IP Library Granted Patent US 8,769,671
Granted Patent B2
US 8,769,671 · App. 10/709,398 · Granted Jul 1, 2014

Online fraud solution

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,769,671
App. No.
10/709,398
Granted
Jul 1, 2014
Kind
B2
Abstract

Various embodiments of the invention provide solutions, including systems, methods and software, for dealing with unethical uses of electronic mail, and in particular, with attempts to use email messages to facilitate online fraud. Some embodiments function to gather a set of at least one incoming email message, analyze that incoming message, categorize the message as a categorize the incoming email message as a fraudulent email message. Other embodiments can investigate the uniform resource locator included with the incoming email message to determine information about a server hosting the web site referenced by the uniform resource locator and pursue a response to a fraudulent attempt to collect personal information. In some cases, responses may be administrative and/or technical in nature.

Claims (74)

1. A computer system for responding to a fraudulent attempt to collect personal information, the computer system comprising:

a processor; and

a memory communicatively coupled with the processor, the memory having stored therein instructions which, when executed by the processor, cause the processor to:

download a web page from a suspicious server;

parse the web page to identify a form within the web page, the form comprising at least one field into which a user may enter personal information and a label associated with each field, the label indicating the personal information requested;

analyze the at least one field and associated label to identify a type of information requested by the at least one field;

determine, based at least in part on analysis of the at least one field and associated label, that the suspicious service is engaged in a fraudulent attempt to collect confidential personal information;

generate a set of safe data comprising personal information associated with a fictitious entity;

based on analysis of the at least one field and associated label, select at least a portion of the set of safe data comprising the type of information requested by the at least one field and indicated by the associated label;

format a response to the web page, the response including the portion of the safe data comprising the type of information requested by the at least one field and indicated by the associated label; and

transmit the response to the web page for reception by the suspicious server.

2. A computer system for responding to a fraudulent attempt to collect personal information as recited in claim 1 , wherein analyzing the at least one field to identify a type of information requested by the field comprises interpreting the label associated with the at least one field.

3. A computer system for responding to a fraudulent attempt to collect personal information as recited in claim 1 , wherein the set of safe data is associated with a financial account, and wherein the instructions further cause the processor to:

monitor the financial account for an account activity evidencing a use of information obtained from the set of safe data; and

trace the account activity to identify an entity using the information obtained from the set of safe data.

4. A computer system for responding to a fraudulent attempt to collect personal information as recited in claim 1 , wherein the instructions further cause the processor to:

generate a plurality of sets of safe data, each of the sets of safe data comprising personal information associated with a fictitious entity;

based on an analysis of the at least one field, select at least a portion of each of the sets of safe data responsive to the at least one field;

format a plurality of responses to the web page, each of the plurality of response including the portion of one of the sets of safe data, each of the portions of one of the sets of safe data being responsive to the at least one field; and

transmit the plurality of responses to the web page for reception by the suspicious server.

5. A computer system for responding to a fraudulent attempt to collect personal information as recited in claim 4 , wherein the instructions further cause the processor to:

transmit for reception by the suspicious server a number of responses to the web page sufficient to cause a recipient of the responses to be uncertain which of a plurality of responses include valid personal information.

6. A computer system for responding to a fraudulent attempt to collect personal information as recited in claim 4 , wherein the instructions further cause the processor to:

transmit for reception by the suspicious server a number of responses to the web page sufficient to indicate that the fraudulent attempt to collect personal information has been discovered.

7. A computer system for responding to a fraudulent attempt to collect personal information as recited in claim 4 , wherein the instructions further cause the processor to:

transmit for reception by the suspicious server a number of responses to the web page sufficient to prevent the suspicious server from receiving any responses comprising valid personal information.

8. A method for responding to a fraudulent attempt to collect personal information, the method comprising:

downloading, by a computer system, a web page from a suspicious server;

parsing, by the computer system, the web page to identify a form within the web page, the form comprising at least one field into which a user may enter personal information and a label associated with each field, the label indicating the personal information requested;

analyzing, by the computer system, the at least one field and associated label to identify a type of information requested by the at least one field;

determining, by the computer system based at least in part on analysis of the at least one field and associated label, that the suspicious service is engaged in a fraudulent attempt to collect confidential personal information;

generating, by the computer system, a set of safe data comprising personal information associated with a fictitious entity;

based on analysis of the at least one field and associated label, selecting, by the computer system, at least a portion of the set of safe data comprising the type of information requested by the at least one field and indicated by the associated label;

formatting, by the computer system, a response to the web page, the response including the portion of the safe data comprising the type of information requested by the at least one field and indicated by the associated label; and

transmitting, by the computer system, the response to the web page for reception by the suspicious server.

9. The method of claim 8 , wherein analyzing the at least one field to identify a type of information requested by the field comprises interpreting the label associated with the at least one field.

10. The method of claim 8 , wherein the set of safe data is associated with a financial account, the method further comprising:

monitoring, by the computer system, the financial account for an account activity evidencing a use of information obtained from the set of safe data; and

tracing, by the computer system, the account activity to identify an entity using the information obtained from the set of safe data.

11. The method of claim 8 , further comprising:

generating, by the computer system, a plurality of sets of safe data, each of the sets of safe data comprising personal information associated with a fictitious entity;

based on an analysis of the at least one field, selecting, by the computer system, at least a portion of each of the sets of safe data responsive to the at least one field;

formatting, by the computer system, a plurality of responses to the web page, each of the plurality of response including the portion of one of the sets of safe data, each of the portions of one of the sets of safe data being responsive to the at least one field; and

transmitting, by the computer system, the plurality of responses to the web page for reception by the suspicious server.

12. The method of claim 11 , further comprising:

transmitting, by the computer system for reception by the suspicious server, a number of responses to the web page sufficient to cause a recipient of the responses to be uncertain which of a plurality of responses include valid personal information.

13. The method of claim 11 , further comprising:

transmitting, by the computer system for reception by the suspicious server, a number of responses to the web page sufficient to indicate that the fraudulent attempt to collect personal information has been discovered.

14. The method of claim 11 , further comprising:

transmitting, by the computer system for reception by the suspicious server, a number of responses to the web page sufficient to prevent the suspicious server from receiving any responses comprising valid personal information.

15. A computer-readable memory having stored thereon a sequence of instructions which, when executed by a processor, cause the processor to respond to a fraudulent attempt to collect personal information by:

downloading a web page from a suspicious server;

parsing the web page to identify a form within the web page, the form comprising at least one field into which a user may enter personal information and a label associated with each field, the label indicating the personal information requested;

analyzing the at least one field and associated label to identify a type of information requested by the at least one field;

determining, based at least in part on analysis of the at least one field and associated label, that the suspicious service is engaged in a fraudulent attempt to collect confidential personal information;

generating a set of safe data comprising personal information associated with a fictitious entity;

based on analysis of the at least one field and associated label, selecting at least a portion of the set of safe data comprising the type of information requested by the at least one field and indicated by the associated label;

formatting a response to the web page, the response including the portion of the safe data comprising the type of information requested by the at least one field and indicated by the associated label; and

transmitting the response to the web page for reception by the suspicious server.

16. The computer-readable memory of claim 15 , wherein analyzing the at least one field to identify a type of information requested by the field comprises interpreting the label associated with the at least one field.

17. The computer-readable memory of claim 15 , wherein the set of safe data is associated with a financial account, the method further comprising:

monitor the financial account for an account activity evidencing a use of information obtained from the set of safe data; and

trace the account activity to identify an entity using the information obtained from the set of safe data.

18. The computer-readable memory of claim 15 , further comprising:

generating a plurality of sets of safe data, each of the sets of safe data comprising personal information associated with a fictitious entity;

based on an analysis of the at least one field, selecting at least a portion of each of the sets of safe data responsive to the at least one field;

formatting a plurality of responses to the web page, each of the plurality of response including the portion of one of the sets of safe data, each of the portions of one of the sets of safe data being responsive to the at least one field; and

transmitting the plurality of responses to the web page for reception by the suspicious server.

19. The computer-readable memory of claim 18 , further comprising:

transmitting for reception by the suspicious server a number of responses to the web page sufficient to cause a recipient of the responses to be uncertain which of a plurality of responses include valid personal information.

20. The computer-readable memory of claim 18 , further comprising:

transmitting for reception by the suspicious server a number of responses to the web page sufficient to indicate that the fraudulent attempt to collect personal information has been discovered.

21. The computer-readable memory of claim 18 , further comprising:

transmitting for reception by the suspicious server a number of responses to the web page sufficient to prevent the suspicious server from receiving any responses comprising valid personal information.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2020
From: CAMELOT UK BIDCO LIMITED
To: OPSEC ONLINE LIMITED
Reel/Frame 052070/0544 →
SECURITY INTEREST Recorded Nov 1, 2019
From: CAMELOT UK BIDCO LIMITED
To: WILMINGTON TRUST, N.A. AS COLLATERAL AGENT
Reel/Frame 050906/0553 →
RELEASE OF SECURITY INTEREST Recorded Nov 1, 2019
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: CAMELOT UK BIDCO LIMITED
Reel/Frame 050911/0796 →
SECURITY INTEREST Recorded Nov 1, 2019
From: CAMELOT UK BIDCO LIMITED
To: BANK OF AMERICA, N.A.
Reel/Frame 050906/0284 →
SECURITY INTEREST Recorded Oct 3, 2016
From: CAMELOT UK BIDCO LIMITED
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040205/0156 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2016
From: THOMSON REUTERS GLOBAL RESOURCES
To: CAMELOT UK BIDCO LIMITED
Reel/Frame 040206/0448 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2014
From: MARKMONITOR INC
To: THOMSON REUTERS GLOBAL RESOURCES
Reel/Frame 034141/0378 →