IP Library Granted Patent US 10,484,415
Granted Patent B1
US 10,484,415 · App. 15/381,908 · Granted Nov 19, 2019

Systems and methods for detecting security risks in network pages

Inventor: Brant Peterson (Denver, CO)
Assignee: Worldpay, LLC
H04L63/1433G06Q20/401G06Q20/02G06Q20/40G06Q30/02H04L63/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,484,415
App. No.
15/381,908
Granted
Nov 19, 2019
Kind
B1
Abstract

Embodiments include methods and systems for detecting security risks in network pages, comprising providing at least one secure transaction page to a secure transaction provider, the secure transaction page enabling the secure transaction provider to request secure transactions, determining a request rate for the secure transaction page associated with the secure transaction provider, determining a predetermined threshold for a change in request rate for the secure transaction page by the secure transaction provider, determining that the predetermined threshold, for the change in request rate for the secure transaction page by the secure transaction provider, has been exceeded, and providing a notification to the secure transaction provider based on the determination that the predetermined threshold, for the change in request rate for the secure transaction page by the secure transaction provider, has been exceeded.

Claims (67)

1. A method for detecting security risks in network pages, comprising:

providing at least one secure transaction page to a secure transaction provider, the secure transaction page enabling the secure transaction provider to request secure transactions;

determining an expected request rate for the secure transaction page by the secure transaction provider based on a history of request rate for the secure transaction page;

determining an actual request rate for the secure transaction page by the secure transaction provider, the actual request rate being indicative of a number of calls for the secure transaction page over a predetermined time period;

determining a first predetermined threshold for a change in request rate for the secure transaction page by the secure transaction provider, the change in request rate representing a difference between the expected request rate and the actual request rate;

determining that the first predetermined threshold, for the change in request rate for the secure transaction page by the secure transaction provider, has been exceeded, with the actual request rate being lower than the expected request rate by an amount exceeding the first predetermined threshold;

in response to determining that the first predetermined threshold, for the change in request rate for the secure transaction page by the secure transaction provider, has been exceeded, declining at least one of a new token request or a card-not-present (CNP) token request from the secure transaction provider;

providing a notification to the secure transaction provider based on the determination that the first predetermined threshold, for the change in request rate for the secure transaction page by the secure transaction provider, has been exceeded;

receiving secure transaction data from the secure transaction provider; and

determining a second predetermined threshold, the second predetermined threshold being lower than the first predetermined threshold, for a change in request rate for the secure transaction page by the secure transaction provider, based on the secure transaction data from the secure transaction provider.

2. The method of claim 1 , wherein determining the first predetermined threshold for the change in request rate comprises:

comparing the actual request rate with the expected request rate to determine the first predetermined threshold for the change in request rate.

3. The method of claim 1 , further comprising:

receiving sensitive data corresponding to an account via the secure transaction page from the secure transaction provider;

generating a token corresponding to the sensitive data; and

providing the token corresponding to the sensitive data to the secure transaction provider.

4. The method of claim 1 , further comprising:

determining whether the secure transaction page is functioning;

receiving an electronic transaction request associated with the secure transaction provider; and

in response to determining that the secure transaction page is not functioning, declining the electronic transaction request.

5. The method of claim 1 , wherein the secure transaction provider is an online merchant.

6. The method of claim 1 , wherein the secure transaction page is an iFrame hosted by a third party, such that sensitive data received via the secure transaction page is isolated from the secure transaction page.

7. A system for detecting security risks in network pages, the system comprising:

a data storage device storing instructions for detecting security risks in secure transaction pages; and

a processor configured to execute the instructions to perform a method comprising:

providing at least one secure transaction page to a secure transaction provider, the secure transaction page enabling the secure transaction provider to request secure transactions;

determining an expected request rate for the secure transaction page by the secure transaction provider based on a history of request rate for the secure transaction page;

determining an actual request rate for the secure transaction page by the secure transaction provider, the actual request rate being indicative of a number of calls for the secure transaction page over a predetermined time period;

determining a first predetermined threshold for a change in request rate for the secure transaction page by the secure transaction provider, the change in request rate representing a difference between the expected request rate and the actual request rate;

determining that the first predetermined threshold, for the change in request rate for the secure transaction page by the secure transaction provider, has been exceeded, with the actual request rate being lower than the expected request rate by an amount exceeding the first predetermined threshold;

in response to determining that the first predetermined threshold, for the change in request rate for the secure transaction page by the secure transaction provider, has been exceeded, declining at least one of a new token request or a card-not-present (CNP) token request from the secure transaction provider;

providing a notification to the secure transaction provider based on the determination that the first predetermined threshold, for the change in request rate for the secure transaction page by the secure transaction provider, has been exceeded;

receiving secure transaction data from the secure transaction provider; and

determining a second predetermined threshold, the second predetermined threshold being lower than the first predetermined threshold, for a change in request rate for the secure transaction page by the secure transaction provider, based on the secure transaction data from the secure transaction provider.

8. The system of claim 7 , wherein determining the first predetermined threshold for the change in request rate comprises:

comparing the actual request rate with the expected request rate to determine the first predetermined threshold for the change in request rate.

9. The system of claim 7 , the processor executing a method further comprising:

receiving sensitive data corresponding to an account via the secure transaction page from the secure transaction provider;

generating a token corresponding to the sensitive data; and

providing the token corresponding to the sensitive data to the secure transaction provider.

10. The system of claim 7 , the processor executing a method further comprising:

determining whether the secure transaction page is functioning;

receiving an electronic transaction request associated with the secure transaction provider; and

in response to determining that the secure transaction page is not functioning, declining the electronic transaction request.

11. The system of claim 7 , wherein the secure transaction provider is an online merchant.

12. The system of claim 7 , wherein the secure transaction page is an iFrame hosted by a third party, such that sensitive data received via the secure transaction page is isolated from the secure transaction page.

13. A non-transitory computer-readable medium storing instructions that, when executed by a transaction processor, cause the transaction processor to perform a method for detecting security risks in network pages, the method comprising:

providing at least one secure transaction page to a secure transaction provider, the secure transaction page enabling the secure transaction provider to request secure transactions;

determining an expected request rate for the secure transaction page by the secure transaction provider based on a history of request rate for the secure transaction page;

determining an actual request rate for the secure transaction page by the secure transaction provider, the actual request rate being indicative of a number of calls for the secure transaction page over a predetermined time period;

determining a first predetermined threshold for a change in request rate for the secure transaction page by the secure transaction provider, the change in request rate representing a difference between the expected request rate and the actual request rate;

determining that the first predetermined threshold, for the change in request rate for the secure transaction page by the secure transaction provider, has been exceeded, with the actual request rate being lower than the expected request rate by an amount exceeding the first predetermined threshold;

in response to determining that the first predetermined threshold, for the change in request rate for the secure transaction page by the secure transaction provider, has been exceeded, declining at least one of a new token request or a card-not-present (CNP) token request from the secure transaction provider;

providing a notification to the secure transaction provider based on the determination that the first predetermined threshold, for the change in request rate for the secure transaction page by the secure transaction provider, has been exceeded;

receiving secure transaction data from the secure transaction provider; and

determining a second predetermined threshold, the second predetermined threshold being lower than the first predetermined threshold, for a change in request rate for the secure transaction page by the secure transaction provider, based on the secure transaction data from the secure transaction provider.

14. The computer-readable medium of claim 13 , wherein determining the first predetermined threshold for the change in request rate comprises:

comparing the actual request rate with the expected request rate to determine the first predetermined threshold for the change in request rate.

15. The computer-readable medium of claim 13 , the transaction processor performing a method further comprising:

receiving sensitive data corresponding to an account via the secure transaction page from the secure transaction provider;

generating a token corresponding to the sensitive data; and

providing the token corresponding to the sensitive data to the secure transaction provider.

16. The computer-readable medium of claim 13 , the transaction processor performing a method further comprising:

determining whether the secure transaction page is functioning;

receiving an electronic transaction request associated with the secure transaction provider; and

in response to determining that the secure transaction page is not functioning, declining the electronic transaction request.

17. The computer-readable medium of claim 13 , wherein the secure transaction provider is an online merchant.

Assignments (6)
RELEASE OF SECURITY INTERESTS RECORDED AT REEL/FRAMES 066626/0655, 066625/0426, 066625/0347, AND 066625/0276 Recorded Jan 12, 2026
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: WORLDPAY, LLC; WORLDPAY ISO AND ECOMMERCE, LLC; PAYMETRIC, LLC; WORLDPAY US, LLC
Reel/Frame 074314/0622 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 066624/0719 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: WORLDPAY, LLC
Reel/Frame 074315/0412 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066624/0719 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 066626/0655 →
CHANGE OF NAME Recorded Aug 6, 2018
From: VANTIV, LLC
To: WORLDPAY, LLC
Reel/Frame 046723/0234 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2016
From: PETERSON, BRANT
To: VANTIV, LLC
Reel/Frame 040674/0149 →
Cited By (3)
US 12,423,454 US 12,423,455 US 12,694,143