IP Library Granted Patent US 12,079,813
Granted Patent B2
US 12,079,813 · App. 17/162,039 · Granted Sep 3, 2024

System and method for identifying suspicious destinations

Inventors: Jamie Gamble (Toronto, CA); Gadi Shpits (Toronto, CA); Ilya Kolmanovich (Toronto, CA); Cormac O'Keeffe (Toronto, CA)
Assignee: ROYAL BANK OF CANADA
G06Q20/4016G06Q20/4014H04L63/0876H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,079,813
App. No.
17/162,039
Granted
Sep 3, 2024
Kind
B2
Abstract

Transaction destinations are identified by identifying requests for a login page of a web server for a financial institution and determining a referring website for each of the requests; classifying the referring websites into classes, each of the classes having a risk rating; identifying logins to access the web server and determining a user associated with each login; associating each of the logins with one of the requests and the referring website for that request; for each of the users, identifying transactions occurring within a time period from when the login was initiated; for each of the transactions occurring within the time period, associating a transaction destination of that transaction with the referring website for that login; and assigning a risk rating to each of the transaction destinations based at least in part on a risk rating of the class of the associated referring website.

Claims (81)

1. A computer-implemented method for facilitating electronic financial transactions, the method performed by a web server, the method comprising:

receiving data records representing requests for a login page of the web server, wherein the requests include HTTP requests;

upon receiving the data records representing the requests, determining a referring website for each of the identified requests based on an HTTP referrer header of each of said requests, said HTTP referrer header including an address of said referring website;

scanning, by a site classifier, each of said referring websites to extract keywords from each respective referring website;

identifying, by said site classifier using natural language processing, an industry of each respective referring website;

generating classifications for classifying the referring websites into classes based on a classification system and said industry, each of the classes having a risk rating;

detecting data payloads representing logins to access the web server;

upon detecting the data payloads representing the logins, determining a user identifier associated with each of the logins;

associating each of the data payloads representing the logins with one of the identified requests and with the referring website for that identified request;

for each of the user identifiers, determining transactions occurring within a time period from when the one of the logins was initiated;

for each of the transactions occurring within the time period, associating an transaction destination with the referring website for that one of the logins;

assigning a risk rating to each of the transaction destinations based at least in part on the risk rating of the class of the associated referring website; and

permitting or blocking an electronic transaction of the transactions occurring within the time period based on the risk rating of the transaction destination associated with that transaction.

2. The computer-implemented method of claim 1 , wherein the determining the referring website comprises extracting an identifier of the referring website web server logs.

3. The computer-implemented method of claim 1 , wherein the associating each of the logins with one of the requests and the referring website for that request is based at least in part on at least one of:

comparing a time stamp of the login and a time stamp of the request; or

a cookie upon login linking an account of the user with a browser of the user.

4. The computer-implemented method of claim 1 , wherein the determining the user associated with each login is based at least in part on at least one of:

an IP address in a web server log; or

an IP address in a HTTP request.

5. The computer-implemented method of claim 1 , comprising, grouping users from a common class of the referring websites and identifying, for each of the groups of users, a common transaction destination.

6. The computer-implemented method of claim 5 , wherein the common transaction destination is identified from the destinations containing a common word.

7. The computer-implemented method of claim 1 , wherein the time period is at least one of:

between ten and thirty minutes; or

twenty minutes.

8. The computer-implemented method of claim 1 , wherein the risk ratings of the classes are based at least in part on a whitelist of websites.

9. The computer-implemented method of claim 1 , wherein the transaction destination of at least one of the transaction is at least one of:

an identification of an entity; or

a bank account.

10. The computer-implemented method of claim 1 , comprising at least one of:

identifying additional transaction that send funds to one or more of the transaction destinations;

assigning a risk rating to the additional transaction based at least in part on the risk ratings of the transaction destinations; or

for each of the transaction, identifying a transaction type and assigning a risk rating to the transaction type based at least in part on the risk rating of the transaction destination.

11. A computer system comprising:

a processor; and

a memory in communication with the processor, the memory storing instructions that, when executed by the processor configure the processor to:

receive data records representing requests for a login page of a web server, wherein the requests include HTTP requests;

upon receiving the data records representing the requests, determine a referring website for each of the identified requests based on an HTTP referrer header of each of said requests, said HTTP referrer header including an address of said referring website;

scan, by a site classifier, each of said referring websites to extract keyboards from each respective referring website;

identifying, by said site classifier using natural language processing, an industry of each respective referring website;

generate classifications for classifying the referring websites into classes based on a classification system and said industry, each of the classes having a risk rating;

detecting data payloads representing logins to access the web server;

upon detecting the data payloads representing the logins, determine a user identifier associated with each of the identified login;

associate each of the data payloads representing the identified logins with one of the identified requests and with the referring website for that identified request;

for each of the user identifiers, determine transaction occurring within a time period from when the one of the logins was initiated;

for each of the transaction occurring within the time period, associate an transaction destination of that transaction with the referring website for that one of the logins;

assign a risk rating to each of the transaction destinations based at least in part on the risk rating of the class of the associated referring website; and

permit or block an electronic transaction of the transaction occurring within the time period based on the risk rating of the transaction destination associated with that transaction.

12. The computer system of claim 11 , wherein to determine the referring website the processor is configured to extract an identifier of the referring website web server logs.

13. The computer system of claim 11 , wherein the associating each of the logins with one of the requests and the referring website for that request is based at least in part on at least one of:

the processor comparing a time stamp of the login and a time stamp of the request; or

a cookie upon login linking an account of the user with a browser of the user.

14. The computer system of claim 11 , wherein the determining the user associated with each login is based at least in part on at least one of:

an IP address in a web server log; or

an IP address in a HTTP request.

15. The computer system of claim 11 , wherein the processor is configured to group users from a common class of the referring websites and identifying, for each of the groups of users, a common transaction destination.

16. The computer system of claim 15 , wherein the common transaction destination is identified from the destinations containing a common word.

17. The computer system of claim 11 , wherein the time period is at least one of:

between ten and thirty minutes; or

twenty minutes.

18. The computer system of claim 11 , wherein the risk ratings of the classes are based at least in part on a whitelist of websites.

19. The computer system of claim 11 , wherein the transaction destination of at least one of the transaction is at least one of:

an identification of an entity; or

a bank account.

20. The computer system of claim 11 , wherein the processor is configured to at least one of:

identify additional transaction that send funds to one or more of the transaction destinations;

assign a risk rating to the additional transaction based at least in part on the risk ratings of the transaction destinations; or

for each of the transaction, identify an transaction type and assigning a risk rating to the transaction type based at least in part on the risk rating of the transaction destination.

21. A non-transitory computer-readable medium having computer executable instructions stored thereon for execution by a computing device, that when executed perform a method comprising:

receiving data records representing requests for a login page of a web server, wherein the requests include HTTP requests;

upon receiving the data records representing the requests, determining a referring website for each of the identified requests based on an HTTP referrer header of each of said requests, said HTTP referrer header including an address of said referring website;

scanning, by a site classifier, each of said referring websites to extract keywords from each respective referring website;

identifying, by said site classifier using natural language processing, an industry of each respective referring website;

generating classifications for classifying the referring websites into classes based on a classification system and said industry, each of the classes having a risk rating;

detecting data payloads representing logins to access the web server;

upon detecting the data payloads representing the logins, determining a user identifier associated with each of the logins;

associating each of the data payloads representing the logins with one of the identified requests and with the referring website for that identified request;

for each of the user identifiers, determining transaction occurring within a time period from when the one of the logins was initiated;

for each of the transaction occurring within the time period, associating an transaction destination of that transaction with the referring website for that one of the logins;

assigning a risk rating to each of the transaction destinations based at least in part on the risk rating of the class of the associated referring website; and

permitting or blocking an electronic transaction of the transaction occurring within the time period based on the risk rating of the transaction destination associated with that transaction.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2024
From: GAMBLE, JAMIE
To: ROYAL BANK OF CANADA
Reel/Frame 068058/0627 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2024
From: SHPITS, GADI; KOLMANOVICH, ILYA; O’KEEFFE, CORMAC
To: ROYAL BANK OF CANADA
Reel/Frame 068058/0853 →
Continuity (2)
Provisional Application 62968192 · Jan 31, 2020
Related Publication 20210241281A1 · Aug 5, 2021