IP Library Granted Patent US 10,530,807
Granted Patent B2
US 10,530,807 · App. 16/392,367 · Granted Jan 7, 2020

Compromised password detection based on abuse and attempted abuse

Inventors: Lachlan A. Maxwell (Ashburn, VA); Donald J. McQueen (Leesburg, VA); William C. Wakefield, III (McLean, VA)
Assignee: Oath Inc.
H04L63/1441G06F21/46H04L63/083H04L63/107H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,530,807
App. No.
16/392,367
Filed
Apr 23, 2019
Granted
Jan 7, 2020
Kind
B2
Art Unit
2439
USPC
726/23
Abstract

Systems and methods are disclosed for analyzing a plurality of failed login records that correspond to failed login attempts detected by a computing system, to identify suspicious patterns of activity that can facilitate the supplementation of password blacklists for improving account security. To accomplish the foregoing, failed login records that include information associated with failed login attempts are obtained for analysis. The failed login records are analyzed to identify a set of failed login records that show initial characteristics of a suspicious pattern of activity. The information included in the set of failed login records are further analyzed to determine whether a suspicious pattern of activity is actually present. When a suspicious pattern of activity is identified in the set of failed login records, the passwords used in the failed login attempts are stored in password blacklists associated with the account identifier(s) with which the passwords were used.

Claims (41)

1. A computer-implemented method, comprising:

obtaining a list that includes a record generated for each of a plurality of detected failed login attempts, each record including a corresponding account identifier, a corresponding piece of password data, a corresponding location reference, and a corresponding temporal reference associated with one of the plurality of detected failed login attempts;

determining that a first location reference in the list is identical to a second location reference in the list, that a first account identifier in the list is different than a second account identifier in the list, and that a number of generated records in the list exceeds a predefined threshold of failed login attempts for a predefined duration based on one or more temporal references in the list;

selecting a password blacklist from a plurality of password blacklists based on a determination that an average travel time between two physical locations determined based on the first location reference and the second location reference exceeds a calculated duration between two or more temporal references in the list;

modifying the password blacklist to include a first piece of password data; and

employing the password blacklist to prevent an association of the first piece of password data with at least one account identifier associated with the password blacklist.

2. The computer-implemented method of claim 1 , the selecting the password blacklist from the plurality of password blacklists based on a determination that the first location reference is associated with a first country and the second location reference is associated with a second country different than the first country.

3. The computer-implemented method of claim 1 , the selecting the password blacklist from the plurality of password blacklists based on a determination that two or more account identifiers in the list are identical.

4. The computer-implemented method of claim 1 , the

selecting the password blacklist from the plurality of password blacklists based on a defined suspicious pattern of activity type, the method comprising:

modifying the password blacklist to include a reference to the defined suspicious pattern of activity type.

5. The computer-implemented method of claim 1 , wherein each corresponding location reference in the list includes a network address associated with one of the plurality of detected failed login attempts.

6. The computer-implemented method of claim 1 , wherein each corresponding temporal reference in the list includes a timestamp associated with one of the plurality of detected failed login attempts.

7. The computer-implemented method of claim 1 , wherein each corresponding piece of password data in the list includes a password hash associated with one of the plurality of detected failed login attempts.

8. A non-transitory computer-readable medium storing instructions that, when executed, cause performance of operations comprising:

obtaining a list that includes a record generated for each of a plurality of detected failed login attempts, each record including a corresponding account identifier, a corresponding piece of password data, a corresponding location reference, and a corresponding temporal reference associated with one of the plurality of detected failed login attempts;

determining that a first account identifier in the list is identical to a second account identifier in the list, that a first piece of password data in the list is different than a second piece of password data in the list, and that a number of generated records in the list exceeds a predefined threshold of failed login attempts for a predefined duration based on one or more temporal references in the list;

selecting a password blacklist from a plurality of password blacklists based on a determination that an average travel time between two physical locations determined based on a first location reference and a second location reference exceeds a calculated duration between two or more temporal references in the list;

modifying the password blacklist to include the first piece of password data; and

employing the password blacklist to prevent an association of the first piece of password data with at least one account identifier associated with the password blacklist.

9. The non-transitory computer-readable medium of claim 8 , the selecting the password blacklist from the plurality of password blacklists based on a determination that the first location reference is associated with a first country and the second location reference is associated with a second country different than the first country.

10. The non-transitory computer-readable medium of claim 8 , the selecting the password blacklist from the plurality of password blacklists based on a determination that two or more account identifiers in the list are identical.

11. The non-transitory computer-readable medium of claim 8 , the selecting the password blacklist from the plurality of password blacklists based on a defined suspicious pattern of activity type, the operations comprising:

modifying the password blacklist to include a reference to the defined suspicious pattern of activity type.

12. The non-transitory computer-readable medium of claim 8 , wherein each corresponding location reference in the list includes a network address associated with one of the plurality of detected failed login attempts.

13. The non-transitory computer-readable medium of claim 8 , wherein each corresponding temporal reference in the list includes a timestamp associated with one of the plurality of detected failed login attempts.

14. The non-transitory computer-readable medium of claim 8 , wherein each corresponding piece of password data in the list includes a password hash associated with one of the plurality of detected failed login attempts.

15. A system comprising:

a processor; and

a computer-readable medium storing instructions that, when executed by the processor, cause the processor to:

obtain a list that includes a record generated for each of a plurality of detected failed login attempts, each record including a corresponding account identifier, a corresponding piece of password data, a corresponding location reference, and a corresponding temporal reference associated with one of the plurality of detected failed login attempts;

determine that a first account identifier in the list is identical to a second account identifier in the list, that a first location reference in the list is different than a second location reference in the list, and that a number of generated records in the list exceeds a predefined threshold of failed login attempts for a predefined duration based on one or more temporal references in the list;

select a password blacklist from a plurality of password blacklists based on a determination that an average travel time between two physical locations determined based on the first location reference and the second location reference exceeds a calculated duration between two or more temporal references in the list;

modify the password blacklist to include a first piece of password data; and

employ the password blacklist to prevent an association of the first piece of password data with at least one account identifier associated with the password blacklist.

16. The system of claim 15 , the selecting the password blacklist from the plurality of password blacklists based on a determination that the first location reference is associated with a first country and the second location reference is associated with a second country different than the first country.

17. The system of claim 15 , the selecting the password blacklist from the plurality of password blacklists based on a determination that two or more account identifiers in the list are identical.

18. The system of claim 15 , the selecting the password blacklist from the plurality of password blacklists based on a defined suspicious pattern of activity type, the computer-readable medium storing instructions that, when executed by the processor, cause the processor to:

modify the password blacklist to include a reference to the defined suspicious pattern of activity type.

19. The system of claim 15 , wherein each corresponding location reference in the list includes a network address associated with one of the plurality of detected failed login attempts.

20. The system of claim 15 , wherein each corresponding piece of password data in the list includes a password hash associated with one of the plurality of detected failed login attempts.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2022
From: MAXWELL, LACHLAN A.; MCQUEEN, DONALD J.; WAKEFIELD, WILLIAM C., III
To: AOL INC.
Reel/Frame 059825/0963 →
CHANGE OF NAME Recorded May 5, 2022
From: AOL INC.
To: OATH INC.
Reel/Frame 059856/0380 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2021
From: VERIZON MEDIA INC.
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 057453/0431 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2020
From: OATH INC.
To: VERIZON MEDIA INC.
Reel/Frame 054258/0635 →
Continuity (2)
Continuation 15005319 · Jan 25, 2016
Related Publication 20190253451A1 · Aug 15, 2019