IP Library Granted Patent US 10,083,439
Granted Patent B2
US 10,083,439 · App. 15/193,057 · Granted Sep 25, 2018

Device, system, and method of differentiating over multiple accounts between legitimate user and cyber-attacker

Inventors: Avi Turgeman (Cambridge, MA); Oren Kedem (Tel Aviv, IL)
Assignee: BIOCATCH LTD.
G06Q20/382G06F21/316G06Q20/40H04L63/08H04L63/1441G06F2221/2133H04L2463/082H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,083,439
App. No.
15/193,057
Granted
Sep 25, 2018
Kind
B2
Abstract

Devices, systems, and methods of user authentication, as well as automatic differentiation between a legitimate user and a cyber-attacker. A system detects that two different accounts of the same computerized service, were accessed by a single computing device over a short period of time. The system may employ various techniques in order to determine automatically whether a legitimate user accessed the two different account, such as, a husband accessing his own bank account and shortly after that accessing also his wife's bank account, or a payroll company accessing bank accounts of two clients for payroll management purposes. Conversely, the system is able to detect that the same user exhibited the same pattern of interactions when operating the two accounts, a pattern of interactions that does not frequently appear in the general population of legitimate users, thereby indicating that the single user is a cyber-attacker.

Claims (135)

1. A method comprising:

(a) detecting that within a pre-defined period of time, a single user is attempting to access, via a single computing device,

a first account that belongs to a first account-owner, and a second account that belongs to a second account-owner;

(b) querying a database that stores data about real-life relationship between people, and determining existence of a real-life family linkage or a real-life business linkage, between the first account owner and the second account-owner;

(c) based on said real-life linkage, determining that said single user is a legitimate human user that is genuinely associated with each one of said accounts, and is not a cyber-attacker that is illegitimately attempting to access multiple accounts.

2. The method of claim 1 , wherein the determining of step (c) is performed by generating a fraud-probability score, which indicates a probability that said single user is a cyber-attacker.

3. The method of claim 1 , wherein the determining of step (c) is performed by generating a binary-type indication which indicates either: (I) a determination that said single user is a legitimate human user that is genuinely associated with each one of said two or more accounts, or (II) a determination that said single user is a cyber-attacker that is illegitimately attempting to access multiple accounts.

4. The method of claim 1 , wherein,

if the generated linkage score value that indicates the strength of real-life linkage between the first account owner and the second account-owner, is greater than a pre-defined threshold value, then determining that said single user is a legitimate human user that is genuinely associated with each one of said two or more accounts;

if the generated linkage score value that indicates the strength of real-life linkage between the first account owner and the second account-owner, is smaller than said pre-defined threshold value, then determining that said single user is a cyber-attacker that is illegitimately attempting to access multiple accounts.

5. The method of claim 1 , wherein the determining of step (c) comprises:

(A) determining that the first account-owner and the second account-owner have different first-names and also have the same family-name;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

6. The method of claim 1 , wherein the determining of step (c) comprises:

(A) determining that the first account-owner and the second account-owner have different first-names; and further determining that the family-name of the first account-owner comprises (i) the family name of the second account-owner, and also (ii) an additional string;

(B) based on the two determining operations of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

7. The method of claim 1 , wherein the determining of step (c) comprises:

(A) determining that the first account-owner and the second account-owner are associated with the same real-life address;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

8. The method of claim 1 , wherein the determining of step (c) comprises:

(A) determining that the first account-owner and the second account-owner were previously accessed by two legitimate users from a same, single, Internet Protocol (IP) address;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

9. The method of claim 1 , wherein the determining of step (c) comprises:

(A) determining that the first account-owner and the second account-owner were previously accessed by two legitimate users from a same, single, electronic device;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

10. The method of claim 1 , wherein the determining of step (c) comprises:

(A) determining that the first account-owner and the second account-owner are associated with the same single employer;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

11. The method of claim 1 , wherein the determining of step (c) comprises:

(A) determining that the first account-owner and the second account-owner are associated with the same single corporate entity;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

12. The method of claim 1 , wherein the determining of step (c) comprises:

(A) by querying a database that stores data about real-life relationship between people, determining that there exists a family relationship between the first account-owner and the second account-owner even though the first and account-owner and the second account-owner do not have the same last-name;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

13. The method of claim 1 , wherein the determining of step (c) comprises:

(A) by querying a database that stores data about real-life relationship between people, determining that the first account-owner is a spouse of the second account-owner;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

14. The method of claim 1 , wherein the determining of step (c) comprises:

(A) by querying a database that stores data about real-life relationship between people, determining that the first account-owner is a parent of the second account-owner;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

15. The method of claim 1 , wherein the determining of step (c) comprises:

(A) by querying a database that stores data about corporate relationship among corporate entities, determining that: the first account-owner, who is a first corporate entity, is affiliated by a corporate relationship with the second account-owner, who is a second corporate entity;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

16. The method of claim 1 , wherein the determining of step (c) comprises:

(A) by querying a database that stores data about corporate relationship among corporate entities, determining that: the first account-owner, who is a first corporate entity, is a subsidiary of the second account-owner, who is a second corporate entity;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

17. The method of claim 1 , wherein the determining of step (c) comprises:

(A) by querying a database that stores data about corporate relationship among corporate entities, determining that the same majority shareholder owns a majority interest in the first account-owner and also owns a majority interest in the second account-owner;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

18. The method of claim 1 , wherein the determining of step (c) comprises:

(A) analyzing a similarity between (i) a corporate name of the first account-owner, and (ii) a corporate name of the second account-owner; and based on said analyzing, determining that: the first account-owner, who is a first corporate entity, is affiliated by a corporate relationship with the second account-owner, who is a second corporate entity;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

19. The method of claim 1 , wherein the determining of step (c) comprises:

(A) determining that said single user accessed said first account and said second account, via the same single computing device which is associated with a funds-managing entity that manages funds for clients;

(B) determining that the first account belongs to a first client of said funds-managing entity;

(C) determining that the second account belongs to a second client of said funds-managing entity;

(D) based on the determining operations of steps (A) and (B) and (C), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

20. The method of claim 1 , wherein the determining of step (c) comprises:

(A) determining that said single user accessed said first account and said second account, via the same single computing device which is associated with an accounting service provider that provides accounting services to clients;

(B) determining that the first account belongs to a first client of said accounting service provider;

(C) determining that the second account belongs to a second client of said accounting service provider;

(D) based on the determining operations of steps (A) and (B) and (C), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

21. The method of claim 1 , wherein the determining of step (c) comprises:

(A) determining that said single user accessed said first account and said second account, via the same single computing device which is associated with a payroll service provider that provides payroll services to clients;

(B) determining that the first account belongs to a first client of said payroll service provider;

(C) determining that the second account belongs to a second client of said payroll service provider;

(D) based on the determining operations of steps (A) and (B) and (C), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

22. The method of claim 1 , wherein the determining of step (c) comprises:

(A) determining that said single user accessed said first account and said second account, via the same single computing device which is associated with a consulting service provider that provides consulting services to clients;

(B) determining that the first account belongs to a first client of said consulting service provider;

(C) determining that the second account belongs to a second client of said consulting service provider;

(D) based on the determining operations of steps (A) and (B) and (C), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

23. The method of claim 1 , wherein the determining of step (c) comprises:

(A) determining that the first account-owner is a legal custodian of the second account-owner;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

24. The method of claim 1 , wherein the determining of step (c) comprises:

(A) determining that there exists a trustee-and-beneficiary relationship between the first account-owner and the second account-owner;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

25. The method of claim 1 , wherein the determining of step (c) comprises:

(A) determining that the first account and the second account are currently non-linked to each other; and further determining that the first account and the second account used to be linked to each other at a past time-point;

(B) based on the determining of step (A), determining that said single user is a legitimate human user that is genuinely associated with each one of said first account and second account.

26. The method of claim 1 , comprising:

(A) monitoring operations that said single user performs as logged-in user in said first account;

(B) determining a first pattern of operations that said single user performed as logged-in user in said first account;

(C) monitoring operations that said single user performs as logged-in user in said second account;

(D) determining a second pattern of operations that said single user performed as logged-in user in said second account;

(E) determining that the first pattern of operations is identical to the second pattern of operations;

(F) based on the determining of step (E), determining that said single user is a cyber-attacker attempting to attack said first account and said second account.

27. The method of claim 1 , comprising:

(A) monitoring operations that said single user performs as logged-in user in said first account;

(B) determining a first pattern of operations that said single user performed as logged-in user in said first account;

(C) monitoring operations that said single user performs as logged-in user in said second account;

(D) determining a second pattern of operations that said single user performed as logged-in user in said second account;

(E) determining that the first pattern of operations is similar, beyond a pre-defined level of similarity, to the second pattern of operations;

(F) based on the determining of step (E), determining that said single user is a cyber-attacker attempting to attack said first account and said second account.

28. The method of claim 1 , comprising:

(A) monitoring operations that said single user performs as logged-in user in said first account;

(B) determining a first pattern of operations that said single user performed as logged-in user in said first account;

(C) monitoring operations that said single user performs as logged-in user in said second account;

(D) determining a second pattern of operations that said single user performed as logged-in user in said second account;

(E) determining that the first pattern of operations is identical to the second pattern of operations, and further determining that the first account is not related to the second account;

(F) based on the determining operations of step (E), determining that said single user is a cyber-attacker attempting to attack said first account and said second account.

29. The method of claim 1 , comprising:

(A) monitoring operations that said single user performs as logged-in user in said first account;

(B) determining a first pattern of operations that said single user performed as logged-in user in said first account;

(C) monitoring operations that said single user performs as logged-in user in said second account;

(D) determining a second pattern of operations that said single user performed as logged-in user in said second account;

(E) determining that the first pattern of operations is similar, beyond a pre-defined level of similarity, to the second pattern of operations, and further determining that the first account is not related to the second account;

(F) based on the determining operations of step (E), determining that said single user is a cyber-attacker attempting to attack said first account and said second account.

30. The method of claim 1 , comprising:

(A) monitoring operations that said single user performs as logged-in user in said first account;

(B) determining a first pattern of operations that said single user performed as logged-in user in said first account;

(C) monitoring operations that said single user performs as logged-in user in said second account;

(D) determining a second pattern of operations that said single user performed as logged-in user in said second account;

(E) determining that the first pattern of operations is identical to the second pattern of operations, and further determining that the first pattern of operations is abnormal relative to a general distribution of operation patterns of a general group of users of said computerized service;

(F) based on the determining of step (E), determining that said single user is a cyber-attacker attempting to attack said first account and said second account.

31. The method of claim 1 , comprising:

(A) monitoring operations that said single user performs as logged-in user in said first account;

(B) determining a first pattern of operations that said single user performed as logged-in user in said first account;

(C) monitoring operations that said single user performs as logged-in user in said second account;

(D) determining a second pattern of operations that said single user performed as logged-in user in said second account;

(E) determining that the first pattern of operations is similar, beyond a pre-defined level of similarity, to the second pattern of operations, and further that the first pattern of operations is abnormal relative to a general distribution of operation patterns of a general group of users of said computerized service;

(F) based on the determining of step (E), determining that said single user is a cyber-attacker attempting to attack said first account and said second account.

32. The method of claim 1 , comprising:

(A) monitoring operations that said single user performs as logged-in user in said first account;

(B) determining a first pattern of operations that said single user performed as logged-in user in said first account;

(C) monitoring operations that said single user performs as logged-in user in said second account;

(D) determining a second pattern of operations that said single user performed as logged-in user in said second account;

(E) determining that the first pattern of operations is identical to the second pattern of operations, and further determining that the first account is non-related to the second account, and further determining that the first pattern of operations is abnormal relative to a general distribution of operation patterns of a general group of users of said computerized service;

(F) based on the determining of step (E), determining that said single user is a cyber-attacker attempting to attack said first account and said second account.

33. The method of claim 1 , comprising:

(A) monitoring operations that said single user performs as logged-in user in said first account; and determining a first pattern of operations that said single user performed as logged-in user in said first account;

(B) monitoring operations that said single user performs as logged-in user in said second account; and determining a second pattern of operations that said single user performed as logged-in user in said second account;

(C) determining that the first pattern of operations is similar, beyond a pre-defined level of similarity, to the second pattern of operations, and further determining that the first account is non-related to the second account, and further that the first pattern of operations is abnormal relative to a general distribution of operation patterns of a general group of users of said computerized service;

(D) based on the determining of step (C), determining that said single user is a cyber-attacker attempting to attack said first account and said second account.

Assignments (6)
INTELLECTUAL PROPERTY SECURITY AGREEMENT TERMINATION UNDER REEL/FRAME: 049480/0823 Recorded Sep 14, 2020
From: KREOS CAPITAL VI (EXPERT FUND) LP
To: BIOCATCH LTD.
Reel/Frame 053769/0729 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT TERMINATION UNDER REEL/FRAME: 040233/0426 Recorded Sep 14, 2020
From: KREOS CAPITAL V (EXPERT FUND) L.P.
To: BIOCATCH LTD.
Reel/Frame 053770/0145 →
SECURITY INTEREST Recorded Jun 16, 2019
From: BIOCATCH LTD.
To: KREOS CAPITAL VI (EXPERT FUND) L.P.
Reel/Frame 049480/0823 →
CHANGE OF ADDRESS Recorded Jun 13, 2019
From: BIOCATCH LTD.
To: BIOCATCH LTD.
Reel/Frame 049459/0302 →
SECURITY INTEREST Recorded Nov 6, 2016
From: BIOCATCH LTD.
To: KREOS CAPITAL V (EXPERT FUND) L.P.
Reel/Frame 040233/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2016
From: TURGEMAN, AVI; KEDEM, OREN
To: BIOCATCH LTD.
Reel/Frame 039174/0319 →
Continuity (9)
Continuation In Part 14325398 · Jul 8, 2014
Continuation In Part 14320656 · Jul 1, 2014
Continuation In Part 14325396 · Jul 8, 2014
Continuation In Part 13922271 · Jun 20, 2013
Continuation In Part 13877676
Provisional Application 62190264 · Jul 9, 2015
Provisional Application 61843915 · Jul 9, 2013
Provisional Application 61417479 · Nov 29, 2010
Related Publication 20160307191A1 · Oct 20, 2016
Cited By (2)
US 12,380,455 US 12,603,940