US2021326436A1PendingUtilityA1

Malicious behavior detection and mitigation in a document execution environment

Assignee: DOCUSIGN INCPriority: Apr 21, 2020Filed: Apr 21, 2020Published: Oct 21, 2021
Est. expiryApr 21, 2040(~13.7 yrs left)· nominal 20-yr term from priority
G06F 21/554G06F 2221/2111G06F 21/567G06F 2221/034
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A document execution engine receives a training set of data representative of incidents of malicious activity within a document execution environment. The training set also includes data representative of remedial actions taken in response to the malicious behavior, and resulting measures of mitigation. The document execution engine trains a machine learned model based on the training set. The trained machine learned model, when applied to activity within the document execution environment, can identify activity that is indicative of malicious behavior. The trained machine learned model can then output recommendations for remedial actions to take in response to the identified malicious activity. The recommended remedial actions can be provided for display to a user of the document execution engine, via a client device of the user.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 accessing a training set of information representative of incidents of malicious behavior in a document execution environment and, for each of one or more of the incidents, one or more remedial actions taken in response to the malicious behavior and a resulting measure of mitigation;   training a machine learned model based on the accessed training set of information, the machine learned model configured to detect malicious behavior based on activity within the document execution environment and to identify remedial actions that can mitigate the malicious behavior;   receiving a document for execution within the document execution environment;   detecting activity within the document execution environment associated with the received document;   applying the trained machine learned model to the detected activity to determine if the detected activity is representative of malicious behavior and, in response to determining that the detected activity is representative of malicious behavior, to identify remedial actions that can mitigate the malicious behavior; and   providing, to a device of a user, a recommendation to perform the identified remedial actions.   
     
     
         2 . The method of  claim 1 , wherein detecting activity associated with the received document comprises:
 identifying a party that created the document for execution;   detecting an access to the document by a second party;   detecting an execution of the document by the second party; and   determining a time of the execution.   
     
     
         3 . The method of  claim 2 , wherein the detected activity associated with the received document further comprises:
 determining a geographic location associated with the detected access of the document by the second party; or   determining a geographic location associated with the detected execution of the document by the second party.   
     
     
         4 . The method of  claim 1 , wherein detecting activity associated with the received document comprises:
 identifying a type of the document;   accessing a second document of the same type; and   comparing the document and the second document for variability.   
     
     
         5 . The method of  claim 1 , wherein detecting activity associated with the received document comprises identifying changes made to content of the document. 
     
     
         6 . The method of  claim 1 , wherein the detected activity associated with the received document comprises:
 identifying a payment associated with an execution of the document; and   identifying an amount of the payment.   
     
     
         7 . The method of  claim 1 , wherein detecting activity associated with the received document comprises detecting a deletion of the document or content within the document from the document execution environment. 
     
     
         8 . The method of  claim 1 , wherein the recommendation identifies the document for execution and a type of the detected activity determined to be malicious. 
     
     
         9 . The method of  claim 1 , wherein the identified remedial actions comprise at least one of:
 in response to detecting a deletion of the document for execution, restoring the document within the document execution environment;   providing the document for execution to additional signatories; and   limiting access to the document within the document execution environment.   
     
     
         10 . The method of  claim 1 , wherein at least one type of detected activity representative of malicious behavior is defined by the user. 
     
     
         11 . The method of  claim 10 , wherein the at least one type of detected activity representative of malicious behavior defined by the user comprises a defined threshold amount of the at least one type of detected activity. 
     
     
         12 . The method of  claim 1 , wherein the device of the user comprises:
 an interface on which the recommendation is displayed, the interface comprising:
 for each of the identified remedial actions, an interface element that, when selected by the user, causes the remedial action to be performed. 
   
     
     
         13 . A non-transitory computer readable storage medium comprising computer executable code that when executed by one or more processors causes the one or more processors to perform operations comprising:
 accessing a training set of information representative of incidents of malicious behavior in a document execution environment and, for each of one or more of the incidents, one or more remedial actions taken in response to the malicious behavior and a resulting measure of mitigation;   training a machine learned model based on the accessed training set of information, the machine learned model configured to detect malicious behavior based on activity within the document execution environment and to identify remedial actions that can mitigate the malicious behavior;   receiving a document for execution within the document execution environment;   detecting activity within the document execution environment associated with the received document;   applying the trained machine learned model to the detected activity to determine if the detected activity is representative of malicious behavior and, in response to determining that the detected activity is representative of malicious behavior, to identify remedial actions that can mitigate the malicious behavior; and   providing, to a device of a user, a recommendation to perform the identified remedial actions.   
     
     
         14 . The non-transitory computer readable storage medium of  claim 13 , wherein detecting activity associated with the received document corresponds to computer executable code that causes the processors to perform operations further comprising:
 identifying a party that created the document for execution;   detecting an access to the document by a second party;   detecting an execution of the document by the second party; and   determining a time of the execution.   
     
     
         15 . The non-transitory computer readable storage medium of  claim 13 , wherein detecting activity associated with the received document corresponds to computer executable code that causes the processors to perform operations further comprising:
 identifying changes made to content of the document.   
     
     
         16 . The non-transitory computer readable storage medium of  claim 13 , wherein detecting activity associated with the received document corresponds to computer executable code that causes the processors to perform operations further comprising:
 identifying a payment in conjunction with an execution of the document; and   identifying an amount of the payment.   
     
     
         17 . The non-transitory computer readable storage medium of  claim 13 , wherein the remedial actions comprise at least one of:
 in response to detecting a deletion of the document for execution, restoring the document within the document execution environment;   providing the document for execution to additional signatories; and   limiting access to the document execution environment.   
     
     
         18 . The non-transitory computer readable storage medium of  claim 13 , wherein at least one type of detected activity representative of malicious behavior is defined by the user. 
     
     
         19 . The non-transitory computer readable storage medium of  claim 18 , wherein the at least one type of detected activity representative of malicious behavior defined by the user comprises a defined threshold amount of the at least one type of detected activity. 
     
     
         20 . A computer system comprising:
 one or more computer processors; and   a non-transitory computer readable storage medium comprising computer executable code that when executed by one or more processors causes the one or more processors to perform operations comprising:
 accessing a training set of information representative of incidents of malicious behavior in a document execution environment and, for each of one or more of the incidents, one or more remedial actions taken in response to the malicious behavior and a resulting measure of mitigation; 
 training a machine learned model based on the accessed training set of information, the machine learned model configured to detect malicious behavior based on activity within the document execution environment and to identify remedial actions that can mitigate the malicious behavior; 
 receiving a document for execution within the document execution environment; 
 detecting activity within the document execution environment associated with the received document; 
 applying the trained machine learned model to the detected activity to determine if the detected activity is representative of malicious behavior and, in response to determining that the detected activity is representative of malicious behavior, to identify remedial actions that can mitigate the malicious behavior; and 
 providing, to a device of a user, a recommendation to perform the identified remedial actions.

Join the waitlist — get patent alerts

Track US2021326436A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.