IP Library Granted Patent US 9,684,888
Granted Patent B2
US 9,684,888 · App. 14/680,898 · Granted Jun 20, 2017

Online fraud solution

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,684,888
App. No.
14/680,898
Granted
Jun 20, 2017
Kind
B2
Abstract

Various embodiments of the invention provide solutions (including inter alia, systems, methods and software) for dealing with online fraud. Some embodiments function to access and/or obtain information from (and/or receive data from) a data source; the data might, for example, indicate a possible instance of online fraud. Certain embodiments, therefore, can be configured to analyze the data, e.g., to determine whether the data indicate a likely instance of online fraud. Such instances may be further investigated, and/or a response may be initiated. Data sources can include, without limitation, web pages, email messages, online chat sessions, domain zone files, newsgroups (and/or postings thereto), etc. Data obtained from the data sources can include, without limitation, suspect domain registrations, uniform resource locators, references to trademarks, advertisements, etc.

Claims (37)

1. A computer system for investigating suspicious information associated with a suspect server to determine whether the suspect server is associated with fraudulent activities, the computer system comprising:

a master computer; and

at least one memory device coupled with the master computer, the at least one memory device having stored therein a sequence of instructions which, when executed by the master computer, cause the computer system to:

obtain, by the master computer, a data set associated with the suspect server;

analyze, by the master computer, the data set to detect potential fraudulent activity associated with a data set by identifying, within the data set, a request for specified personal information from a user;

detect potential fraudulent activity;

generate, in response to detecting potential fraudulent activity and by using a dilution engine, a plurality of responses to the request for specified personal information, each response including a set of safe data responsive to the request for specified personal information;

associate each of the plurality of responses with one of a plurality of IP addresses from at least one network block or one or more proxy servers;

transmit the plurality of responses to the suspect server;

monitor for the use of the set of safe data on a network; and

trace the use of the set of safe data to a potential perpetrator.

2. The system of claim 1 , wherein the plurality of responses is generated using the dilution engine, and wherein the dilution engine operates on a computer separate from the master computer.

3. The system of claim 1 , wherein the master computer is configured to analyze at least one of an e-mail message, a newsgroup posting, a web page and a transcript, in conjunction with analyzing the data set to detect fraudulent activity.

4. The system of claim 1 , wherein the master computer is configured to identify potential fraudulent activity by detecting that the request for specified personal information comprises a request for at least one of a financial institution account number, a credit card number including an expiration date and/or security code, a userID, a password, a mother's maiden name, a social security number, and a driver's license number.

5. The system of claim 1 , wherein the plurality of responses are generated using a plurality of response computers, each response computer comprising the dilution engine.

6. The system of claim 1 , further comprising a megaproxy, the megaproxy configured to transmit the plurality of responses to the suspect server to assist in making the plurality of responses appear to originate from an IP address contained within the at least one network block.

7. The system of claim 1 , wherein the one or more proxy servers are configured so that the plurality of responses are transmitted serially through at least two of the proxy servers before being transmitted to the suspect server.

8. The system of claim 7 , wherein header information within the plurality of responses is disguised to hide the identity of a computer upon which the plurality of responses are generated.

9. The system of claim 7 , wherein at least one of the plurality of proxy servers omits data from, and/or substitutes false or pseudorandom data into, at least one field in an HTTP request associated with the transmission of the plurality of responses.

10. A method of investigating suspicious information associated with a suspect server to determine whether the suspect server is associated with fraudulent activities, comprising:

obtaining, by a master computer, a data set associated with the suspect server;

analyzing, by the master computer, the data set to detect potential fraudulent activity associated with the data set by identifying, within the data set, a request for specified personal information from a user;

detecting potential fraudulent activity in response to identifying the request for specified personal information;

generating, in response to detecting potential fraudulent activity and by using a dilution engine, a plurality of responses to the request for specified personal information, each response including a set of safe data responsive to the request for specified personal information;

associating each of the plurality of responses with one of a plurality of IP addresses from at least one network block or one or more proxy servers;

transmitting the plurality of responses to the suspect server;

monitoring for the use, subsequent to said transmitting, of the set of safe data on a network; and

tracing the use of the set of safe data to a potential perpetrator.

11. The method of claim 10 , wherein the master computer is configured to analyze at least one of an e-mail message, a newsgroup posting, a web page and a transcript, in conjunction with analyzing the data set to detect fraudulent activity.

12. The method of claim 10 , wherein the master computer is configured to identify potential fraudulent activity by detecting that the request of specified personal information comprises a request for at least one of a financial institution account number, a credit card number including an expiration date and/or security code, a userID, a password, a mother's maiden name, a social security number, and a driver's license number.

13. The method of claim 10 , wherein the plurality of responses are generated using a plurality of response computers, each response computer comprising the dilution engine.

14. The method of claim 10 , wherein the plurality of responses are transmitted to the suspect server using a megaproxy, the megaproxy configured to assist in making the plurality of responses appear to originate from an IP address contained within the at least one network block.

15. The method of claim 10 , wherein the one or more proxy servers are configured so that the plurality of responses are transmitted serially through at least two proxy servers before being transmitted to the suspect server.

16. The method of claim 15 , wherein header information within the plurality of responses is disguised to hide the identity of a computer upon which the plurality of responses are generated.

17. The method of claim 15 , wherein at least one of the plurality of proxy servers omits data from, and/or substitutes false or pseudorandom data into, at least one field in an HTTP request associated with the transmission of the plurality of responses.

18. The method of claim 10 , wherein at least one proxy server is an internet service provider, and the plurality of responses are transmitted to the internet service provider before being transmitted to the suspect server.

19. The method of claim 10 , wherein the generating the plurality of responses is done using the dilution engine.

Assignments (10)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2020
From: CAMELOT UK BIDCO LIMITED
To: OPSEC ONLINE LIMITED
Reel/Frame 052070/0544 →
SECURITY INTEREST Recorded Nov 1, 2019
From: CAMELOT UK BIDCO LIMITED
To: BANK OF AMERICA, N.A.
Reel/Frame 050906/0284 →
RELEASE OF SECURITY INTEREST Recorded Nov 1, 2019
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: CAMELOT UK BIDCO LIMITED
Reel/Frame 050911/0796 →
SECURITY INTEREST Recorded Nov 1, 2019
From: CAMELOT UK BIDCO LIMITED
To: WILMINGTON TRUST, N.A. AS COLLATERAL AGENT
Reel/Frame 050906/0553 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2017
From: EMARKMONITOR INC.
To: MARKMONITOR INC.
Reel/Frame 041889/0384 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2016
From: THOMSON REUTERS GLOBAL RESOURCES
To: CAMELOT UK BIDCO LIMITED
Reel/Frame 040206/0448 →
SECURITY INTEREST Recorded Oct 3, 2016
From: CAMELOT UK BIDCO LIMITED
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040205/0156 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2016
From: HEPWORTH, JAMES
To: EMARKMONITOR, INC.
Reel/Frame 039719/0033 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2016
From: SHRAIM, IHAB; SHULL, MARK
To: MARKMONITOR, INC.
Reel/Frame 037887/0394 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2016
From: MARKMONITOR, INC.
To: THOMSON REUTERS GLOBAL RESOURCES
Reel/Frame 037887/0676 →