US 11,777,992 B1
Security model utilizing multi-channel data
Shane Cross, Matthews, NC (US); Daniel Fricano, San Francisco, CA (US); Thomas Gilheany, San Francisco, CA (US); Peter Anatole Makohon, San Francisco, CA (US); Dale Miller, San Francisco, CA (US); Charles Steven Edison, San Francisco, CA (US); Kodzo Wegba, San Francisco, CA (US); and James Bonk, San Francisco, CA (US)
Assigned to Wells Fargo Bank, N.A., San Francisco, CA (US)
Filed by Wells Fargo Bank, N.A., San Francisco, CA (US)
Filed on Dec. 21, 2020, as Appl. No. 17/129,767.
Application 17/129,767 is a continuation in part of application No. 17/081,275, filed on Oct. 27, 2020.
Claims priority of provisional application 63/007,045, filed on Apr. 8, 2020.
Int. Cl. H04L 9/40 (2022.01); G06F 16/23 (2019.01); H04L 43/0811 (2022.01); G06F 16/11 (2019.01); H04L 61/4511 (2022.01); H04L 61/5007 (2022.01); H04L 101/37 (2022.01)
CPC H04L 63/20 (2013.01) [G06F 16/128 (2019.01); G06F 16/2379 (2019.01); H04L 43/0811 (2013.01); H04L 61/4511 (2022.05); H04L 61/5007 (2022.05); H04L 63/0876 (2013.01); H04L 63/1433 (2013.01); H04L 2101/37 (2022.05); H04L 2463/121 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method of dynamically discovering new components of a computer network environment, the method comprising:
determining, by a processing circuit of a data acquisition engine, a domain name associated with an entity profile, the entity profile comprising previously stored device connectivity data for an entity, the device connectivity data comprising the domain name;
determining, by the processing circuit, internet protocol (IP) address data based on the domain name;
determining, by the processing circuit, an IP range based on the IP address data, wherein the IP range comprises an IP address and indicates an internet service provider (ISP) of the IP range;
validating, by the processing circuit, the domain name, the IP range, and the IP address, comprising determining whether the IP address is included in the previously stored device connectivity data;
collecting, by the processing circuit, additional device connectivity data associated with the IP address; and
providing, by the processing circuit, the additional device connectivity data to a security model.