IP Library Granted Patent US 10,176,482
Granted Patent B1
US 10,176,482 · App. 15/724,946 · Granted Jan 8, 2019

System to identify vulnerable card readers

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,176,482
App. No.
15/724,946
Granted
Jan 8, 2019
Kind
B1
Abstract

Example embodiments relate to a network-based vulnerability detection system configured to access a database of customer transaction data corresponding to a set of card readers that includes transaction codes, receive an identification of a set of compromised card readers among the set of card readers, identify common transaction codes within the transaction data of the set of compromised card readers, and correlate the common transaction codes to one or more instances of fraud associated with the compromised set of card readers. In some example embodiments, the vulnerability detection system may be applied to monitor one or more card readers, receive transaction data corresponding to transaction conducted through the card readers, identify the common transaction codes correlated to the instances of fraud, and cause display of a notification that includes an indication of the instance of fraud at a client device.

Claims (80)

1. A method comprising:

accessing historical transaction data gathered from a set of devices, the historical transaction data including a set of device identifiers and transaction codes, the device identifiers and the transaction codes corresponding to a set of transactions conducted through the set of devices identified by the device identifiers;

identifying a set of compromised devices from among the set of devices based on a subset of the historical transaction data, the subset associated with the set of compromised devices;

identifying a common transaction code within the subset of the historical transaction data;

correlating the common transaction code to an instance of fraud associated with the compromised set of devices;

receiving new transaction data from a first device, the new transaction data including a new set of transaction codes and a first device identifier that identifiers the first device;

detecting the common transaction code within the new transaction data from the first device; and

causing display of a notification at a client device in response to the identifying the common transaction code within the new transaction data, the notification including a presentation of the first device identifier of the first device.

2. The method of claim 1 , wherein the method further comprises:

disabling the first device in response to the identifying the common transaction code within the new transaction data from the first device.

3. The method of claim 1 , wherein the method further comprises:

causing the first device to display an indication that the first device is compromised in response to the detecting the common transaction code within the new transaction data from the first device.

4. The method of claim 1 , wherein the transaction codes among the historical transaction data include timestamps that indicate a time of a transaction, and wherein the identifying the set of compromised devices from among the set of devices based on the subset of the historical transaction data includes:

receiving an identification of a time period;

identifying the subset of the historical transaction data based on the time period, the subset of the historical transaction data having timestamps within the time period; and

identifying the set of compromised devices based on the subset of the historical transaction data.

5. The method of claim 1 , wherein the new transaction data includes transaction details, and the method further comprises:

generating a report that includes the first device identifier, and the transaction details.

6. The method of claim 1 , wherein the new transaction data includes at least a user account identifier, and the method further comprises:

transmitting the notification to a user account associated with the user account identifier in response to the identifying the common transaction code within the new transaction data from the first device.

7. The method of claim 1 , wherein the method further comprises:

collecting the new transaction data from the first device for a duration;

determining a rate in which the common transaction code appears within the new transaction data within the duration;

calculating a vulnerability score based on the rate and the duration; and

assigning the vulnerability score to the first device.

8. The method of claim 7 , wherein the first device is of a device type, and wherein the method further comprises:

retrieving an expected rate of the first device in response to the determining the rate in which the common transaction code appears within the new transaction data within the duration, the expected rate based on the device type;

determining a threshold value to apply to the vulnerability score based on the expected rate;

determining that the vulnerability score transgresses the threshold value; and

causing display of the notification at the client device in response to the determining that the vulnerability score transgresses the threshold value.

9. The method of claim 7 , wherein the duration includes at least one of:

a length of time; and

a maximum number of transactions conducted through the first device.

10. The method of claim 1 , wherein the transaction codes indicate a status of a transaction, and wherein the status includes at least one of:

an incomplete transaction;

a complete transaction; and

a declined transaction.

11. A system comprising:

one or more processors of a machine; and

a memory storing instructions that, when executed by at least one processor among the one or more processors, causes the machine to perform operations comprising:

accessing historical transaction data gathered from a set of devices, the historical transaction data including a set of device identifiers and transaction codes, the device identifiers and the transaction codes corresponding to a set of transactions conducted through the set of devices identified by the device identifiers;

identifying a set of compromised devices from among the set of devices based on a subset of the historical transaction data, the subset associated with the set of compromised devices;

identifying a common transaction code within the subset of the historical transaction data;

correlating the common transaction code to an instance of fraud associated with the compromised set of devices;

receiving new transaction data from a first device, the new transaction data including a new set of transaction codes and a first device identifier that identifiers the first device;

detecting the common transaction code within the new transaction data from the first device; and

causing display of a notification at a client device in response to the identifying the common transaction code within the new transaction data, the notification including a presentation of the first device identifier of the first device.

12. The system of claim 11 , wherein the instructions cause the system to perform operations further comprising:

disabling the first device in response to the identifying the common transaction code within the new transaction data from the first device.

13. The system of claim 11 , wherein the instructions cause the system to perform operations further comprising:

causing the first device to display an indication that the first device is compromised in response to the detecting the common transaction code within the new transaction data from the first device.

14. The system of claim 11 , wherein the transaction codes among the historical transaction data include timestamps that indicate a time of a transaction, and wherein the identifying the set of compromised devices from among the set of devices based on the subset of the historical transaction data includes:

receiving an identification of a time period;

identifying the subset of the historical transaction data based on the time period, the subset of the historical transaction data having timestamps within the time period; and

identifying the set of compromised devices based on the subset of the historical transaction data.

15. The system of claim 11 , wherein the new transaction data includes transaction details, and the method further comprises:

generating a report that includes the first device identifier, and the transaction details.

16. The system of claim 11 , wherein the new transaction data includes at least a user account identifier, and the instructions cause the system to perform operations further comprising:

transmitting the notification to a user account associated with the user account identifier in response to the identifying the common transaction code within the new transaction data from the first device.

17. The system of claim 11 , wherein the instructions cause the system to perform operations further comprising:

collecting the new transaction data from the first device for a duration;

determining a rate in which the common transaction code appears within the new transaction data within the duration;

calculating a vulnerability score based on the rate and the duration; and

assigning the vulnerability score to the first device.

18. The system of claim 17 , wherein the first device is of a device type, and wherein the instructions cause the system to perform operations further comprising:

retrieving an expected rate of the first device in response to the determining the rate in which the common transaction code appears within the new transaction data within the duration, the expected rate based on the device type;

determining a threshold value to apply to the vulnerability score based on the expected rate;

determining that the vulnerability score transgresses the threshold value; and

causing display of the notification at the client device in response to the determining that the vulnerability score transgresses the threshold value.

19. The system of claim 17 , wherein the duration includes at least one of:

a length of time; and

a maximum number of transactions conducted through the first device.

20. A non-transitory machine-readable storage medium comprising instructions that, when executed by one or more processors of a machine, cause the machine to perform operations comprising:

accessing historical transaction data gathered from a set of devices, the historical transaction data including a set of device identifiers and transaction codes, the device identifiers and the transaction codes corresponding to a set of transactions conducted through the set of devices identified by the device identifiers;

identifying a set of compromised devices from among the set of devices based on a subset of the historical transaction data, the subset associated with the set of compromised devices;

identifying a common transaction code within the subset of the historical transaction data;

correlating the common transaction code to an instance of fraud associated with the compromised set of devices;

receiving new transaction data from a first device, the new transaction data including a new set of transaction codes and a first device identifier that identifiers the first device;

detecting the common transaction code within the new transaction data from the first device; and

causing display of a notification at a client device in response to the identifying the common transaction code within the new transaction data, the notification including a presentation of the first device identifier of the first device.

Assignments (8)
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2017
From: SHUKLA, ANANYA; NORRIS, DANIEL
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 044421/0762 →