IP Library Granted Patent US 12,647,437
Granted Patent B1
US 12,647,437 · App. 17/993,482 · Granted Jun 2, 2026

Detection of anomalous activity of components of external computing systems

Inventors: Daniel Fricano (San Francisco, CA); Cheng Tcha Vue (San Francisco, CA); Robert I. Kirby (Charlotte, NC); Shawn Wallis (Fremont, CA); John Finn (Moorsville, NC); Shane Dale Cross (Matthews, NC)
Assignee: Wells Fargo Bank, N.A.
H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,437
App. No.
17/993,482
Granted
Jun 2, 2026
Kind
B1
Abstract

Systems and methods for monitoring particular communication interfaces linked with external computing systems are provided. The system includes a processing circuit configured to establish a communication interface compatible with a communication protocol of an external computing system. The processing circuit is configured to receive first data identifying a transmission by the communication interface with the external computing system. The processing circuit ingests the first data identifying the transmission based on a parameter to authorize the communication protocol to include second data indicative of the transmission and compatible with the communication protocol. The processing circuit identifies, in response to a determination based on the parameter that the transmission satisfies a threshold corresponding to the parameter, an anomaly state of the transmission by the communication interface. The processing circuit traces, based on the anomaly state, a source of the anomaly state at the external computing system.

Claims (37)

1 . A system for monitoring particular communication interfaces linked with external computing systems, the system comprising:

memory and one or more processors configured to:

establish a communication interface compatible with a communication protocol of an external computing system and configured to receive first data identifying a transmission by the communication interface with the external computing system, wherein the first data is a token identifier that identifies the transmission;

ingest the first data identifying the transmission based on a parameter of the external computing system to authorize the communication protocol to include second data indicative of at least one of a type of the transmission or a time of the transmission and compatible with the communication protocol;

identify, in response to a determination based on the parameter that the transmission satisfies a threshold corresponding to the parameter, an anomaly state of the transmission by the communication interface;

identify an anomaly metric of the anomaly state, the anomaly metric corresponding to a particular bitrate of transmission activity from the external computing system; and

trace, based on the anomaly metric, a source of the anomaly state at the external computing system.

2 . The system of claim 1 , wherein the memory and one or more processors are further configured, in response to receiving the parameter from the external computing system, to configure the communication interface to be compatible with the communication protocol.

3 . The system of claim 1 , wherein the memory and one or more processors are further configured, in response to authorization by the external computing system to transmit the first data identifying the transmission, to ingest third data compatible with the parameter.

4 . The system of claim 1 , wherein the one or more processors are further configured to generate a report comprising the transmission activity and remediation actions.

5 . The system of claim 1 , wherein the parameter is established based on verifying a unique identifier, the unique identifier comprising at least one of internet protocol (IP) information, a domain name, application, service, daemon, or circuit identification (ID) of the external computing system.

6 . The system of claim 5 , wherein the unique identifier is compatible with at least one of a database of the system, firewall policy, or router interface.

7 . The system of claim 1 , wherein the anomaly state is based on a type of one or more of the first data and the second data.

8 . The system of claim 1 , wherein the anomaly state of at least one of the first data or the second data is based on at least one of historical first data or historical second data transmitted between an entity and the external computing system.

9 . The system of claim 1 , wherein identification of the anomaly state further comprises matching of at least one of the first data or the second data with attributes of the external computing system.

10 . A method for monitoring particular communication interfaces linked with external computing systems, the method comprising memory and one or more processors configured to:

establish a communication interface compatible with a communication protocol of an external computing system and configured to receive first data identifying a transmission by the communication interface with the external computing system, wherein the first data is a token identifier that identifies the transmission;

ingest the first data identifying the transmission based on a parameter of the external computing system to authorize the communication protocol to include second data indicative of at least one of a type of the transmission or a time of the transmission and compatible with the communication protocol;

identify, in response to a determination based on the parameter that the transmission satisfies a threshold corresponding to the parameter, an anomaly state of the transmission by the communication interface;

identify an anomaly metric of the anomaly state, the anomaly metric corresponding to a particular bitrate of transmission activity from the external computing system; and

trace, based on the anomaly metric, a source of the anomaly state at the external computing system.

11 . The method of claim 10 , wherein the memory and one or more processors are further configured, in response to receiving the parameter from the external computing system, to configure the communication interface to be compatible with the communication protocol.

12 . The method of claim 10 , wherein the memory and one or more processors are further configured, in response to authorization by the external computing system to transmit the first data identifying the transmission, to ingest third data compatible with the parameter.

13 . The method of claim 10 , wherein the communication interface is compatible with a privileged connection having a restricted metric.

14 . The method of claim 10 , wherein the parameter is established based on verifying a unique identifier, the unique identifier comprising at least one of internet protocol (IP) information, a domain name, application, service, daemon, or circuit identification (ID) of the external computing system.

15 . The method of claim 14 , wherein the unique identifier is compatible with at least one of a database, firewall policy, or router interface.

16 . The method of claim 10 , wherein the anomaly state is based on data volume predetermined by at least one of a type of at least one of the first data or the second data, or a service agreement established with an entity managing the external computing system.

17 . The method of claim 10 , wherein the anomaly state of at least one of the first data or the second data is based on at least one of historical first data or historical second data transmitted between an entity and the external computing system.

18 . The method of claim 10 , wherein identification of the anomaly state further comprises matching at least one of the first data or the second data with attributes of the external computing system.

19 . A non-transitory computer-readable medium including one or more instructions stored thereon and executable by a processor to:

establish a communication interface compatible with a communication protocol of an external computing system and configured to receive first data identifying a transmission by the communication interface with the external computing system, wherein the first data is a token identifier that identifies the transmission;

ingest the first data identifying the transmission based on a parameter of the external computing system to authorize the communication protocol to include second data indicative of at least one of a type of the transmission or a time of the transmission and compatible with the communication protocol;

identify, in response to a determination based on the parameter that the transmission satisfies a threshold corresponding to the parameter, an anomaly state of the transmission by the communication interface;

identify an anomaly metric of the anomaly state, the anomaly metric corresponding to a particular bitrate of transmission activity from the external computing system; and

trace, based on the anomaly metric, a source of the anomaly state at the external computing system.

20 . The non-transitory computer-readable medium of claim 19 , wherein the non-transitory computer-readable medium further includes one or more instructions executable by the processor to:

match at least one of the first data or the second data with attributes of the external computing system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2026
From: FRICANO, DANIEL; VUE, CHENG TCHA; FINN, JOHN; CROSS, SHANE D.
To: WELLS FARGO BANK, N.A.
Reel/Frame 074295/0490 →
References Cited (32)
US 7188150B2 · Grueneberg et al. · 2007 [cited by applicant]
US 7769877B2 · Mcbride et al. · 2010 [cited by applicant]
US 8171538B2 · El Husseini et al. · 2012 [cited by applicant]
US 8608487B2 · Huie et al. · 2013 [cited by applicant]
US 10142364B2 · Baukes et al. · 2018 [cited by applicant]
US 10282712B2 · Devan et al. · 2019 [cited by applicant]
US 10362117B1 · Nelson · 2019 [cited by applicant]
US 10897472B1 · Viglione · 2021 [cited by applicant]
US 20060212407A1 · Lyon · 2006 [cited by applicant]
US 20120311691A1 · Karlin et al. · 2012 [cited by applicant]
US 20160234232A1 · Poder et al. · 2016 [cited by applicant]
US 20170099210A1 · Fardid et al. · 2017 [cited by applicant]
US 20170230410A1 · Hassanzadeh · 2017 [cited by examiner]
US 20180091547A1 · St. Pierre · 2018 [cited by applicant]
US 20180316705A1 · Tsironis · 2018 [cited by examiner]
US 20190020667A1 · Parker · 2019 [cited by examiner]
US 20190334934A1 · Teshome · 2019 [cited by examiner]
US 20200067948A1 · Baradaran · 2020 [cited by examiner]
US 20200357067A1 · Kreider et al. · 2020 [cited by applicant]
US 20200358813A1 · Hasumi et al. · 2020 [cited by applicant]
US 20210272066A1 · Bratman · 2021 [cited by examiner]
US 20220239676A1 · Demopoulos · 2022 [cited by examiner]
US 20220400400A1 · Gloanec et al. · 2022 [cited by applicant]
US 20230007018A1 · Levy · 2023 [cited by examiner]
US 20230283629A1 · Boyer · 2023 [cited by examiner]
US 20240015183A1 · Bahirat · 2024 [cited by applicant]
CN 102484806A · 2012 [cited by applicant]
CN 104320297A · 2015 [cited by applicant]
JP 2007043483A · 2007 [cited by applicant]
WO WO2018003919A1 · 2018 [cited by applicant]
WO WO2021245854A1 · 2021 [cited by applicant]
Opara & Marchewka, “Enterprise Integrated Security Platform: A Comparision of Remote Access And Extranet Virtual Private Networks,” Journal of International Technology and Information Management 15(2):3, 11 pages (2016). [cited by applicant]