IP Library Patent Application 14153959
Patent Application
App. No. 14/153,959

Detecting a suspicious transaction within a network-based facility

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/153,959
Abstract

Methods and associated computer-readable media to detect fraudulent activities made over a network-based facility using a machine are disclosed. Responsive to a first event with respect to the network-based facility and initiated either under a first user identity or a first set of user transaction preferences from the machine which is coupled to the network-based facility via a network, the method causes a first identifier associated with either the first user identity or the first set of user transaction preferences to be stored on the machine. Responsive to a second event initiated under either a second user identity or a second set of user transaction preferences, detecting a potentially fraudulent activity occurs by detecting a lack of correspondence between the first identifier stored on the machine and a second identifier associated with either the second user identity or the second set of user transaction preferences.

Claims (36)

1 . A method of detecting fraudulent activity, the method comprising:

causing a first identifier associated with a first user identity to be stored on a machine responsive to a first event with respect to a network-based facility and initiated under the first user identity from the machine that is coupled to the network-based facility via a network; and

detecting, one or more processors, a potentially fraudulent activity by detecting a lack of correspondence between the first identifier stored on the machine and a second identifier associated with a second user identity responsive to a second event with respect to the network-based facility and initiated under the second user identity from the machine.

2 . The method of claim 1 , further comprising storing the first identifier in a shill cookie on the machine.

3 . The method of claim 2 , further comprising generating the second identifier associated with the second user identity and storing the second user identifier in the shill cookie on the machine.

4 . The method of claim 2 , further comprising encoding the shill cookie.

5 . The method of claim 2 , further comprising encrypting the shill cookie.

6 . The method of claim 1 , further comprising generating and storing a new shill cookie on the machine or adding to an existing shill cookie stored on the machine each time one of a plurality of triggering events occurs.

7 . The method of claim 3 , wherein the plurality of triggering events includes at least one type of event selected from a group of events including registering with the network-based facility, communicating with the network-based facility to offer a good or service for sale, communicating with the network-based facility to purchase a good or service, communicating with the network-based facility to present feedback regarding a transaction, and updating a profile maintained by the network-based facility.

8 . The method of claim 1 , wherein the network-based facility is a network-based transaction facility.

9 . The method of claim 1 , wherein the network-based facility is a network-based auction facility.

10 . The method of claim 1 , further comprising recording a set of transaction preferences for the first user identity.

11 . The method of claim 10 , wherein the set of transaction preferences include a plurality of items selected from items including credit card numbers, bidding histories, payment methods, and shipping addresses.

12 . The method of claim 1 , further comprising recording the potentially fraudulent activity at the network-based facility responsive to the detection of the lack of correspondence between the first identifier and the second identifier.

13 . The method of claim 1 , further comprising:

generating a potential fraudulent activities table having a fraudulent activity field, a cookie identifier field, a user identifier field, and a frequency field;

recording each of a plurality of potentially fraudulent activities and corresponding information into the potential fraudulent activities table;

updating the potential fraudulent activities table on at least a periodic basis; and

providing an updated report of the potential fraudulent activities table to an investigation team.

14 . The method of claim 1 , further comprising providing a priority ranking system having a low priority for a low potential fraudulent activity frequency, a medium priority for a medium potential fraudulent activity frequency, and a high priority for a high potential fraudulent activity frequency.

15 . A method of detecting fraudulent activity, the method comprising:

generating a first identifier associated with a first set of transaction preferences, the first identifier to be stored on a first client machine, the first identifier being generated responsive to at least one of a plurality of triggering events with respect to a network-based facility;

generating a second identifier associated with a second set of transaction preferences, the second identifier to be stored with either the first identifier on the first client machine or on a second client machine, the second identifier being generated responsive to at least one of the plurality of triggering events with respect to the network-based facility;

receiving information stored in one or both of the first identifier and the second identifier at the network-based facility; and

detecting, using one or more hardware processors, potentially fraudulent activity by detecting a lack of correspondence between the first set of transaction preferences and the second set of transaction preferences.

16 . The method of claim 15 , wherein the plurality of triggering events includes at least one type of event selected from a group of events including registering with the network-based facility, communicating with the network-based facility to offer a good or service for sale, communicating with the network-based facility to purchase a good or service, communicating with the network-based facility to present feedback regarding a transaction, and updating a profile maintained by the network-based facility.

17 . The method of claim 15 , wherein the potentially fraudulent activity includes at least one of shill bidding and shill feedback.

18 . The method of claim 15 , wherein the detection of the potentially fraudulent activity is responsive to a matching of a plurality of user transaction preferences from a plurality of different user identifies.

19 . The method of claim 15 , further comprising:

generating a first shill cookie and a second shill cookie for the first user identifier and the second user identifier, respectively; and

transmitting information stored on the first shill cookie and the second shill cookie to the network-based facility responsive to one of the plurality of triggering events with respect to a network-based facility and associated with the first identifier and the second identifier, respectively.

20 . A computer-readable storage medium comprising no transitory signals, the computer-readable storage medium having instructions that, when executed by at least one processor causes the at least one processor to perform operations, the operations comprising:

generating a first identifier associated with a first set of transaction preferences, the first identifier to be stored on a first client machine, the first identifier being generated responsive to at least one of a plurality of triggering events with respect to a network-based facility;

generating a second identifier associated with a second set of transaction preferences, the second identifier to be stored with either the first identifier on the first client machine or on a second client machine, the second identifier being generated responsive to at least one of the plurality of triggering events with respect to the network-based facility;

receiving information stored in one or both of the first identifier and the second identifier at the network-based facility; and

detecting potentially fraudulent activity by detecting a lack of correspondence between the first set of transaction preferences and the second set of transaction preferences.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE LAST NAME OF THE OF SIXTH CONVEYING PARTY PREVIOUSLY RECORDED ON REEL 033946 FRAME 0694. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 11, 2016
From: CHENG, CHRISTINE; WON, BRENDA; MOHNIA, DHEERAJ SINGH; NGUYEN, HA; MALTZMAN, REED; STRACK, ISAAC; MORIN, NOEL
To: PAYPAL, INC.
Reel/Frame 037796/0262 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2015
From: EBAY INC.
To: PAYPAL, INC.
Reel/Frame 036171/0144 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2014
From: CHENG, CHRISTINE; WON, BRENDA; MOHNIA, DHEERAJ SINGH; NGUYEN, HA; MALTZMAN, REED; ISAAC, ISAAC; MORIN, NOEL
To: EBAY INC.
Reel/Frame 033946/0694 →