IP Library Granted Patent US 10,284,590
Granted Patent B2
US 10,284,590 · App. 15/386,989 · Granted May 7, 2019

Automatic detection of points of compromise

Inventors: Miguel Ramos de Araujo (Porto, PT); Miguel Sousa Borges de Almeida (Lisbon, PT); Pedro Gustavo Santos Rodrigues Bizarro (Lisbon, PT)
Assignee: Feedzai—Consultadoria e Inovação Tecnólogica, S.A.
H04L63/1433G06F21/577G06F2221/2111G06Q20/4016
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,284,590
App. No.
15/386,989
Granted
May 7, 2019
Kind
B2
Abstract

Techniques described herein include determining, for each account of several accounts, an element blame score (EBS) for each potential point of compromise (POC) of a plurality of POCs. Determining the EBS includes: representing the determinations as a computer computational matrix operation, dividing a matrix of the operation into blocks, and distributing the blocks among nodes for distributed computation. The method further includes determining an overall compromise blame score (OCBS) for each potential POC based on the determined EBS and determining whether the OCBSs have converged. If the OCBSs have converged, select at least one of the potential POCs as a likely POC based at least on the corresponding OCBS of the selected likely POC. If the determined OCBSs have not converged, updating the OCBS for each potential POC and the EBSs for each potential POC.

Claims (48)

1. A method, comprising:

for each account of a plurality of accounts, determining an element blame score for each potential point of compromise (POC) of a plurality of potential locations of compromise, wherein determining the element blame score includes:

assigning an initial value to the element blame score based at least in part on an even division of blame among locations with which an account has interacted;

representing the determinations as at least a computer computational matrix operation,

dividing a matrix of the computer computational matrix operation into computational blocks, and

distributing the blocks among a plurality of computational computer nodes for distributed computer computation;

determining an overall compromise blame score for each potential point of compromise of the plurality of potential locations of compromise based on the determined element blame score including by summing the determined element blame scores and dividing by a number of accounts with which the potential POC interacted;

determining whether the determined overall compromise blame scores have converged;

in the event the determined overall compromise blame scores have converged, selecting at least one of the plurality of potential locations of compromise as a likely point of compromise based at least on the corresponding overall compromise blame score of the selected likely point of compromise; and

in the event the determined overall compromise blame scores have not converged, updating the overall compromise blame score for each potential point of compromise and the element blame scores for each potential point of compromise of the plurality of potential locations of compromise.

2. The method of claim 1 , further comprising determining the plurality of accounts based on received transaction data, the transaction data including transaction parameter values.

3. The method of claim 1 , wherein the determining the element blame score includes comparing a convergence criteria with (i) a first element blame score generated by a first combination of identified transaction parameter values and (ii) a second element blame score generated by a second combination of identified transaction parameter values.

4. The method of claim 1 , wherein the overall compromise blame score for a potential POC includes a sum of the determined element blame scores divided by a number of accounts with which the potential POC interacted weighted by at least one past calculation of the overall compromise blame score.

5. The method of claim 1 , wherein the determining whether the determined overall compromise blame scores have converged includes determining that at least one of the overall compromise blame scores meets a convergence criteria.

6. The method of claim 5 , wherein the determining that at least one of the overall compromise blame scores meets the convergence criteria includes determining whether a threshold amount of time has elapsed.

7. The method of claim 1 , further comprising dynamically identifying the plurality of accounts and the plurality of potential points of compromise, wherein the identification of the plurality of accounts and the plurality of potential points of compromise is based on at least one interaction between at least one of the plurality of accounts and at least one of the plurality of potential points of compromise within a predefined time period.

8. The method of claim 1 , further comprising receiving a list of accounts known to be compromised.

9. The method of claim 1 , further comprising providing an identifier of the selected likely point of compromise.

10. The method of claim 9 , wherein selecting the likely point of compromise includes determining a pattern in geographical locations of the plurality of potential points of compromise, and the identifier identifies a grouping of the plurality of the potential points of compromise selected based at least in part on the pattern.

11. The method of claim 1 , further comprising determining the plurality of potential points of compromise based on each potential point of compromise having interacted at least once with a compromised account.

12. The method of claim 1 , wherein the determining the element blame score includes using at least one previously-calculated probability and a relative confidence between a current overall compromise blame score and the at least one previously-calculated probability to determine the overall compromise blame score.

13. The method of claim 1 , wherein the updating includes splitting a blame proportionally based on a measure of confidence.

14. The method of claim 1 , wherein after the overall compromise blame score for each potential point of compromise and the element blame scores for each potential point of compromise of the plurality of potential points of compromise are updated in the event the determined overall compromise blame scores have not converged, a determination of whether the updated determined overall compromise blame scores have converged is performed.

15. The method of claim 1 , further comprising preprocessing the computer computational matrix operation to remove those accounts that are determined to not be compromised such that calculations are not made for the removed accounts.

16. The method of claim 1 , wherein each of the computational blocks is associated with a different subset of input data to be utilized to fill the computer computational matrix operation.

17. The method of claim 1 , wherein each of the computational blocks includes a different subset of elements of the computer computational matrix operation.

18. A system for identifying a point of compromise, comprising:

a processor configured to:

for each account of a plurality of accounts, determine an element blame score for each potential point of compromise (POC) of a plurality of potential locations of compromise, wherein determining the element blame score includes:

assigning an initial value to the element blame score based at least in part on an even division of blame among locations with which an account has interacted;

representing the determinations as at least a computer computational matrix operation,

dividing a matrix of the computer computational matrix operation into computational blocks, and

distributing the blocks among a plurality of computational computer nodes for distributed computer computation;

determine an overall compromise blame score for each potential point of compromise of the plurality of potential locations of compromise based on the determined element blame score including by summing the determined element blame scores and dividing by a number of accounts with which the potential POC interacted;

determine whether the determined overall compromise blame scores have converged;

in the event the determined overall compromise blame scores have converged, select at least one of the plurality of potential locations of compromise as a likely point of compromise based at least on the corresponding overall compromise blame score of the selected likely point of compromise; and

in the event the determined overall compromise blame scores have not converged, update the overall compromise blame score for each potential point of compromise and the element blame scores for each potential point of compromise of the plurality of potential locations of compromise; and

a memory coupled to the processor and configured to provide the processor with instructions.

19. A computer program product for identifying a point of compromise, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

for each account of a plurality of accounts, determining an element blame score for each potential point of compromise (POC) of a plurality of potential locations of compromise, wherein determining the element blame score includes:

assigning an initial value to the element blame score based at least in part on an even division of blame among locations with which an account has interacted;

representing the determinations as at least a computer computational matrix operation,

dividing a matrix of the computer computational matrix operation into computational blocks, and

distributing the blocks among a plurality of computational computer nodes for distributed computer computation;

determining an overall compromise blame score for each potential point of compromise of the plurality of potential locations of compromise based on the determined element blame score including by summing the determined element blame scores and dividing by a number of accounts with which the potential POC interacted;

determining whether the determined overall compromise blame scores have converged;

in the event the determined overall compromise blame scores have converged, selecting at least one of the plurality of potential locations of compromise as a likely point of compromise based at least on the corresponding overall compromise blame score of the selected likely point of compromise; and

in the event the determined overall compromise blame scores have not converged, updating the overall compromise blame score for each potential point of compromise and the element blame scores for each potential point of compromise of the plurality of potential locations of compromise.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE'S NAME PREVIOUSLY RECORDED AT REEL: 041813 FRAME: 0507. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded May 17, 2021
From: ARAÚJO, MIGUEL RAMOS DE; BORGES DE ALMEIDA, MIGUEL SOUSA; BIZARRO, PEDRO GUSTAVO SANTOS RODRIGUES
To: FEEDZAI - CONSULTADORIA E INOVAÇÃO TECNOLÓGICA, S.A.
Reel/Frame 056267/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2017
From: RAMOS DE ARAUJO, MIGUEL; BORGES DE ALMEIDA, MIGUEL SOUSA; BIZARRO, PEDRO GUSTAVO SANTOS RODRIGUES
To: FEEDZAI - CONSULTADORIA E INOVACAO TECNOLOGICA, S.A.
Reel/Frame 041813/0507 →
Continuity (2)
Provisional Application 62293535 · Feb 10, 2016
Related Publication 20170230404A1 · Aug 10, 2017
Cited By (1)
US 12,719,883