IP Library Granted Patent US 9,378,354
Granted Patent B2
US 9,378,354 · App. 14/218,839 · Granted Jun 28, 2016

Systems and methods for assessing security risk

Inventor: Christopher Everett Bailey (Langley, CA)
Assignee: NuData Security Inc.
G06F21/36G06Q30/02G06Q30/0277G06T13/80H04L63/0884H04L63/1433G06F2221/2103
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,378,354
App. No.
14/218,839
Granted
Jun 28, 2016
Kind
B2
Abstract

Systems and methods for providing identification tests. In some embodiments, a system and a method are provided for generating and serving to a user an animated challenge graphic comprising a challenge character set whose appearance may change over time. In some embodiments, marketing content may be incorporated into a challenge message for use in an identification test. The marketing content may be accompanied by randomly selected content to increase a level of security of the identification test, hi some embodiments, a challenge message for use in an identification test may be provided based on information regarding a transaction for which the identification test is administered. For example, the transaction information may include a user identifier such as an IP address. In some embodiments, identification test results may be tracked and analyzed to identify a pattern of behavior associated with a user identifier. A score indicative of a level of trustworthiness may be computed for the user identifier.

Claims (48)

1. A system for assessing security risk associated with an electronic transaction, the system comprising at least one processor programmed to:

analyze current user information indicative of at least one user behavior observed in connection with the electronic transaction;

determine at least one user identifier associated with the electronic transaction;

analyze history information associated with the at least one user identifier, the history information being indicative of at least one previously observed behavior associated with the at least one user identifier;

analyze at least one risk factor associated with the electronic transaction; and

provide a risk assessment for the electronic transaction at least in part by combining the current user information, the history information associated with the at least one user identifier, and the at least one risk factor associated with the electronic transaction;

wherein the at least one user identifier comprises at least one network address;

wherein the at least one processor is further programmed to:

obtain a first risk value based on the current user information;

obtain a second risk value based on the history information associated with the at least one network address; and

obtain a third risk value based on the least one risk factor associated with the electronic transaction; and

use a plurality of weights to combine the first, second, and third risk values to thereby obtain an overall risk value indicative of a level of risk associated with the electronic transaction, wherein the plurality of weights comprises first, second, and third weights applied respectively to the first, second, and third risk values.

2. The system of claim 1 , wherein the at least one processor is further programmed to:

determine, based on the risk assessment, whether the electronic transaction is likely to be associated with an attack at a first publisher; and

upon detecting an attack at the first publisher, notify a second publisher of the attack.

3. The system of claim 1 , wherein the at least one processor is further to programmed to:

provide the overall risk value to a publisher associated with the electronic transaction.

4. The system of claim 1 , wherein the at least one processor is further to programmed to:

use the overall risk value to determine whether the electronic transaction is likely to be associated with an attack; and

provide to a publisher associated with the electronic transaction an indication of whether the electronic transaction is likely to be associated with an attack.

5. The system of claim 1 , wherein the current user information indicates whether a user associated with the electronic transaction provided a correct response to an identification test.

6. The system of claim 1 , wherein the current user information indicates how much time the user took to respond to an identification test.

7. The system of claim 1 , wherein the at least one processor is programmed to analyze history information associated with the at least one network address repeatedly over time, each analysis taking into account recent history information associated with the at least one network address.

8. The system of claim 1 , wherein the electronic transaction is a current transaction, and wherein the history information associated with the at least one network address comprises information regarding one or more prior transactions associated with the at least one network address.

9. A method for assessing security risk associated with an electronic transaction, the method comprising acts of:

analyzing current user information indicative of at least one user behavior observed in connection with the electronic transaction;

determining at least one user identifier associated with the electronic transaction;

analyzing history information associated with the at least one user identifier, the history information being indicative of at least one previously observed behavior associated with the at least one user identifier;

analyzing at least one risk factor associated with the electronic transaction; and

providing a risk assessment for the electronic transaction at least in part by combining the current user information, the history information associated with the at least one user identifier, and the at least one risk factor associated with the electronic transaction;

wherein the at least one user identifier comprises at least one network address;

further comprising acts of:

obtaining a first risk value based on the current user information;

obtaining a second risk value based on the history information associated with the at least one network address; and

obtaining a third risk value based on the least one risk factor associated with the electronic transaction; and

using a plurality of weights to combine the first, second, and third risk values to thereby obtain an overall risk value indicative of a level of risk associated with the electronic transaction, wherein the plurality of weights comprises first, second, and third weights applied respectively to the first, second, and third risk values.

10. The method of claim 9 , further comprising acts of:

determining, based on the risk assessment, whether the electronic transaction is likely to be associated with an attack at a first publisher; and

upon detecting an attack at the first publisher, notifying a second publisher of the attack.

11. The method of claim 9 , further comprising an act of:

providing the overall risk value to a publisher associated with the electronic transaction.

12. The method of claim 9 , further comprising acts of:

using the overall risk value to determine whether the electronic transaction is likely to be associated with an attack; and

providing to a publisher associated with the electronic transaction an indication of whether the electronic transaction is likely to be associated with an attack.

13. The method of claim 9 , wherein the current user information indicates whether a user associated with the electronic transaction provided a correct response to an identification test.

14. The method of claim 9 , wherein the current user information indicates how much time the user took to respond to an identification test.

15. The method of claim 9 , wherein the act of analyzing history information associated with the at least one network address is performed repeatedly over time, each analysis taking into account recent history information associated with the at least one network address.

16. The method of claim 9 , wherein the electronic transaction is a current transaction, and wherein the history information associated with the at least one network address comprises information regarding one or more prior transactions associated with the at least one network address.

Assignments (6)
CERTIFICATE OF AMALGAMATION Recorded Apr 23, 2018
From: NUDATA SECURITY INC.
To: MASTERCARD TECHNOLOGIES CANADA ULC
Reel/Frame 045997/0492 →
SECURITY INTEREST Recorded Jan 21, 2015
From: NUDATA SECURITY INC.
To: B.E.S.T. ACTIVE 365 FUND LP
Reel/Frame 034776/0797 →
SECURITY INTEREST Recorded Jan 21, 2015
From: NUDATA SECURITY INC.
To: TIER ONE CAPITAL LP
Reel/Frame 034777/0156 →
CHANGE OF NAME Recorded Jan 9, 2015
From: NUCAPTCHA INC.
To: NUDATA SECURITY INC.
Reel/Frame 034745/0827 →
CHANGE OF NAME Recorded Jan 9, 2015
From: LEAP MARKETING TECHNOLOGIES INC.
To: NUCAPTCHA INC,
Reel/Frame 034747/0739 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2014
From: BAILEY, CHRISTOPHER E.
To: LEAP MARKETING TECHNOLOGIES INC.
Reel/Frame 032673/0495 →
Continuity (4)
Continuation 12935927
Provisional Application 61050839 · May 6, 2008
Provisional Application 61041556 · Apr 1, 2008
Related Publication 20140317751A1 · Oct 23, 2014