IP Library Granted Patent US 11,687,941
Granted Patent B2
US 11,687,941 · App. 17/396,809 · Granted Jun 27, 2023

Systems and methods for detection of online payment mechanism fraud

Inventor: Ziv Isaiah (Tel-Aviv, IL)
Assignee: nSure.ai Payment Assurance Ltd.
G06Q20/4016G06Q20/3821G06Q20/405
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,687,941
App. No.
17/396,809
Granted
Jun 27, 2023
Kind
B2
Abstract

There is provided a method for detecting fraudulent use of monetary credentials during online transactions, comprising: receiving by a computing system, from a client terminal via a network, a request to obtain a digital voucher having a certain monetary equivalent using monetary credentials of a user, determining, a risk of malicious use of the monetary credentials according to an analysis of data denoting the context of the monetary credentials, providing, to the client terminal, a digital unusable voucher, wherein the digital unusable voucher is invalid for performing an online transaction, wherein the digital unusable voucher is structurally similar to a valid voucher that is valid for performing the online transaction, and identifying malicious use of the monetary credentials when within an elapsed predefined interval of time, no appeal in response to invalidity of the digital usable voucher during an attempt to perform the online transaction is received from the user.

Claims (19)

1. A system with improved performance in detection of malicious activity in a communication network by generating and transmitting digital invalid vouchers into said communication network, comprising:

a malicious activity detection server having a first network interface connecting the malicious activity detection server to a communication network, wherein said malicious activity detection server comprises at least one hardware processing unit and a data depository storing analysis code and for storing at least one invalid voucher:

at least one web server having a second network interface connecting said at least one web server to said communication network, wherein said at least one web server host at least one application providing online transactions; and

at least one validation server having a third network interface connecting said at least one validation server to said communication network;

wherein said malicious activity detection server is configured to receive from said at least one web server, over said communication network credentials of a user sending a request from a client terminal via said communication network to said at least one web server, said request is for obtaining a digital voucher having a certain value using said credentials of said user and wherein said malicious activity detection server is further configured to receive from said at least one validation server, via said communication network, data denoting a context of said credentials;

wherein said malicious activity detection server is configured to analyze said data denoting the context of the credentials by executing said analysis code which uses machine learning algorithm trained on data known to be associated with malicious activity, to determine by said analysis a risk of malicious use of the credentials and to dynamically generate and store in said data depository an invalid voucher, according to the risk determination of malicious use of the credentials, wherein the digital invalid voucher is structurally similar to a valid voucher;

wherein said malicious activity detection server is further configured to transmit said invalid voucher to the client terminal via the communication network, in response to the request to obtain the digital voucher, instead of providing the client terminal the requested digital voucher and

is further configured to monitor at least one interactive User Interface (UI) mechanism generated by the at least one web server and presented on the client terminal, said at least one UI mechanism allows the user who received the invalid voucher to submit an appeal, during a predefined interval of time, as a response of the user to invalidity of the digital invalid voucher during an attempt, of the user, to redeem the invalid voucher through a transaction between said client terminal and said at least one application of said at least one web server;

wherein said malicious activity detection server is configured to transmit to said validation server, over said communication network, a message indicative of an attempt of malicious use of said credentials when said malicious activity detection server identifies that an output of each of said at least one monitored UI mechanism does not indicate that said appeal was submitted by the user within the predefined interval of time; and

wherein said detection of said malicious use of the monetary credentials is performed by said malicious activity detection server without said at least one application hosted by said at least one web server and providing online transactions being aware of said detection.

2. The system of claim 1 , wherein a valid digital voucher having the certain value is provided to the client terminal via the network, when within the elapsed predefined interval of time, the appeal is received from the user.

3. The system of claim 1 , wherein said malicious activity detection server is further configured to identify authorized use of the credentials when within the elapsed predefined interval of time, the appeal is received from the user.

4. The system of claim 1 , wherein said malicious activity detection server is further configured to store in said data depository a profile of the user associated with authorized use of the credentials, and automatically detect authorized use of the credentials according to the profile when the user provides another request to obtain another digital voucher using the credentials.

5. The system of claim 1 , wherein said malicious activity detection server is further configured to instruct providing a refund to the user when within the elapsed predefined interval of time, the appeal is received from the user.

6. The system of claim 1 , wherein said malicious activity detection server is further configured to designate the user associated with the identified malicious use of the credentials as a malicious user and reject future requests to obtain the digital voucher by the malicious user.

7. The system of claim 1 , wherein said malicious activity detection server is further configured to

receive additional data associated with at least one of the user and the credentials, and wherein the analysis to determine the risk of malicious use of the credentials is based on the additional data.

8. The system of claim 7 , wherein the additional data includes one or more members selected from the group consisting of: third party data, empirically collected data, a profile of the user, behavior of the user, and contextual data.

9. The system of claim 1 , wherein said malicious activity detection server is further configured to store in said data depository, the credentials and the identified malicious use of the credentials, and to determine the risk of malicious use when the stored credentials are used in another request to obtain another digital voucher.

Assignments (2)
SECURITY INTEREST Recorded Jun 9, 2022
From: NSURE.AI PAYMENT ASSURANCE LTD.
To: SILICON VALLEY BANK
Reel/Frame 060156/0374 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2021
From: ISAIAH, ZIV
To: NSURE.AI PAYMENT ASSURANCE LTD.
Reel/Frame 057393/0819 →
Continuity (2)
Continuation 15648551 · Jul 13, 2017
Related Publication 20220036364A1 · Feb 3, 2022