IP Library Granted Patent US 9,124,623
Granted Patent B1
US 9,124,623 · App. 13/923,108 · Granted Sep 1, 2015

Systems and methods for detecting scam campaigns

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,124,623
App. No.
13/923,108
Granted
Sep 1, 2015
Kind
B1
Abstract

A computer-implemented method for detecting scam campaigns is described. A plurality of web pages that are pre-filtered according to predetermined criteria is identified. Pattern detection is performed on the pre-filtered web pages. A pattern is detected among the pre-filtered web pages. The detected pattern is compared to a user input.

Claims (45)

1. A computer-implemented method for detecting scam campaigns, the method comprising:

identifying a plurality of web pages that are pre-filtered according to predetermined criteria;

performing pattern detection on the pre-filtered web pages;

extracting at least one of text and an image from one or more of the pre-filtered web pages;

performing at least one of natural language processing on the extracted text to derive a meaning of the extracted text and image analysis on the extracted image to recognize an aspect of the image;

detecting a pattern among the pre-filtered web pages based on at least one of the derived meaning of the extracted text and the recognized aspect of the image;

comparing the detected pattern to a user input;

accessing the repository of common scam campaign techniques in real time relative to detecting a user generating the user input; and

upon detecting the pattern among the pre-filtered web pages, storing the detected pattern in a database in order to build a repository of common scam campaign techniques.

2. The method of claim 1 , further comprising:

upon detecting a match between the detected pattern and the user input, generating a notification.

3. The method of claim 2 , wherein the notification comprises at least one of displaying a pop-up alert, sending an email, sending an instant message, sending a text message, and blocking the user input.

4. The method of claim 1 , wherein the user input comprises at least one of a web query, a URL, an email, an instant message, a text message, a web form entry, and an audio command.

5. The method of claim 1 , wherein the predetermined criteria comprises at least one of a detected age of a file, a detected prevalence of a file, content from a file, an external link used in a file, a user reputation, a website reputation, a digital certificate, a detected request for personally identifiable information, and associations between two or more elements of the predetermined criteria.

6. A computing device configured to detect scam campaigns, comprising:

a processor;

memory in electronic communication with the processor;

instructions stored in the memory, the instructions being executable by the processor to:

identify a plurality of web pages that are pre-filtered according to predetermined criteria;

perform pattern detection on the pre-filtered web pages;

extract at least one of text and an image from one or more of the pre-filtered web pages;

perform at least one of natural language processing on the extracted text to derive a meaning of the extracted text and image analysis on the extracted image to recognize an aspect of the image;

detect a pattern among the pre-filtered web pages based on at least one of the derived meaning of the extracted text and the recognized aspect of the image;

compare the detected pattern to a user input;

access the repository of common scam campaign techniques in real time relative to detecting a user generating the user input; and

upon detecting the pattern among the pre-filtered web pages, store the detected pattern in a database in order to build a repository of common scam campaign techniques.

7. The computing device of claim 6 , wherein the instructions are executable by the processor to:

upon detecting a match between the detected pattern and the user input, generate a notification.

8. The computing device of claim 7 , wherein the notification comprises at least one of displaying a pop-up alert, sending an email, sending an instant message, sending a text message, and blocking the user input.

9. The computing device of claim 6 , wherein the user input comprises at least one of a web query, a URL, an email, an instant message, a text message, a web form entry, and an audio command.

10. The computing device of claim 6 , wherein the predetermined criteria comprises at least one of a detected age of a file, a detected prevalence of a file, content from a file, an external link used in a file, a user reputation, a website reputation, a digital certificate, a detected request for personally identifiable information, and associations between two or more elements of the predetermined criteria.

11. The computing device of claim 6 , wherein the database having the repository of common scam campaign techniques is any of internal to the device or external to the device.

12. The computing device of claim 6 , further comprising an application, wherein the application includes instructions executable by the processor to:

interface with an external scam detection module to identify potential scam campaigns by searching the plurality of pre-filtered web pages, detecting patterns among the plurality of pre-filtered web pages, and comparing the user input to the detected patterns in order to notify the user in real time of a potential scam.

13. A computer-program product for detecting, by a processor, scam campaigns, the computer-program product comprising a non-transitory computer-readable medium storing instructions thereon, the instructions being executable by the processor to:

identify a plurality of web pages that are pre-filtered according to predetermined criteria;

perform pattern detection on the pre-filtered web pages;

extract at least one of text and an image from one or more of the pre-filtered web pages;

perform at least one of natural language processing on the extracted text to derive a meaning of the extracted text and image analysis on the extracted image to recognize an aspect of the image;

detect a pattern among the pre-filtered web pages based on at least one of the derived meaning of the extracted text and the recognized aspect of the image;

compare the detected pattern to a user input;

access the repository of common scam campaign techniques in real time relative to detecting a user generating the user input; and

upon detecting a pattern, store the detected pattern in a database in order to build a repository of common scam campaign techniques.

14. The computer-program product of claim 13 , wherein the instructions are executable by the processor to:

upon detecting a match between the detected pattern and the user input, generate a notification to notify the user of a potential scam.

Assignments (5)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Jan 30, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051759/0845 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2013
From: CHEN, JOSEPH H.
To: SYMANTEC CORPORATION
Reel/Frame 030655/0429 →