IP Library › Granted Patent US 12,743,517
Granted Patent B2
US 12,743,517 · App. 18/895,529 · Granted Sep 22, 2026

Steganographic modification detection and mitigation for enhanced enterprise security

Inventors: Matthew Murray (Roanoke, TX); Garrett Botkin (Charlotte, NC); Dustin Stocks (Stallings, NC)
Assignee: Bank of America Corporation
G06F21/568G06F21/53G06F21/566G06T7/90G06T2207/10024
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,743,517
App. No.
18/895,529
Granted
Sep 22, 2026
Kind
B2
Abstract

Aspects of the disclosure relate to mitigation and detection of steganographic modifications embedded in images. A computing platform may receive an image embedded with steganographic modifications. The computing platform may change or modify any number of bits of one or more color components of one or more pixels of an image, rendering the steganographic modifications ineffective. The computing platform may cause at an isolation zone system, execution of an image, including steganographic modifications, to identify images embedded with steganographic modifications. The computing platform may also compare an image with image stored in an image storage module. The computing platform may store an image from the image storage module with a highest visual comparison score rather than the image.

Claims (62)

1 . A computing platform, comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

a memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

generate a copy of a first image, embedded with steganographic modifications comprising modifications to one or bits of a plurality of pixels of the first image, wherein the steganographic modifications comprise malicious software;

generate a safe first image of the copy of the first image by changing or modifying one or more bits beginning from a least significant bit of at least one pixel of the copy of the first image, wherein generating the safe first image of the copy of the first image renders the steganographic modifications ineffective, wherein generating the safe first image comprises inverting bit values of one or more bits beginning from a least significant bit of at least one color component of a plurality of pixels of the copy of the first image by:

changing bits with a 0 value to a 1 value, and

changing bits with a 1 value to a 0 value;

route the safe first image to an isolation zone system;

based on receiving an indication from the isolation zone system indicating that the safe first image remains embedded with effective steganographic modifications, modify the safe first image by inverting an increased number of bits beginning from a least significant bit of at least one color component of a plurality of pixels of the safe first image until a presence of the effective steganographic modifications is no longer detected;

after identifying that the presence of the effective steganographic modifications is no longer detected, route the safe first image to a first user device;

route the first image to the isolation zone system; and

perform, based on results of execution of the steganographic modifications of the first image in the isolation zone system, one or more security actions.

2 . The computing platform of claim 1 , wherein the one or more security actions comprise:

flagging an outside source of the first image as a malicious entity.

3 . The computing platform of claim 2 , wherein embedding the first image with the steganographic modifications comprises accessing a stored image at the computing platform, and modifying the stored image through steganography.

4 . The computing platform of claim 2 , wherein embedding the first image with the steganographic modifications comprises directing the computing platform to store an image with steganographic modifications.

5 . The computing platform of claim 1 , wherein the steganographic modifications embedded in the first image comprise modifications to one or more color components of the plurality of pixels.

6 . The computing platform of claim 5 , wherein the safe first image is generated by changing or modifying at least one of four bits beginning from a least significant bit of at least one color component of all pixels of the first image.

7 . The computing platform of claim 1 , wherein the memory stores computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

store the safe first image rather than the first image.

8 . The computing platform of claim 1 , wherein routing the safe first image to the first user device is responsive to receiving a request from the first user device to view the first image.

9 . The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

receive a third image;

compare the third image to a plurality of stored verified images;

identify that the third image matches an image from the plurality of stored verified images;

store the identified image rather than the third image, wherein storing the identified image rather than the third image renders any steganographic modifications of the third image ineffective; and

route the identified image to the first user device based on a request from the first user device to view the third image.

10 . The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

receive the first image.

11 . The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

automatically cause, at the isolation zone system through one or more commands directing the isolation zone system to execute the steganographic modifications of the first image, execution of the steganographic modifications of the first image.

12 . A method comprising:

at a computing platform, the computing platform having at least one processor and memory:

generating a copy of a first image, embedded with steganographic modifications comprising modifications to one or bits of a plurality of pixels of the first image, wherein the steganographic modifications comprise malicious software;

generating a safe first image of the copy of the first image by changing or modifying one or more less significant bits of at least one pixel of the copy of the first image, wherein generating the safe first image of the copy of the first image renders the steganographic modifications ineffective, wherein generating the safe first image comprises inverting bit values of one or more bits beginning from a least significant bit of at least one color component of a plurality of pixels of the copy of the first image by:

changing bits with a 0 value to a 1 value, and

changing bits with a 1 value to a 0 value;

routing the safe first image to an isolation zone system;

based on receiving an indication from the isolation zone system indicating that the safe first image remains embedded with effective steganographic modifications, modifying the safe first image by inverting an increased number of bits beginning from a least significant bit of at least one color component of a plurality of pixels of the safe first image until a presence of the effective steganographic modifications is no longer detected;

after identifying that the presence of the effective steganographic modifications is no longer detected, routing the safe first image to a first user device;

routing the first image to the isolation zone system; and

performing, based on results of execution of the steganographic modifications of the first image in the isolation zone system, one or more security actions.

13 . The method of claim 12 , wherein the one or more security actions comprises:

flagging an outside source of the first image as malicious entity.

14 . The method of claim 13 , wherein embedding the first image with steganographic modifications comprises accessing a stored image at the computing platform, and modifying the stored image through steganography.

15 . The method of claim 14 , wherein embedding the first image with the steganographic modifications comprises directing the computing platform to store an image with the steganographic modifications.

16 . The method of claim 12 , wherein the steganographic modifications embedded in the first image comprise modifications to one or more color components of the plurality of pixels.

17 . The method of claim 16 , wherein the safe first image is generated by changing or modifying at least one of four bits beginning from a least significant bit of at least one color component of all pixels of the first image.

18 . One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, memory, and a communication interface, cause the computing platform to:

generate a copy of a first image, embedded with steganographic modifications comprising modifications to one or bits of a plurality of pixels of the first image, wherein the steganographic modifications comprise malicious software;

generate a safe first image by changing or modifying one or more bits beginning from a least significant bit of at least one pixel of the copy of the first image, wherein generating the safe first image of the copy of the first image renders the steganographic modifications ineffective;, wherein generating the safe first image comprises inverting bit values of one or more bits beginning from a least significant bit of at least one color component of a plurality of pixels of the copy of the first image by:

changing bits with a 0 value to a 1 value, and

changing bits with a 1 value to a 0 value;

route the safe first image to an isolation zone system;

based on receiving an indication from the isolation zone system indicating that the safe first image remains embedded with effective steganographic modifications, modify the safe first image by inverting an increased number of bits beginning from a least significant bit of at least one color component of a plurality of pixels of the safe first image until a presence of the effective steganographic modifications is no longer detected;

after identifying that the presence of the effective steganographic modifications is no longer detected, route the safe first image to a first user device;

route the first image to an isolation zone system; and

perform, based on results of execution of the steganographic modifications of the first image in the isolation zone system, one or more security actions.

19 . The computing platform of claim 9 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

identify that a visual comparison score, assigned to the identified image, meets or exceeds a minimum visual comparison threshold score, wherein storing the identified image rather than the third image is further in response to identifying that the visual comparison score meets or exceeds the minimum visual comparison threshold score.

20 . The computing platform of claim 1 , wherein routing the first safe image to the isolation zone system includes sending commands directing the isolation zone system to execute the first safe image over a duration of time to identify latent malicious software that is not immediately identifiable upon execution of the first safe image.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2024
From: MURRAY, MATTHEW; BOTKIN, GARRETT; STOCKS, DUSTIN
To: BANK OF AMERICA CORPORATION
Reel/Frame 068691/0855 →
Continuity (2)
Continuation 17872354 · Jul 25, 2022
Related Publication 20250013749A1 · Jan 9, 2025
References Cited (58)
US 5613004A · Cooperman · 1997 [cited by examiner]
US 6831991B2 · Fridrich · 2004 [cited by examiner]
US 7970166B2 · Carr · 2011 [cited by examiner]
US 8745742B1 · Satish · 2014 [cited by examiner]
US 9647846B1 · Schulman · 2017 [cited by examiner]
US 10270790B1 · Jackson · 2019 [cited by examiner]
US 10360354B1 · Easttom, II · 2019 [cited by applicant]
US 10366165B2 · Devkar et al. · 2019 [cited by applicant]
US 10366222B2 · Daly · 2019 [cited by examiner]
US 10467208B1 · Easttom, II · 2019 [cited by applicant]
US 10489874B2 · Chandorkar · 2019 [cited by applicant]
US 10491574B1 · Jung et al. · 2019 [cited by applicant]
US 10560599B2 · Holub et al. · 2020 [cited by applicant]
US 10586055B2 · Boutnaru · 2020 [cited by examiner]
US 10706160B1 · Mohapatra · 2020 [cited by applicant]
US 10769265B2 · Daly et al. · 2020 [cited by applicant]
US 10771440B2 · Wu · 2020 [cited by examiner]
US 10834289B2 · Boshoff et al. · 2020 [cited by applicant]
US 10853456B1 · Crawforth · 2020 [cited by examiner]
US 10909649B2 · Yoon · 2021 [cited by examiner]
US 10949392B2 · Boutnaru · 2021 [cited by applicant]
US 11050591B2 · Nikitin · 2021 [cited by applicant]
US 11057192B2 · Zheng et al. · 2021 [cited by applicant]
US 11200316B2 · Gehtman et al. · 2021 [cited by applicant]
US 11295029B1 · Greenblatt · 2022 [cited by examiner]
US 11295300B2 · Lieberman et al. · 2022 [cited by applicant]
US 11361075B1 · Singh · 2022 [cited by examiner]
US 11388310B2 · Mendonca Da Silva Goncalves et al. · 2022 [cited by applicant]
US 11557227B2 · Sanchez · 2023 [cited by examiner]
US 11681801B2 · Gehtman · 2023 [cited by examiner]
US 20030026447A1 · Fridrich · 2003 [cited by examiner]
US 20060239502A1 · Petrovic · 2006 [cited by examiner]
US 20070074026A1 · Hicks · 2007 [cited by examiner]
US 20100191602A1 · Mikkelsen · 2010 [cited by examiner]
US 20130042294A1 · Colvin · 2013 [cited by examiner]
US 20150047037A1 · Wood · 2015 [cited by examiner]
US 20150242981A1 · Reed · 2015 [cited by examiner]
US 20170033837A1 · McCormack · 2017 [cited by examiner]
US 20170126631A1 · Vikramaratne · 2017 [cited by examiner]
US 20170169737A1 · Probert · 2017 [cited by examiner]
US 20180349400A1 · Boutnaru · 2018 [cited by examiner]
US 20180351969A1 · MacLeod · 2018 [cited by examiner]
US 20190130117A1 · Boutnaru · 2019 [cited by examiner]
US 20200226254A1 · Gehtman · 2020 [cited by examiner]
US 20200226255A1 · Gehtman · 2020 [cited by examiner]
US 20210006591A1 · Akuka · 2021 [cited by examiner]
US 20210042410A1 · Gehtman · 2021 [cited by examiner]
US 20210192019A1 · Lwowski · 2021 [cited by examiner]
US 20220164247A1 · Mead · 2022 [cited by examiner]
US 20220173899A1 · Low · 2022 [cited by examiner]
US 20230231872A1 · MacLeod · 2023 [cited by examiner]
US 20230356539A1 · Osborn · 2023 [cited by examiner]
US 20230362012A1 · Osborn · 2023 [cited by examiner]
US 20230362013A1 · Osborn · 2023 [cited by examiner]
US 20240104681A1 · Kishore · 2024 [cited by examiner]
Wojciech Mazurczyk and Luca Caviglione; Steganography in Modern Smartphones and Mitigation Techniques: IEEE: Year:2014; pp. 334-357. [cited by examiner]
Shadi Elshare, “Modified Multi-Level Steganography to Enhance data security” Researchgate, Year 2018, pp. 509-525. [cited by applicant]
Aug. 7, 2024—(US) Notice of Allowance—U.S. Appl. No. 17/872,354. [cited by applicant]