter does not satisfy the second threshold; and

in response to determining that the value of the second counter satisfies the first threshold and that the value of the first counter does not satisfy the second threshold, generating a static value as the counterweight.

11 . The system of claim 8 , the operations comprising:

after identifying the counterweight, resetting the second counter to zero.

12 . The system of claim 8 , wherein controlling access of the object to the system resources based on whether the updated risk score satisfies the predetermined risk threshold value comprises:

determining that the updated risk score satisfies the predetermined risk threshold value; and

in response to determining that the updated risk score satisfies the predetermined risk threshold value, granting, to the object, access to system resources.

13 . A non-transitory, computer-readable medium storing computer-readable instructions, that upon execution by at least one hardware processor, cause performance of operations, comprising:

determining, by a threat detection system and at a first time interval, for an object that is deployed within a networked environment and based on a first risk score computed for the object, that the object poses a threat to the networked environment;

receiving actual threat data indicating that the object does not pose an actual threat to the networked environment;

in response to receiving the actual threat data, computing a value of a first counter based on prior incorrect identification of the object as a threat to the networked environment;

identifying, based on the value of the first counter, a counterweight comprising, in response to receiving the actual threat data, incrementing (1) a value of a second counter and (2) a value of a historical counter that indicates a number of times that the object has been incorrectly identified by the threat detection system as a threat to the networked environment;

downscaling, using the identified counterweight and at a second time interval, a second risk score for the object to obtain an updated risk score for the object;

controlling access of the object to system resources based on whether the updated risk score satisfies a predetermined risk threshold value;

computing the value of the first counter by scaling the value of the historical counter by a predetermined value; and

determining whether the value of the second counter satisfies a first threshold and whether the value of the first counter satisfies a second threshold.

14 . The non-transitory, computer-readable medium of claim 13 , the operations comprising:

determining that the value of the second counter satisfies the first threshold and that the value of the first counter satisfies the second threshold; and

in response to determining that the value of the second counter satisfies the first threshold and that the value of the first counter satisfies the second threshold, generating a dynamic value as the counterweight.

15 . The computer-implemented method of claim 1 , comprising:

analyzing threat events used for calculating the first risk score by a trained machine learning model for determining the likelihood that the object poses an actual threat; and

generating actual threat data based on the likelihood that the object poses an actual threat.

16 . The system of claim 8 , the operations comprising:

analyzing threat events used for calculating the first risk score by a trained machine learning model for determining the likelihood that the object poses an actual threat; and

generating actual threat data based on the likelihood that the object poses an actual threat.

17 . The non-transitory, computer-readable medium of claim 13 , the operations comprising:

analyzing threat events used for calculating the first risk score by a trained machine learning model for determining the likelihood that the object poses an actual threat; and

generating actual threat data based on the likelihood that the object poses an actual threat.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2023
From: DZEPAROSKA, KRISTINA; CLARK, RACHEL L.
To: THE TORONTO-DOMINION BANK
Reel/Frame 062851/0370 →
Continuity (1)
Related Publication 20240193268A1 · Jun 13, 2024
References Cited (7)
US 8744894B2 · Christiansen et al. · 2014 [cited by applicant]
US 9438626B1 · Zilberberg et al. · 2016 [cited by applicant]
US 9501647B2 · Yampolskiy et al. · 2016 [cited by applicant]
US 10375104B1 · Wu · 2019 [cited by examiner]
US 11349863B2 · Akella et al. · 2022 [cited by applicant]
US 20240095349A1 · Ozugur · 2024 [cited by examiner]
U.S. Appl. No. 18/046,748, Clark et al., filed Oct. 14, 2022. [cited by applicant]