Malicious behavior detection and mitigation in a document execution environment
Abstract
A document execution engine receives a training set of data representative of incidents of malicious activity within a document execution environment. The training set also includes data representative of remedial actions taken in response to the malicious behavior, and resulting measures of mitigation. The document execution engine trains a machine learned model based on the training set. The trained machine learned model, when applied to activity within the document execution environment, can identify activity that is indicative of malicious behavior. The trained machine learned model can then output recommendations for remedial actions to take in response to the identified malicious activity. The recommended remedial actions can be provided for display to a user of the document execution engine, via a client device of the user.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
accessing a training set of information representative of incidents of malicious behavior in a document execution environment and, for each of one or more of the incidents, one or more remedial actions taken in response to the malicious behavior and a resulting measure of mitigation; training a machine learned model based on the accessed training set of information, the machine learned model configured to detect malicious behavior based on activity within the document execution environment and to identify remedial actions that can mitigate the malicious behavior; receiving a document for execution within the document execution environment; detecting activity within the document execution environment associated with the received document; applying the trained machine learned model to the detected activity to determine if the detected activity is representative of malicious behavior and, in response to determining that the detected activity is representative of malicious behavior, to identify remedial actions that can mitigate the malicious behavior; and providing, to a device of a user, a recommendation to perform the identified remedial actions.
2 . The method of claim 1 , wherein detecting activity associated with the received document comprises:
identifying a party that created the document for execution; detecting an access to the document by a second party; detecting an execution of the document by the second party; and determining a time of the execution.
3 . The method of claim 2 , wherein the detected activity associated with the received document further comprises:
determining a geographic location associated with the detected access of the document by the second party; or determining a geographic location associated with the detected execution of the document by the second party.
4 . The method of claim 1 , wherein detecting activity associated with the received document comprises:
identifying a type of the document; accessing a second document of the same type; and comparing the document and the second document for variability.
5 . The method of claim 1 , wherein detecting activity associated with the received document comprises identifying changes made to content of the document.
6 . The method of claim 1 , wherein the detected activity associated with the received document comprises:
identifying a payment associated with an execution of the document; and identifying an amount of the payment.
7 . The method of claim 1 , wherein detecting activity associated with the received document comprises detecting a deletion of the document or content within the document from the document execution environment.
8 . The method of claim 1 , wherein the recommendation identifies the document for execution and a type of the detected activity determined to be malicious.
9 . The method of claim 1 , wherein the identified remedial actions comprise at least one of:
in response to detecting a deletion of the document for execution, restoring the document within the document execution environment; providing the document for execution to additional signatories; and limiting access to the document within the document execution environment.
10 . The method of claim 1 , wherein at least one type of detected activity representative of malicious behavior is defined by the user.
11 . The method of claim 10 , wherein the at least one type of detected activity representative of malicious behavior defined by the user comprises a defined threshold amount of the at least one type of detected activity.
12 . The method of claim 1 , wherein the device of the user comprises:
an interface on which the recommendation is displayed, the interface comprising:
for each of the identified remedial actions, an interface element that, when selected by the user, causes the remedial action to be performed.
13 . A non-transitory computer readable storage medium comprising computer executable code that when executed by one or more processors causes the one or more processors to perform operations comprising:
accessing a training set of information representative of incidents of malicious behavior in a document execution environment and, for each of one or more of the incidents, one or more remedial actions taken in response to the malicious behavior and a resulting measure of mitigation; training a machine learned model based on the accessed training set of information, the machine learned model configured to detect malicious behavior based on activity within the document execution environment and to identify remedial actions that can mitigate the malicious behavior; receiving a document for execution within the document execution environment; detecting activity within the document execution environment associated with the received document; applying the trained machine learned model to the detected activity to determine if the detected activity is representative of malicious behavior and, in response to determining that the detected activity is representative of malicious behavior, to identify remedial actions that can mitigate the malicious behavior; and providing, to a device of a user, a recommendation to perform the identified remedial actions.
14 . The non-transitory computer readable storage medium of claim 13 , wherein detecting activity associated with the received document corresponds to computer executable code that causes the processors to perform operations further comprising:
identifying a party that created the document for execution; detecting an access to the document by a second party; detecting an execution of the document by the second party; and determining a time of the execution.
15 . The non-transitory computer readable storage medium of claim 13 , wherein detecting activity associated with the received document corresponds to computer executable code that causes the processors to perform operations further comprising:
identifying changes made to content of the document.
16 . The non-transitory computer readable storage medium of claim 13 , wherein detecting activity associated with the received document corresponds to computer executable code that causes the processors to perform operations further comprising:
identifying a payment in conjunction with an execution of the document; and identifying an amount of the payment.
17 . The non-transitory computer readable storage medium of claim 13 , wherein the remedial actions comprise at least one of:
in response to detecting a deletion of the document for execution, restoring the document within the document execution environment; providing the document for execution to additional signatories; and limiting access to the document execution environment.
18 . The non-transitory computer readable storage medium of claim 13 , wherein at least one type of detected activity representative of malicious behavior is defined by the user.
19 . The non-transitory computer readable storage medium of claim 18 , wherein the at least one type of detected activity representative of malicious behavior defined by the user comprises a defined threshold amount of the at least one type of detected activity.
20 . A computer system comprising:
one or more computer processors; and a non-transitory computer readable storage medium comprising computer executable code that when executed by one or more processors causes the one or more processors to perform operations comprising:
accessing a training set of information representative of incidents of malicious behavior in a document execution environment and, for each of one or more of the incidents, one or more remedial actions taken in response to the malicious behavior and a resulting measure of mitigation;
training a machine learned model based on the accessed training set of information, the machine learned model configured to detect malicious behavior based on activity within the document execution environment and to identify remedial actions that can mitigate the malicious behavior;
receiving a document for execution within the document execution environment;
detecting activity within the document execution environment associated with the received document;
applying the trained machine learned model to the detected activity to determine if the detected activity is representative of malicious behavior and, in response to determining that the detected activity is representative of malicious behavior, to identify remedial actions that can mitigate the malicious behavior; and
providing, to a device of a user, a recommendation to perform the identified remedial actions.Join the waitlist — get patent alerts
Track US2021326436A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.