Preventing unauthorized access to secure information systems using advanced pre-authentication techniques

US10965675B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10965675-B2
Application numberUS-201815920549-A
CountryUS
Kind codeB2
Filing dateMar 14, 2018
Priority dateMar 14, 2018
Publication dateMar 30, 2021
Grant dateMar 30, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Aspects of the disclosure relate to preventing unauthorized access to secured information systems using advanced pre-authentication techniques. A computing platform may receive, from a local traffic manager, a first enriched access request associated with a first remote computing device. Then, the computing platform may apply a pre-authentication classification model to the first enriched access request associated with the first remote computing device. Thereafter, the computing platform may determine that the first enriched access request associated with the first remote computing device is likely malicious. Then, the computing platform may generate one or more first pre-authentication response commands directing client portal server infrastructure to process the first enriched access request associated with the first remote computing device as a malicious request. Subsequently, the computing platform may send the one or more first pre-authentication response commands to the client portal server infrastructure.

First claim

Opening claim text (preview).

What is claimed is: 1. A computing platform, comprising: at least one processor; a communication interface communicatively coupled to the at least one processor; and memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: receive, via the communication interface, from a local traffic manager, a first enriched access request associated with a first remote computing device; based on receiving the first enriched access request associated with the first remote computing device from the local traffic manager, apply a pre-authentication classification model to the first enriched access request associated with the first remote computing device; based on applying the pre-authentication classification model to the first enriched access request associated with the first remote computing device, determine that the first enriched access request associated with the first remote computing device is likely malicious; based on determining that the first enriched access request associated with the first remote computing device is likely malicious, generate one or more first pre-authentication response commands directing client portal server infrastructure to process the first enriched access request associated with the first remote computing device as a malicious request; and send, via the communication interface, to the client portal server infrastructure, the one or more first pre-authentication response commands directing the client portal server infrastructure to process the first enriched access request associated with the first remote computing device as a malicious request, wherein receiving the first enriched access request associated with the first remote computing device from the local traffic manager comprises receiving, from the local traffic manager, one or more hypertext transfer protocol (HTTP) headers originating from a first access request received by the local traffic manager from the first remote computing device and additional enrichment information generated by the local traffic manager based on the first access request received by the local traffic manager from the first remote computing device, and wherein applying the pre-authentication classification model to the first enriched access request associated with the first remote computing device comprises: using a dependent probability machine learning model to calculate a probability that the first enriched access request associated with the first remote computing device is likely malicious based on the one or more HTTP headers originating from the first access request received by the local traffic manager from the first remote computing device and based on the additional enrichment information generated by the local traffic manager; and based on the probability calculated using the dependent probability machine learning model exceeding a predetermined threshold, determining that the first enriched access request associated with the first remote computing device is likely malicious. 2. The computing platform of claim 1 , wherein sending the one or more first pre-authentication response commands directing the client portal server infrastructure to process the first enriched access request associated with the first remote computing device as a malicious request causes the client portal server infrastructure to deny access to the first remote computing device. 3. The computing platform of claim 1 , wherein sending the one or more first pre-authentication response commands directing the client portal server infrastructure to process the first enriched access request associated with the first remote computing device as a malicious request causes the client portal server infrastructure to connect the first remote computing device to a honeypot site in which actual user account information is not accessible. 4. The computing platform of claim 1 , wherein sending the one or more first pre-authentication response commands directing the client portal server infrastructure to process the first enriched access request associated with the first remote computing device as a malicious request causes the client portal server infrastructure to throttle communications associated with the first remote computing device. 5. The computing platform of claim 1 , wherein sending the one or more first pre-authentication response commands directing the client portal server infrastructure to process the first enriched access request associated with the first remote computing device as a malicious request causes the client portal server infrastructure to require step-up authentication credentials from the first remote computing device. 6. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: prior to receiving the first enriched access request associated with the first remote computing device from the local traffic manager: receive a known legitimate request reference dataset comprising HTTP header information associated with verified legitimate requests; receive a known malicious request reference dataset comprising HTTP header information associated with verified malicious requests; generate the pre-authentication classification model based on the known legitimate request reference dataset and the known malicious request reference dataset; and store the pre-authentication classification model generated based on the known legitimate request reference dataset and the known malicious request reference dataset. 7. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: after sending the one or more first pre-authentication response commands to the client portal server infrastructure, update the pre-authentication classification model based on determining that the first enriched access request associated with the first remote computing device is likely malicious. 8. The computing platform of claim 7 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: receive, via the communication interface, from the local traffic manager, a second enriched access request associated with a second remote computing device; based on receiving the second enriched access request associated with the second remote computing device from the local traffic manager, apply the pre-authentication classification model to the second enriched access request associated with the second remote computing device; based on applying the pre-authentication classification model to the second enriched access request associated with the second remote computing device, determine that the second enriched access request associated with the second remote computing device is likely not malicious; based on determining that the second enriched access request associated with the second remote computing device is likely not malicious, generate one or more second pre-authentication response commands directing the client portal server infrastructure to process the second enriched access request associated with the second remote computing device as a legitimate request; and send, via the communication interface, to the client portal server infrastructure, the one or more second pre-authentication response commands directing the client portal server infrastructure to process the second enriched access request associated with the second remote computing device as a legitimate request. 9. A method, comprising: at a com

Assignees

Inventors

Classifications

  • Traffic logging, e.g. anomaly detection · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • using deception as countermeasure, e.g. honeypots, honeynets, decoys or entrapment · CPC title

  • H04L63/10Primary

    for controlling access to devices or network resources · CPC title

  • Event detection, e.g. attack signature detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10965675B2 cover?
Aspects of the disclosure relate to preventing unauthorized access to secured information systems using advanced pre-authentication techniques. A computing platform may receive, from a local traffic manager, a first enriched access request associated with a first remote computing device. Then, the computing platform may apply a pre-authentication classification model to the first enriched acces…
Who is the assignee on this patent?
Bank Of America
What technology area does this patent fall under?
Primary CPC classification H04L63/10. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 30 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).