IP Library Granted Patent US 7,870,608
Granted Patent B2
US 7,870,608 · App. 10/996,566 · Granted Jan 11, 2011

Early detection and monitoring of online fraud

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,870,608
App. No.
10/996,566
Granted
Jan 11, 2011
Kind
B2
Abstract

Various embodiments of the invention provide solutions (including inter alia, systems, methods and software) for dealing with online fraud. In particular, various embodiments of the invention can provide early warning of an online fraud, for instance by finding suspicious domains and/or monitoring those domains for activity. If a suspicious domain shows activity (for example, if a web site associated with the domain becomes active), one or more actions may be taken with respect to the domain.

Claims (57)

1. A method of preventing online fraud, the method comprising:

a computer automatically monitoring a domain registration zone file;

the computer ascertaining a change in a domain registration record incorporated in the domain registration zone file;

the computer monitoring a domain associated with the domain registration record to determine the existence of a web site associated with the domain;

the computer periodically saving on a storage medium a representation of a set of content on the web site associated with the domain to create a plurality of representations of the set of content on the web site;

the computer comparing one of the plurality of the representations of the set of content on the web site with at least one other of the plurality of representations of the set of content on the web site to determine that the set of content has been modified; and

the computer taking an action based on a determination that the set of content on the web site has been modified, wherein taking an action comprises investigating the web site, wherein investigating the web site comprises investigating the domain, and wherein investigating the domain comprises obtaining registration information about the domain from a domain registration record, obtaining current information about an Internet Protocol (“IP”) address associated with the web site, and comparing the registration information with the current information.

2. A method of preventing online fraud as recited in claim 1 , wherein monitoring the domain registration zone file comprises searching the domain registration zone file for any new or modified domain registrations similar to a brand name of a customer.

3. A method of preventing online fraud as recited in claim 2 , the method further comprising verifying that the new or modified domain registrations are not owned by the customer.

4. A method of preventing online fraud as recited in claim 1 , wherein the representation of the set of content on the web site is a value calculated from the set of content on the web site.

5. A method of preventing online fraud as recited in claim 4 , wherein the value is selected from the group consisting of a hash of at least one web page, a checksum calculated from at least one web page, and a file size of at least one web page.

6. A method of preventing online fraud as recited in claim 1 , wherein taking an action comprises informing a user that the domain is active.

7. A method of preventing online fraud as recited in claim 1 , wherein taking an action comprises creating an event in an event manager.

8. A method of preventing online fraud as recited in claim 1 , wherein investigating the web site comprises interrogating a server associated with the web site.

9. A method of preventing online fraud as recited in claim 1 , wherein the information about an IP address associated with the web site is information about an IP block assigned to the domain.

10. A method of preventing online fraud as recited in claim 1 , wherein the IP address associated with the web site is an IP address of a server hosting the web site.

11. A method of preventing online fraud as recited in claim 1 , wherein taking an action comprises initiating a response against the web site.

12. A method of preventing online fraud as recited in claim 11 , wherein initiating a response against the web site comprises submitting to the web site a plurality of substantially simultaneous hypertext transfer protocol (“HTTP”) requests.

13. A method of preventing online fraud as recited in claim 12 , wherein each of the HTTP requests comprises a response to a request from the server for personal information.

14. A method of preventing online fraud as recited in claim 11 , wherein initiating a response against the web site comprises taking an administrative action against the web site.

15. A method of preventing online fraud as recited in claim 14 , wherein taking an administrative action comprises informing an ISP associated with the web site that the web site is involved in an online fraud.

16. A method of preventing online fraud as recited in claim 14 , wherein taking an administrative action comprises initiating a domain name dispute against an owner of the suspicious domain.

17. A computer system for preventing online fraud, the system comprising a processor, a storage medium and instructions executable by the processor to:

monitor a domain registration zone file;

ascertain a change in a domain registration incorporated in the domain registration zone file;

monitor a domain associated with the domain registration to determine the existence of a web site associated with the domain;

periodically save on the storage medium a representation of a set of content on the web site associated with the domain to create a plurality of representations of the set of content on the web site;

compare one of the plurality of the representations of the set of content on the web site with at least one other of the plurality of representations of the set of content on the web site to determine that the set of content has been modified; and

take an action based on a determination that the set of content on the web site has been modified, wherein taking an action comprises investigating the web site, wherein investigating the web site comprises investigating the domain, and wherein investigating the domain comprises obtaining registration information about the domain from a domain registration record, obtaining current information about an Internet Protocol (“IP”) address associated with the web site, and comparing the registration information with the current information.

18. A software program for preventing online fraud, the software program being stored on a non-transitory computer readable medium and comprising instructions executable by a computer to:

monitor a domain registration zone file;

ascertain a change in a domain registration incorporated in the domain registration zone file;

monitor a domain associated with the domain registration to determine the existence of a web site associated with the domain;

periodically save on a storage medium a representation of a set of content on the web site associated with the domain to create a plurality of representations of the set of content on the web site;

compare one of the plurality of the representations of the set of content on the web site with at least one other of the plurality of representations of the set of content on the web site to determine that the set of content has been modified; and

take an action based on a determination that the set of content on the web site has been modified, wherein taking an action comprises investigating the web site, wherein investigating the web site comprises investigating the domain, and wherein investigating the domain comprises obtaining registration information about the domain from a domain registration record, obtaining current information about an Internet Protocol (“IP”) address associated with the web site, and comparing the registration information with the current information.

19. A system, comprising:

means for monitoring a domain registration zone file;

means for ascertaining a change in a domain registration incorporated in the domain registration zone file;

means for monitoring a domain associated with the domain registration to determine the existence of a web site associated with the domain;

means for periodically saving a representation of a set of content on the web site associated with the domain to create a plurality of representations of the set of content on the web site;

means for comparing one of the plurality of the representations of the set of content on the web site with at least one other of the plurality of representations of the set of content on the web site to determine that the set of content has been modified; and

means for taking an action based on a determination that the set of content on the web site has been modified, wherein taking an action comprises investigating the web site, wherein investigating the web site comprises investigating the domain, and wherein investigating the domain comprises obtaining registration information about the domain from a domain registration record, obtaining current information about an Internet Protocol (“IP”) address associated with the web site, and comparing the registration information with the current information.

20. The system of claim 17 , wherein monitoring the domain registration zone file comprises searching the domain registration zone file for any new or modified domain registrations similar to a brand name of a customer.

21. The system of claim 20 , wherein the instructions are further executable by the processor to:

verify that the new or modified domain registrations are not owned by the customer.

22. The system of claim 17 , wherein the representation of the set of content on the web site is a value calculated from the content of the web site, and wherein the value is selected from the group consisting of a hash of at least one web page, a checksum calculated from at least one web page, and a file size of at least one web page.

23. The system of claim 17 , wherein investigating the web site comprises interrogating a server associated with the web site.

24. The system of claim 17 , wherein the information about an IP address associated with the web site is information about an IP block assigned to the domain.

25. The system of claim 17 , wherein the IP address associated with the web site is an IP address of a server hosting the web site.

26. The system of claim 17 , wherein taking an action comprises initiating a response against the web site.

27. The system of claim 26 , wherein initiating a response against the web site comprises submitting to the web site a plurality of substantially simultaneous hypertext transfer protocol (“HTTP”) requests.

28. The system of claim 27 , wherein each of the HTTP requests comprises a response to a request from the server for personal information.

29. The system of claim 26 , wherein initiating a response against the web site comprises taking an administrative action against the web site.

30. The system of claim 29 , wherein taking an administrative action comprises informing an ISP associated with the web site that the web site is involved in an online fraud.

31. The system of claim 29 , wherein taking an administrative action comprises initiating a domain name dispute against an owner of the suspicious domain.

32. The system of claim 17 , wherein the set of content comprises at least a portion of one or more web pages on the web site.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2020
From: CAMELOT UK BIDCO LIMITED
To: OPSEC ONLINE LIMITED
Reel/Frame 052070/0544 →
SECURITY INTEREST Recorded Nov 1, 2019
From: CAMELOT UK BIDCO LIMITED
To: BANK OF AMERICA, N.A.
Reel/Frame 050906/0284 →
SECURITY INTEREST Recorded Nov 1, 2019
From: CAMELOT UK BIDCO LIMITED
To: WILMINGTON TRUST, N.A. AS COLLATERAL AGENT
Reel/Frame 050906/0553 →
RELEASE OF SECURITY INTEREST Recorded Nov 1, 2019
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: CAMELOT UK BIDCO LIMITED
Reel/Frame 050911/0796 →
SECURITY INTEREST Recorded Oct 3, 2016
From: CAMELOT UK BIDCO LIMITED
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040205/0156 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2016
From: THOMSON REUTERS GLOBAL RESOURCES
To: CAMELOT UK BIDCO LIMITED
Reel/Frame 040206/0448 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2014
From: MARKMONITOR INC
To: THOMSON REUTERS GLOBAL RESOURCES
Reel/Frame 034141/0441 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2006
From: SHRAIM, IHAB; SHULL, MARK
To: MARKMONITOR, INC.
Reel/Frame 017843/0964 →