Systems and methods for network security

US12301632B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12301632-B2
Application numberUS-202318381561-A
CountryUS
Kind codeB2
Filing dateOct 18, 2023
Priority dateJun 18, 2021
Publication dateMay 13, 2025
Grant dateMay 13, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A security system for a network may be configured to detect one or more failed authentication attempts to access the network by at least one user device and determine the number of the failed authentication attempts. The system may determine a first risk score based on the number of failed authentication attempts and determine whether the first risk score is greater than or equal to a first risk score threshold and generate a first notification indicating that the user device is attempting to gain unauthorized access onto the network. The system may transmit the first notification to an administrator of the network, determine the user device is successfully authenticated to access the network after the number of failed authentication attempts has been detected, and apply a first set of network activity restrictions to the user device.

First claim

Opening claim text (preview).

What is claimed is: 1. A security system for a network, comprising: a processor; and a memory storing instructions executable by the processor, wherein, upon execution of the instructions by the processor, the processor is configured to: detect one or more failed authentication attempts to access the network by at least one user device; determine a number of the one or more failed authentication attempts; determine a first risk score for the at least one user device based on the number of the one or more failed authentication attempts and one or more factors comprising: network signal strength, network connection type, network connection location, authentication history and credential similarities; determine whether the first risk score of the at least one user device is equal to or greater than a first risk score threshold; in response to a determination that the first risk score of the at least one user device is equal to or greater than the first risk score threshold, generate a first notification indicating that the at least one user device is attempting to gain unauthorized access onto the network; determine whether the at least one user device is successfully authenticated to access the network after the number of the one or more failed authentication attempts have been detected; in response to a determination that the at least one user device is successfully authenticated to access the network after the number of the one or more failed authentication attempts have been detected, apply a first set of network activity restrictions to the at least one user device, such that the at least one user device has access to the network under the first set of network activity restrictions that limits network activities that can be performed by the at least one device, monitor network activities of the at least one user device when the at least one user device is accessing the network under the first set of network activity restriction; generate a second notification indicating one or more network activities relating to the at least the one user device; and transmit, via the network, the second notification to a recipient, wherein the monitored network activities of the at least one user device include at least one selected from the group of downloading a large amount of data, exporting a large amount of data outside of the network, visiting an unexpected website, or visiting a restricted website. 2. The security system of claim 1 , wherein the processor is further configured to transmit the first notification to an administrator of the network. 3. The security system of claim 1 , wherein the processor is further configured to determine a second risk score for the at least one user device based on the monitored network activities. 4. The security system of claim 3 , wherein the processor is further configured to determine whether the second risk score is equal to or greater than a second risk score threshold. 5. The security system of claim 4 , wherein the processor is further configured to, when the second risk score is determined to be equal to or greater than the second risk score threshold, apply a second set of network activity restrictions to the at least one user device, such that the at least one user device is restricted to access the network under the second set of network activity restrictions. 6. The security system of claim 5 , wherein the second notification indicates that the at least one user device is performing unusual network activities on the network. 7. The security system of claim 6 , wherein the recipient comprises the administrator of the network. 8. The security system of claim 3 , wherein the machine learning algorithm determines the first risk score based on one or more of a network signal strength, a network connection type, a network connection location of the user device, an authentication history of the user device, or a credential similarities between the failed authentication attempts. 9. The security system of claim 1 , wherein the processor is further configured to apply a machine learning algorithm to determine the first risk score. 10. A method for network security, comprising: detecting, by a server, one or more failed authentication attempts to access a network by at least one user device; determining, by the server, a number of the one or more failed authentication attempts; determining, by the server, a first risk score for the at least one user device based on the number of the one or more failed authentication attempts and one or more factors comprising: network signal strength, network connection type, network connection location, authentication history and credential similarities; determining, by the server, whether the first risk score of the at least one user device is equal to or greater than a first risk score threshold; in response to a determination that the first risk score of the at least one user device is equal to or greater than the first risk score threshold, generating, by the server, a first notification indicating that the at least one user device is attempting to gain unauthorized access onto the network; determining, by the server, whether the at least one user device is successfully authenticated to access the network after the number of the one or more failed authentication attempts have been detected; in response to a determination that the at least one user device is successfully authenticated to access the network after the number of the one or more failed authentication attempts have been detected, applying, by the server, a first set of network activity restrictions to the at least one user device, such that the at least one user device has access to the network under the first set of network activity restrictions that limits network activities that can be performed by the at least one device, monitoring, by the server, network activities of the at least one user device when the at least one user device is accessing the network under the first set of network activity restrictions; generate a second notification indicating one or more network activities relating to the at least the one user device; and transmit, via the network, the second notification to a recipient, wherein the monitored network activities of the at least one user device include at least one selected from the group of downloading a large amount of data, exporting a large amount of data outside of the network, visiting an unexpected website, or visiting a restricted website. 11. The method of claim 10 , comprising: determining, by the server, a second risk score for the at least one user device based on the monitored network activities; determining, by the server, whether the second risk score is equal to or greater than a second risk score threshold; and when the second risk score is determined to be equal to or greater than the second risk score threshold, applying, by the server, a second set of network activity restrictions to the at least one user device, such that the at least one user device is restricted to access the network under the second set of network activity restrictions. 12. The method of claim 11 , wherein the second set of network activity restrictions includes disconnecting the at least one user device from the network. 13. The method of claim 10 , wherein the first set of network activity restrictions include at least one selected from the group of reducing network connection speed of the at least one user device, restricting Internet protocol (IP) addresses that the at least one user is allowed to ping, and limiting ability of the at least one user device to adjust settings of the ne

Assignees

Inventors

Classifications

  • H04W12/08Primary

    Access security · CPC title

  • Hardware identity · CPC title

  • Authentication · CPC title

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12301632B2 cover?
A security system for a network may be configured to detect one or more failed authentication attempts to access the network by at least one user device and determine the number of the failed authentication attempts. The system may determine a first risk score based on the number of failed authentication attempts and determine whether the first risk score is greater than or equal to a first ris…
Who is the assignee on this patent?
Capital One Services Llc
What technology area does this patent fall under?
Primary CPC classification H04W12/08. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 13 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).