IP Library Granted Patent US 11,165,762
Granted Patent B2
US 11,165,762 · App. 16/682,641 · Granted Nov 2, 2021

System and method for detecting malicious payment transaction activity using aggregate views of payment transaction data in a distributed network environment

Inventors: James Randall Ryan (Elgin, TX); Ruhul Alam (Austin, TX); James Edward Sylvana (Austin, TX); Conleth S. O'Connell, Jr. (Austin, TX)
Assignee: GIVEGAB, INC.
H04L63/08G06F21/30G06F21/36G06F21/554G06Q20/10G06Q20/4016G06Q20/4018G06Q30/0185H04L63/083H04L63/14H04L63/1416H04L63/1491G06F2221/2133G06Q20/382G06Q30/0279
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,165,762
App. No.
16/682,641
Granted
Nov 2, 2021
Kind
B2
Abstract

Embodiments of systems and methods for fraud prevention in an online distribution network are disclosed. In certain embodiments, service providers that provide forms in association with merchant's web sites for submission of transactions may implement pro-active threat detection based on an aggregate view of transactions in that distributed computer network.

Claims (68)

1. A system comprising a server computer coupled to a plurality of user devices and a plurality of payment gateways through a computer network, comprising:

a data store including aggregated data for a plurality of payment transactions conducted with a plurality of payment gateways through a computer network;

a processor;

a non-transitory computer readable medium, comprising instructions that when executed by the processor, cause the processor to perform steps comprising:

receiving a request from a first user device over the computer network in association with a web page of a merchant organization;

providing at least a portion of the web page to the first user device over the computer network in response to the request, wherein the web page includes one or more fields for entering payment information that are presented to a user in the web page at the first user device;

receiving a first response over the computer network, the first response sent from the web page and including first payment information for a requested first payment transaction;

storing response data as part of the aggregated data;

submitting a gateway request for the requested first payment transaction to a payment gateway of the plurality of payment gateways over the computer network;

receiving a gateway response from the payment gateway over the computer network, wherein the gateway response includes a transaction response code indicating a result of the requested first payment transaction;

storing gateway response data in association with the response data as part of the aggregated data;

accessing a fraud prevention rule, the fraud prevention rule including a pattern for identifying one more sets of data that matches the pattern;

evaluating the fraud prevention rule against the aggregated data to generate an identifier for each matching set of data based on that set of data and storing the identifiers for each of the matching sets of data as a fraud prevention list corresponding to that fraud prevention rule;

accessing the fraud prevention list;

generating a current identifier for a second payment transaction, wherein the current identifier is associated with a second response received from a second user device;

determining whether the current identifier matches any identifier of the fraud prevention list;

identifying the second payment transaction as fraudulent when the current identifier matches any identifier of the fraud prevention list; and

generating a fraud prevention response without submitting the second payment transaction to the plurality of payment gateways.

2. The system of claim 1 , wherein the fraud prevention response is an indication of success of the second payment transaction.

3. The system of claim 1 , wherein the fraud prevention response is not responding to the second user device or an undetermined response.

4. The system of claim 1 , wherein the portion of the web page is a form.

5. The system of claim 1 , wherein the first response is encoded by the portion of the web page.

6. The system of claim 1 , wherein the non-transitory computer readable medium comprises instructions that, when executed by the processor, cause the processor to further perform a step comprising:

receiving analytics data associated with the user's interaction with the portion of the web page, wherein the analytics data is part of the response data stored as part of the aggregated data.

7. The system of claim 1 , wherein the fraud prevention rule is evaluated based on an event trigger.

8. A method implemented at a server computer coupled to a plurality of user devices and a plurality of payment gateways through a computer network, the server computer including a data store including aggregated data for a plurality of payment transactions conducted with the plurality of payment gateways through the computer network, comprising:

receiving, by the server computer, a request from a first user device over the computer network in association with a web page of a merchant organization;

providing, by the server computer, at least a portion of the web page to the first user device over the computer network in response to the request, wherein the web page includes one or more fields for entering payment information that are presented to a user in the web page at the first user device;

receiving, by the server computer, a first response over the computer network, the first response sent from the web page and including first payment information for a requested first payment transaction;

storing, by the server computer, response data as part of the aggregated data;

submitting, by the server computer, a gateway request for the requested first payment transaction to a payment gateway of the plurality of payment gateways over the computer network;

receiving, by the server computer, a gateway response from the payment gateway over the computer network, wherein the gateway response includes a transaction response code indicating a result of the requested first payment transaction;

storing, by the server computer, gateway response data in association with the response data as part of the aggregated data;

accessing, by the server computer, a fraud prevention rule, the fraud prevention rule including a pattern for identifying one more sets of data that matches the pattern;

evaluating, by the server computer, the fraud prevention rule against the aggregated data to generate an identifier for each matching set of data based on that set of data and storing the identifiers for each of the matching sets of data as a fraud prevention list corresponding to that fraud prevention rule;

accessing, by the server computer, the fraud prevention list;

generating, by the server computer, a current identifier for a second payment transaction, wherein the current identifier is associated with a second response received from a second user device;

determining, by the server computer, whether the current identifier matches any identifier of the fraud prevention list;

identifying, by the server computer, the second payment transaction as fraudulent when the current identifier matches any identifier of the fraud prevention list; and

generating, by the server computer, a fraud prevention response without submitting the second payment transaction to the plurality of payment gateways.

9. The method of claim 8 , wherein the fraud prevention response is an indication of success of the second payment transaction.

10. The method of claim 8 , wherein the fraud prevention response is not responding to the second user device or an undetermined response.

11. The method of claim 8 , wherein the portion of the web page is a form.

12. The method of claim 8 , wherein the first response is encoded by the portion of the web page.

13. The method of claim 8 , further comprising receiving, by the server computer, analytics data associated with the user's interaction with the portion of the web page, wherein the analytics data is part of the response data stored as part of the aggregated data.

14. The method of claim 8 , wherein the fraud prevention rule is evaluated based on an event trigger.

15. A non-transitory computer readable media at a server computer coupled to a plurality of user devices and a plurality of payment gateways through the computer network, the server including a data store including aggregated data for a plurality of payment transactions conducted with the plurality of payment gateways through the computer network, the non-transitory computer readable medium comprising instructions that, when executed by the server computer, cause the server computer to perform steps comprising:

receiving, by the server computer, a request from a first user device over the computer network in association with a web page of a merchant organization;

providing, by the server computer, at least a portion of the web page to the first user device over the computer network in response to the request, wherein the web page includes one or more fields for entering payment information that are presented to a user in the web page at the first user device;

receiving, by the server computer, a first response over the computer network, the first response sent from the web page and including first payment information for a requested first payment transaction;

storing, by the server computer, response data as part of the aggregated data;

submitting, by the server computer, a gateway request for the requested first payment transaction to a payment gateway of the plurality of payment gateways over the computer network;

receiving, by the server computer, a gateway response from the payment gateway over the computer network, wherein the gateway response includes a transaction response code indicating a result of the requested first payment transaction;

storing, by the server computer, gateway response data in association with the response data as part of the aggregated data;

accessing, by the server computer, a fraud prevention rule, the fraud prevention rule including a pattern for identifying one more sets of data that matches the pattern;

evaluating, by the server computer, the fraud prevention rule against the aggregated data to generate an identifier for each matching set of data based on that set of data and storing the identifiers for each of the matching sets of data as a fraud prevention list corresponding to that fraud prevention rule;

accessing, by the server computer, the fraud prevention list;

generating, by the server computer, a current identifier for a second payment transaction, wherein the current identifier is associated with a second response received from a second user device;

determining, by the server computer, whether the current identifier matches any identifier of the fraud prevention list;

identifying, by the server computer, the second payment transaction as fraudulent when the current identifier matches any identifier of the fraud prevention list; and

generating, by the server computer, a fraud prevention response without submitting the second payment transaction to the plurality of payment gateways.

16. The non-transitory computer readable media of claim 15 , wherein the fraud prevention response is an indication of success of the second payment transaction.

17. The non-transitory computer readable media of claim 15 , wherein the fraud prevention response is not responding to the second user device or an undetermined response.

18. The non-transitory computer readable media of claim 15 , wherein the portion of the web page is a form.

19. The non-transitory computer readable media of claim 15 , wherein the first response is encoded by the portion of the web page.

20. The non-transitory computer readable media of claim 15 , further comprising instructions that, when executed by the server computer, cause the server computer to further perform steps comprising:

receiving analytics data associated with the user's interaction with the portion of the web page, wherein the analytics data is part of the response data stored as part of the aggregated data.

21. The non-transitory computer readable media of claim 15 , wherein the fraud prevention rule is evaluated based on an event trigger.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 057507, FRAME 0020 Recorded Mar 7, 2025
From: GOLUB CAPITAL MARKETS LLC
To: GIVEGAB, INC.
Reel/Frame 070441/0073 →
SECURITY INTEREST Recorded Mar 7, 2025
From: EVERYACTION, INC.
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 070443/0753 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Sep 8, 2021
From: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
To: GIVEGAB, INC.
Reel/Frame 057437/0646 →
PATENT SECURITY AGREEMENT Recorded Sep 8, 2021
From: GIVEGAB, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 057507/0020 →
NOTICE OF GRANT OF SECURITY INTERESTS IN PATENTS Recorded Apr 30, 2021
From: GIVEGAB, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 056106/0485 →
AGREEMENT ANCILLARY TO FORECLOSURE SALE AND ASSET PURCHASE AGREEMENT Recorded Nov 18, 2019
From: KIMBIA, INC.
To: GIVEGAB, INC.
Reel/Frame 051042/0054 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2019
From: RYAN, JAMES RANDALL; ALAM, RUHUL; SYLVANA, JAMES EDWARD; O'CONNELL, CONLETH S.
To: KIMBIA, INC.
Reel/Frame 051032/0279 →
Continuity (7)
Continuation 15446829 · Mar 1, 2017
Continuation 14988557 · Jan 5, 2016
Provisional Application 62099989 · Jan 5, 2015
Provisional Application 62099995 · Jan 5, 2015
Provisional Application 62099997 · Jan 5, 2015
Provisional Application 62099998 · Jan 5, 2015
Related Publication 20200145400A1 · May 7, 2020