IP Library › Granted Patent US 12,621,340
Granted Patent B2
US 12,621,340 · App. 17/861,626 · Granted May 5, 2026

Detecting and preventing malware attacks using simulated analytics and continuous authentication

Inventor: Vijay Kumar Yarabolu (Telangana, IN)
Assignee: Bank of America Corporation
H04L63/145H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,340
App. No.
17/861,626
Granted
May 5, 2026
Kind
B2
Abstract

Aspects of the disclosure relate to detecting and preventing malware attacks using simulated analytics and continuous authentication. An application server may receive device information and processing capabilities information of a client device. Based on the device information and the processing capabilities information, the application server may generate analytical output data indicating, for each transaction executed on the client device, a transaction processing time. The application server may receive transaction information associated with a transaction being executed at the client device. Based on the received transaction information and the analytical output data, the application server may simulate the transaction being executed at the client device and determine expected payload data. The application server may receive an authorization request including actual payload data associated with the transaction being executed at the client device. The application server may compare the expected payload data with the actual payload data and send an authorization response.

Claims (46)

1 . A system comprising:

a client device;

an application server; and

an application interface located between the client device and the application server, wherein the application server is configured to:

receive, via the application interface, device information of the client device;

receive, via the application interface, processing capabilities information of the client device, wherein the processing capabilities information of the client device is determined by executing simulated processing of one or more types of transactions at the client device during an enrollment process;

based on the device information and the processing capabilities information, generate analytical output data indicating, for each transaction executed on the client device, a transaction processing time, and transmit the analytical output data for storage in one or more database tables;

receive transaction information associated with a transaction being executed at the client device;

based on the received transaction information and the analytical output data, simulate the transaction being executed at the client device using a virtual representation of the client device;

determine expected payload data based on the simulation, wherein the expected payload data comprises an execution time and a data size;

receive an authorization request, wherein the authorization request includes actual payload data associated with the transaction being executed at the client device, wherein the actual payload data comprises an execution time and a data size;

compare the expected payload data with the actual payload data to determine a relative match amount or a relative match percentage;

compare the relative match amount or the relative match percentage to a match threshold to determine when the expected payload data matches the actual payload data; and

based on the comparison, send an authorization response, wherein when the expected payload data does not match the actual payload data, the authorization response comprises a notification indicating presence of malware.

2 . The system of claim 1 , wherein the analytical output data comprises a graphical visualization representing results of a simulated process.

3 . The system of claim 1 , wherein simulating the transaction being executed at the client device comprising simulating transaction steps of the transaction based on the device information and the processing capabilities information of the client device.

4 . The system of claim 1 , wherein receiving the device information of the client device comprises receiving information related to one or more of: a device type, a vendor name, a model name or number, a firmware version, a product name, a device identifier, or a processor identifier.

5 . The system of claim 1 , wherein sending the authorization response comprises sending a message indicating whether the transaction is approved or denied.

6 . The system of claim 1 , wherein receiving transaction information associated with the transaction being executed at the client device comprises receiving information indicative of a transaction type.

7 . The system of claim 1 , wherein the transaction being executed at the client device comprises a transaction initiated on the client device via a mobile application.

8 . A method comprising: at a computing platform comprising at least one processor, a communication interface, and memory:

receiving, by the at least one processor, via the communication interface, device information of a client device;

receiving, by the at least one processor, via the communication interface, processing capabilities information of the client device, wherein the processing capabilities information of the client device is determined by executing simulated processing of one or more types of transactions at the client device during an enrollment process;

based on the device information and the processing capabilities information, generating, by the at least one processor, analytical output data indicating, for each transaction executed on the client device, a transaction processing time, and transmitting the analytical output data for storage in one or more database tables;

receiving, by the at least one processor, transaction information associated with a transaction being executed at the client device using a virtual representation of the client device;

based on the received transaction information and the analytical output data, simulating, by the at least one processor, the transaction being executed at the client device;

determining, by the at least one processor, expected payload data based on the simulation, wherein the expected payload data comprises an execution time and a data size;

receiving, by the at least one processor, an authorization request, wherein the authorization request includes actual payload data associated with the transaction being executed at the client device, wherein the actual payload data comprises an execution time and a data size;

comparing, by the at least one processor, the expected payload data with the actual payload data to determine a relative match amount or a relative match percentage;

comparing the relative match amount or the relative match percentage to a match threshold to determine when the expected payload data matches the actual payload data; and

based on the comparison, sending, by the at least one processor, an authorization response, wherein when the expected payload data does not match the actual payload data, the authorization response comprises a notification indicating presence of malware.

9 . The method of claim 8 , wherein the analytical output data comprises a graphical visualization representing results of a simulated process.

10 . The method of claim 8 , wherein simulating the transaction being executed at the client device comprising simulating transaction steps of the transaction based on the device information and the processing capabilities information of the client device.

11 . The method of claim 8 , wherein receiving the device information of the client device comprises receiving information related to one or more of: a device type, a vendor name, a model name or number, a firmware version, a product name, a device identifier, or a processor identifier.

12 . The method of claim 8 , wherein sending the authorization response comprises sending a message indicating whether the transaction is approved or denied.

13 . The method of claim 8 , wherein receiving transaction information associated with the transaction being executed at the client device comprises receiving information indicative of a transaction type.

14 . One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

receive, via the communication interface, device information of a client device;

receive, via the communication interface, processing capabilities information of the client device, wherein the processing capabilities information of the client device is determined by executing simulated processing of one or more types of transactions at the client device during an enrollment process;

based on the device information and the processing capabilities information, generate analytical output data indicating, for each transaction executed on the client device, a transaction processing time, and transmit the analytical output data for storage in one or more database tables;

receive transaction information associated with a transaction being executed at the client device using a virtual representation of the client device;

based on the received transaction information and the analytical output data, simulate the transaction being executed at the client device;

determine expected payload data based on the simulation, wherein the expected payload data comprises an execution time and a data size;

receive an authorization request, wherein the authorization request includes actual payload data associated with the transaction being executed at the client device, wherein the actual payload data comprises an execution time and a data size;

compare the expected payload data with the actual payload data to determine a relative match amount or a relative match percentage;

compare the relative match amount or the relative match percentage to a match threshold to determine when the expected payload data matches the actual payload data; and based on the comparison, send an authorization response, wherein when the expected payload data does not match the actual payload data, the authorization response comprises a notification indicating presence of malware.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2022
From: YARABOLU, VIJAY KUMAR
To: BANK OF AMERICA CORPORATION
Reel/Frame 060472/0842 →
Continuity (1)
Related Publication 20240015178A1 · Jan 11, 2024
References Cited (33)
US 20050193430A1 · Cohen et al. · 2005 [cited by applicant]
US 20070016953A1 · Morris et al. · 2007 [cited by applicant]
US 20110047620A1 · Mahaffey et al. · 2011 [cited by applicant]
US 20130055404A1 · Khalili · 2013 [cited by applicant]
US 20130173782A1 · Ragutski et al. · 2013 [cited by applicant]
US 20130333037A1 · Bowen et al. · 2013 [cited by applicant]
US 20130347116A1 · Flores et al. · 2013 [cited by applicant]
US 20140189873A1 · Elder et al. · 2014 [cited by applicant]
US 20140351907A1 · Noble · 2014 [cited by examiner]
US 20160065601A1 · Gong et al. · 2016 [cited by applicant]
US 20160103838A1 · Sainani et al. · 2016 [cited by applicant]
US 20170012843A1 · Zaidi, III · 2017 [cited by examiner]
US 20170063901A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063907A1 · Muddu et al. · 2017 [cited by applicant]
US 20170078922A1 · Raleigh · 2017 [cited by examiner]
US 20170126731A1 · Vallone et al. · 2017 [cited by applicant]
US 20180343278A1 · Vallone et al. · 2018 [cited by applicant]
US 20190068616A1 · Woods et al. · 2019 [cited by applicant]
US 20200067966A1 · Irimie et al. · 2020 [cited by applicant]
US 20200128441A1 · Singh · 2020 [cited by examiner]
US 20200342106A1 · Chelarescu · 2020 [cited by examiner]
US 20210173939A1 · Kotler et al. · 2021 [cited by applicant]
US 20210266743A1 · Kvochko · 2021 [cited by examiner]
US 20210344726A1 · Sharifi Mehr · 2021 [cited by applicant]
US 20210382992A1 · Massiglia et al. · 2021 [cited by applicant]
US 20220030009A1 · Hasan · 2022 [cited by applicant]
US 20220109681A1 · Hamdi · 2022 [cited by applicant]
US 20220201042A1 · Crabtree et al. · 2022 [cited by applicant]
US 20220210200A1 · Crabtree et al. · 2022 [cited by applicant]
WO WO9916207A1 · 1999 [cited by examiner]
“5 Reasons why Digital Twins Could be the Future of Retrofitting”, ASITE, Oct. 20, 2021, downloaded from <https://asite.com/blogs/5-reasons-why-digital-twins-could-be-the-future-of-retrofitting> on Jul. 11, 2022. [cited by applicant]
“Digital Twin”, Wikipedia, downloaded from <https://en.wikipedia.org/wiki/Digital_twin> on Jul. 11, 2022. [cited by applicant]
Javier Tordable, “Doubling Down on Insights With Digital Twins”, Jun. 25, 2021, downloaded from <https://www.forbes.com/sites/googlecloud/2021/06/25/doubling-down-on-insights-with-digital-twins/> on Jul. 11, 2022. [cited by applicant]