US 12,395,512 B2
Detecting data exfiltration and compromised user accounts in a computing network
Kenneth A. Kaye, Highlands Ranch, CO (US); Nikhil Sanil, Tega Cay, SC (US); Dipika Joshi, Waxhaw, NC (US); Colin Murphy, Charlotte, NC (US); and Satyanarayana R. Mandapati, Charlotte, NC (US)
Assigned to Bank of America Corporation, Charlotte, NC (US)
Filed by Bank of America Corporation, Charlotte, NC (US)
Filed on Mar. 22, 2024, as Appl. No. 18/613,728.
Application 18/613,728 is a continuation of application No. 17/317,257, filed on May 11, 2021, granted, now 11,973,779.
Prior Publication US 2024/0236133 A1, Jul. 11, 2024
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/1425 (2013.01) [H04L 63/1441 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A system comprising:
a user device in communicate via a communication network; and
a network monitoring platform communicatively coupled to the user device and the communication network, the network monitoring platform comprising:
at least one processor;
a communication interface communicatively coupled to the at least one processor; and
memory storing computer-readable instructions that, when executed by the at least one processor, cause the network monitoring platform to:
monitor outgoing data associated with the user device and communicated via the communication network;
predict, based on a seasonal autoregressive integrated moving average (SARIMA) model of data volumes of the outgoing data associated with the user device, expected data volumes of outgoing data for a first set of time intervals;
measure, without inspecting content, data volumes of outgoing data for the first set of time intervals;
based on the expected data volumes for the first set of time intervals and the measured data volumes for the first set of time intervals, identify anomalies in the measured data volumes for the first set of time intervals; and
send, via the communication interface and based on the identification of anomalies, one or more notifications indicating the user device.