Network Traffic Tracking System Identifies Rogue Access Patterns

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in tracking network traffic data and identifying rogue access patterns within their electronic networks, making it difficult to determine if users are accessing data in an acceptable manner.

Innovation Solution

A system comprising a memory device with computer-readable program code and at least one processing device that receives peer user accounts and data, generates relational mappings, and uses machine learning models to compare access patterns and generate an abnormality score, determining if it meets a predetermined threshold.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations track network traffic data and identify rogue access patterns, then network security is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the network security monitoring function into distinct modules: data collection module, relational mapping generation module, access pattern analysis module, and abnormality detection module. Each module processes specific aspects of network traffic data independently, making the complex security monitoring task manageable and maintainable while improving overall system reliability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a relational mapping as an intermediary structure that connects user accounts, groups, and access patterns. This intermediary layer simplifies the complexity by providing a standardized framework for comparing access patterns across different users and groups, enabling secure identification of rogue behavior without requiring direct complex analysis of all network traffic

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the system generates detailed access patterns and compares historical and current data, then detection precision is improved, but processing time increases

Engineering Contradiction:
Improvedetection precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing group relationships and historical access patterns before current analysis is needed. The relational mapping is generated in advance, and historical data is processed and stored, so that when current network traffic is analyzed, the comparison can be made efficiently without time-consuming real-time analysis of all historical data

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies local quality by focusing the detailed analysis only on specific aspects of access patterns that are most indicative of rogue behavior, such as access timing, data volume, and pattern deviations. Rather than analyzing every detail of all network traffic, the system concentrates computational resources on the most critical detection parameters, improving precision while reducing processing time

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12316660B2Systems, methods, and apparatuses for tracking network traffic data and identifying rogue access patterns in an electronic network
Publication Date: 2025.05.27 BANK OF AMERICA CORP
  • US12316660B2 patent drawing
  • US12316660B2 patent drawing
  • US12316660B2 patent drawing

AI summary

Systems, computer program products, and methods are described herein for tracking network traffic data and identifying rogue access patterns in an electronic network. The present invention is configured to receive a plurality of peer user accounts; receiving a plurality of peer user data associated with the plurality of peer user accounts; generating a relational mapping based at least on the predetermined group; and generating a plurality of peer historical data access patterns based on the plurality of peer user data over the historical predetermined period. The present invention may further be configured to receive a primary user account; receive a plurality of primary user data; generate a plurality of primary user access patterns; compare the plurality of peer historical data access patterns and the plurality of primary user access patterns to generate an abnormality score; and determine whether the abnormality score meets the abnormality threshold.