IP Library › Granted Patent US 12,726,502
Granted Patent B2
US 12,726,502 · App. 19/062,219 · Granted Sep 1, 2026

Event to action and activity correlation system

Inventors: Steven Sinks (Scottsdale, AZ); Joshua Abraham (Sharon, MA)
Assignee: Bank of America Corporation
H04L63/1425H04L63/1416H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,726,502
App. No.
19/062,219
Granted
Sep 1, 2026
Kind
B2
Abstract

Methods may detect, terminate and prevent nefarious actions within a computing network. Methods may mine, track and store a data set comprising patterns of normal user activity. Normal user activity may include login times, data access requests per unit time and self-generated network traffic volume per unit time. Methods may create a frequency baseline corresponding to a pattern of normal activity for each user. Methods may monitor the system for deviations in access frequency within the established baseline. Upon identification of deviations, methods may create a security incident and/or electronically relocate a user associated with the security incident within a secured sandbox environment.

Claims (52)

1 . A method for detecting, terminating and preventing nefarious actions within a computing network, said computing network comprising a hardware processor and a hardware memory, the method comprising:

mining, tracking and storing a big data set comprising patterns of normal user activity, said normal user activity comprising login times, data access requests per unit time and self-generated network traffic volume per unit time;

creating/establishing a frequency baseline for each user within the system, the frequency baseline corresponding to a pattern of normal activity for each user, said frequency baseline comprising network and application utilization volumes;

monitoring, using artificial intelligence and a singular source of correlation, the system for deviations in access frequency within the established baseline, the deviations comprising:

atypical spikes/declines in file use;

atypical spikes/declines in application use;

anomalies including utilization occurring at irregular times;

anomalies including utilization occurring across geographically distant locations in a less than a predetermined time period;

 upon identification of one or more of the deviations comprising atypical spikes/declines in file use, atypical spikes/declines in application use, anomalies including utilization occurring at irregular time and anomalies including utilization occurring across geographically distant locations in less than a predetermined time period, creating a signal for a potential security incident or insider threat;

 in response to creating the signal, electronically relocating a user associated with the security incident within a secured sandbox environment; and

 for a first user within the plurality of users:

electronically translating the baseline frequency into a baseline frequency trendline; and

electronically translating current usage of first user into a current frequency trendline;

electronically comparing the current frequency trendline to the baseline frequency trendline to confirm the deviations for the first user;

 wherein the deviations from the established baseline further comprise a significantly greater than the baseline access frequency to sensitive files.

2 . The method of claim 1 wherein the deviations from the established baseline further comprises anomalous baseline login locations.

3 . The method of claim 1 wherein the deviations from the established baseline further comprises detecting unusual spending patterns.

4 . The method of claim 3 wherein the unusual spending patterns include sudden increases in specific spending categories.

5 . The method of claim 3 wherein the unusual spending patterns include repeated transactions of less than a predetermined transaction amount.

6 . The method of claim 3 wherein:

the deviations from the established baseline further comprise greater than a predetermined number of login attempts; and

the deviations from the established baseline classify an account associated with the predetermined number of login attempts as a compromised account.

7 . The method of claim 3 wherein the deviations from the established baseline further comprises a quantity of transactions or quality of transactions that are greater than and/or less than abnormal user activity, abnormal withdrawal activity and/or abnormal deposit activity.

8 . A system for detecting, terminating and preventing nefarious actions within a computing network, the system comprising:

a hardware memory; and

a hardware processor, the hardware processor operable to:

mine a continually updating big data set comprising patterns of normal user activity pertaining to a plurality of users, said normal user activity comprising user login times, user data access requests per unit time and user self-generated network traffic volume per unit time;

track, from the big data set, for each user included in the plurality of users, a pattern of tracked normal user activity pertaining to the user;

create a frequency baseline for each user, the frequency baseline corresponding to the pattern of tracked normal user activity, said frequency baseline comprising:

spikes and declines in application utilization volume;

spikes and declines in file use;

spikes and declines in geographic locations of resource utilization;

time ranges of application utilization; and

time ranges of file use;

continually monitor, using artificial intelligence and a singular source of correlation, each user's usage within the continually updating big data set for deviations in frequencies between each user's established baseline and each user's continually monitored usage within the continually updating big data set;

upon identification of one or more greater than threshold deviations from the frequency baseline for a first user included in the plurality of users, creating a sandbox environment for the first user, said sandbox environment preventing the first user from accessing data labeled above a threshold security level;

wherein the atypical spikes/declines in application use are:

identified for each user by electronically comparing a baseline frequency trendline, translated from the baseline frequency of each user, to a current frequency trendline, translated from a current usage of each user; and

wherein the deviations from the established baseline further comprise a significantly greater than the baseline access frequency to sensitive files.

9 . The system of claim 8 , wherein the deviations comprise:

atypical spikes/declines in file use;

atypical spikes/declines in application use;

anomalies including utilization occurring at irregular times; and

anomalies including utilization occurring across geographically distant locations in a less than a predetermined time period.

10 . The system of claim 9 wherein the deviations further comprise anomalous baseline login locations.

11 . The system of claim 9 wherein the deviations further comprise unusual spending patterns.

12 . The system of claim 11 wherein the unusual spending patterns includes sudden increases in specific spending categories.

13 . The system of claim 11 wherein the unusual spending patterns include repeated transactions of less than a predetermined transaction amount.

14 . The system of claim 11 wherein:

the deviations further comprise greater than a predetermined number of login attempts; and

the deviations classify an account associated with the predetermined number of login attempts as a compromised account.

15 . The system of claim 11 wherein the deviations further comprise a quantity of transactions or quality of transactions that are greater than and/or less than abnormal user activity, abnormal withdrawal activity and/or abnormal deposit activity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2025
From: SINKS, STEVEN; ABRAHAM, JOSHUA
To: BANK OF AMERICA CORPORATION
Reel/Frame 070316/0648 →
Continuity (1)
Related Publication 20260254826A1 · Aug 27, 2026
References Cited (8)
US 10922210B2 · Richardson · 2021 [cited by examiner]
US 11055405B1 · Jin · 2021 [cited by examiner]
US 11277423B2 · Brown · 2022 [cited by applicant]
US 20180027006A1 · Zimmermann · 2018 [cited by examiner]
US 20190026632A1 · Natsumeda · 2019 [cited by applicant]
US 20190207969A1 · Brown · 2019 [cited by examiner]
US 20200285997A1 · Bhattacharyya · 2020 [cited by examiner]
EP 3531329 · 2019 [cited by applicant]