IP Library Granted Patent US 8,015,414
Granted Patent B2
US 8,015,414 · App. 11/141,377 · Granted Sep 6, 2011

Method and apparatus for providing fraud detection using connection frequency thresholds

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,015,414
App. No.
11/141,377
Granted
Sep 6, 2011
Kind
B2
Abstract

An approach provides detection of unauthorized use of data services. A determination is made as to whether connections supporting remote access to a data network are completed. The number of completed connections associated with a selected attribute is tracked over a time period. It is then determined whether the number of completed connections satisfies a connection frequency threshold. A fraud alert is generated if the connection frequency threshold is satisfied.

Claims (35)

1. A computer-implemented method for detecting unauthorized use of data services, the method comprising a processor configured to perform the steps of:

determining whether connections supporting remote access to a data network are completed;

tracking number of completed connections associated with a selected attribute over a time period for a given usage account, wherein the time period is determined according to a sliding window, wherein the completed connections each includes successful establishment of a connection and termination of the connection, and wherein the selected attribute specifies one or more reasons for connection termination;

determining whether the number of completed connections satisfies a connection frequency threshold that is established based on a baseline usage pattern for the given usage account; and

generating a fraud alert if the connection frequency threshold is satisfied.

2. A method according to claim 1 , wherein the number of completed connections is tracked based on an additional selected attribute that includes an origination attribute, or a service type.

3. A method according to claim 1 , wherein the reason for connection termination is based on an accounting stop, the method further comprising:

detecting a message indicating the accounting stop with respect to one of the connections; and

designating the one connection as completed based on the detected message.

4. A method according to claim 1 , wherein the reason for connection termination is based on a heartbeat message, the method further comprising:

detecting absence of the heartbeat message associated with one of the connections for a specified duration; and

designating the one connection as completed based upon the detected absence.

5. A method according to claim 1 , wherein the number of completed connections is tracked based on an additional selected attribute that includes a log-in identifier, a host identifier, a host user identifier, a partner network, or a geographic region.

6. A method according to claim 1 , wherein the connections are dial-up sessions.

7. An apparatus for detecting unauthorized use of data services, the apparatus comprising:

a communication interface configured to receive information on number of completed connections associated with a selected attribute over a time period for a given usage account, wherein the time period is determined according to a sliding window, wherein the completed connections support remote access to a data network, wherein the completed connections each includes successful establishment of a connection and termination of the connection, and wherein the selected attribute specifies one or more reasons for connection termination; and

a processor configured to determine whether the number of completed connections satisfies a connection frequency threshold that is established based on a baseline usage pattern for the given usage account, wherein a fraud alert is generated if the connection frequency threshold is satisfied.

8. An apparatus according to claim 7 , wherein the number of completed connections is tracked based on an additional selected attribute that includes an origination attribute, or a service type.

9. An apparatus according to claim 7 , wherein the reason for connection termination is based on an accounting stop or a heartbeat message.

10. An apparatus according to claim 7 , wherein the number of completed connections is tracked based on an additional selected attribute that includes a log-in identifier, a host identifier, a host user identifier, a partner network, or a geographic region.

11. An apparatus according to claim 7 , wherein the connections are dial-up sessions.

12. An apparatus for detecting unauthorized use of data services, the apparatus comprising:

means for determining whether connections supporting remote access to a data network are completed;

means for tracking number of completed connections associated with a selected attribute over a time period for a given usage account, wherein the time period is determined according to a sliding window, wherein the completed connections each includes successful establishment of a connection and termination of the connection, and wherein the selected attribute specifies one or more reasons for connection termination;

means for determining whether the number of completed connections satisfies a connection frequency threshold that is established based on a baseline usage pattern for the given usage account; and

means for generating a fraud alert if the connection frequency threshold is satisfied.

13. An apparatus according to claim 12 , wherein the number of completed connections is tracked based on an additional selected attribute that includes an origination attribute, or a service type.

14. An apparatus according to claim 12 , wherein the reason for connection termination is based on an accounting stop, the apparatus further comprising:

means for detecting a message indicating the accounting stop with respect to one of the connections; and

means for designating the one connection as completed based on the detected message.

15. An apparatus according to claim 12 , wherein the reason for connection termination is based on a heartbeat message, the apparatus further comprising:

means for detecting absence of the heartbeat message associated with one of the connections for a specified duration; and

means for designating the one connection as completed based upon the detected absence.

16. An apparatus according to claim 12 , wherein the number of completed connections is tracked based on an additional selected attribute that includes a log-in identifier, a host identifier, a host user identifier, a partner network, or a geographic region.

17. An apparatus according to claim 12 , wherein the connections are dial-up sessions.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 032734 FRAME: 0502. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: VERIZON BUSINESS GLOBAL LLC
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 044626/0088 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2014
From: VERIZON BUSINESS GLOBAL LLC
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 032734/0502 →