IP Library › Granted Patent US 11,729,214
Granted Patent B1
US 11,729,214 · App. 17/458,152 · Granted Aug 15, 2023

Method of generating and using credentials to detect the source of account takeovers

Inventors: Jordan Wright (San Antonio, TX); William Jennings Woodson (San Antonio, TX); Justin Gray (San Antonio, TX)
Assignee: United Services Automobile Association (USAA)
H04L63/1491H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,729,214
App. No.
17/458,152
Granted
Aug 15, 2023
Kind
B1
Abstract

Disclosed herein are systems and methods that may generate so-called “honey credentials” that are transmitted to a “phishing” website, and are then stored into a honey credential database. The honey credentials appear to be valid credentials, but whenever a bad actor attempts to access an enterprise using the honey credentials, security appliances the enterprise may update the records of the honey credential database to include one or more unique identifiers for each bad actor device that attempts to access the enterprise network using the honey credentials. A server may automatically query the honey credential database to identify other accounts that have been accessed by devices that used the honey credentials to access the enterprise. The server may then flag the accounts and restrict their functionality.

Claims (63)

1. A method comprising:

receiving, by a computer, a number of phishing reports associated with a uniform resource locator, wherein the uniform resource locator is associated with a phishing website, wherein the phishing reports are from multiple users;

in response to the number of phishing reports associated with the uniform resource locator satisfying a threshold, selecting, by the computer, from an intelligence file received from a threat intelligence server, the uniform resource locator, wherein at least one of the phishing reports is from a user associated with a user account;

generating, by the computer, a set of fake credentials that resemble information associated with the user account of the user;

transmitting, by the computer, the set of fake credentials to the uniform resource locator associated with the phishing website;

in response to a webserver receiving a web session request to access the user account using the set of fake credentials from an identified attacker device associated with the uniform resource locator:

generating, by the computer, a unique identifier for the identified attacker device;

storing the unique identifier in one or more logging databases, wherein the one or more logging databases are configured to store data associated with one or more devices and their corresponding users and user accounts;

updating, by the computer, a database associated with the user account to comprise the unique identifier for the identified attacker device;

flagging the user account, wherein the flagging restricts transfers, from the user account, of amounts of money that exceed a predetermined threshold; and

in response to determining that the user account is accessed via the identified attacker device, restricting all money transfers from the user account.

2. The method of claim 1 , further comprising:

transmitting, by the computer, an electronic message to a fraud computing system, wherein the electronic message comprises identification of the user of the user account, a device associated with the user, and the unique identifier with the identified attacker device.

3. The method of claim 1 , further comprising:

querying the one or more logging databases to determine other user accounts that have been accessed by the identified attacker device.

4. The method of claim 1 , further comprising:

generating, by the computer, the set of fake credentials uniquely associated with the uniform resource locator.

5. The method of claim 1 , wherein the computer generates the intelligence file based on detecting one or more websites having at least one component linked to a component of a website associated with the computer.

6. The method of claim 1 , wherein the computer generates the intelligence file based on one or more users reposting phishing emails.

7. The method of claim 1 , wherein the flagging restricts a user from changing login credentials associated with the user account.

8. A non-transitory computer-readable medium storing instructions that, when executed by a computing system, cause the computing system to perform operations comprising:

receiving, by a computer, a number of phishing reports associated with a uniform resource locator, wherein the uniform resource locator is associated with a phishing website, wherein the phishing reports are from multiple users;

in response to the number of phishing reports associated with the uniform resource locator satisfying a threshold, selecting, by the computer, from an intelligence file received from a threat intelligence server, the uniform resource locator, wherein at least one of the phishing reports is from a user associated with a user account;

generating, by the computer, a set of fake credentials that resemble information associated with the user account of the user;

transmitting, by the computer, the set of fake credentials to the uniform resource locator associated with the phishing website;

in response to a webserver receiving a web session request to access the user account using the set of fake credentials from an identified attacker device associated with the uniform resource locator:

generating, by the computer, a unique identifier for the identified attacker device;

storing the unique identifier in one or more logging databases, wherein the one or more logging databases are configured to store data associated with one or more devices and their corresponding users and user accounts;

updating, by the computer, a database associated with the user account to comprise the unique identifier for the identified attacker device;

flagging the user account, wherein the flagging restricts transfers, from the user account, of amounts of money that exceed a predetermined threshold; and

in response to determining that the user account is accessed via the identified attacker device, restricting all money transfers from the user account.

9. The non-transitory computer-readable medium of claim 8 , wherein the operations further comprise:

transmitting, by the computer, an electronic message to a fraud computing system, wherein the electronic message comprises identification of the user of the user account, a device associated with the user, and the unique identifier with the identified attacker device.

10. The non-transitory computer-readable medium of claim 8 , wherein the operations further comprise:

querying the one or more logging databases to determine other user accounts that have been accessed by the identified attacker device.

11. The non-transitory computer-readable medium of claim 8 , wherein the operations further comprise:

generating, by the computer, the set of fake credentials uniquely associated with the uniform resource locator.

12. The non-transitory computer-readable medium of claim 8 , wherein the computer generates the intelligence file based on detecting one or more websites having at least one component linked to a component of a website associated with the computer.

13. The non-transitory computer-readable medium of claim 8 , wherein the computer generates the intelligence file based on one or more users reposting phishing emails.

14. The non-transitory computer-readable medium of claim 8 , wherein the flagging restricts a user from changing login credentials associated with the user account.

15. A system comprising:

one or more processors; and

one or more memories storing instructions that, when executed by the one or more processors, cause the system to perform a process comprising:

receiving, by a computer, a number of phishing reports associated with a uniform resource locator, wherein the uniform resource locator is associated with a phishing website, wherein the phishing reports are from multiple users;

in response to the number of phishing reports associated with the uniform resource locator satisfying a threshold, selecting, by the computer, from an intelligence file received from a threat intelligence server, the uniform resource locator, wherein at least one of the phishing reports is from a user associated with a user account;

generating, by the computer, a set of fake credentials that resemble information associated with the user account of the user;

transmitting, by the computer, the set of fake credentials to the uniform resource locator associated with the phishing website;

in response to a webserver receiving a web session request to access the user account using the set of fake credentials from an identified attacker device associated with the uniform resource locator:

generating, by the computer, a unique identifier for the identified attacker device;

storing the unique identifier in one or more logging databases, wherein the one or more logging databases are configured to store data associated with one or more devices and their corresponding users and user accounts;

updating, by the computer, a database associated with the user account to comprise the unique identifier for the identified attacker device;

flagging the user account, wherein the flagging restricts transfers, from the user account, of amounts of money that exceed a predetermined threshold; and

in response to determining that the user account is accessed via the identified attacker device, restricting all money transfers from the user account.

16. The system according to claim 15 , wherein the process further comprises:

transmitting, by the computer, an electronic message to a fraud computing system, wherein the electronic message comprises identification of the user of the user account, a device associated with the user, and the unique identifier with the identified attacker device.

17. The system according to claim 15 , wherein the process further comprises:

querying the one or more logging databases to determine other user accounts that have been accessed by the identified attacker device.

18. The system according to claim 15 , wherein the process further comprises:

generating, by the computer, the set of fake credentials uniquely associated with the uniform resource locator.

19. The system according to claim 15 , wherein the computer generates the intelligence file based on detecting one or more websites having at least one component linked to a component of a website associated with the computer.

20. The system according to claim 15 , wherein

the computer generates the intelligence file based on one or more users reposting phishing emails, and

the flagging restricts a user from changing login credentials associated with the user account.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2023
From: WRIGHT, JORDAN; WOODSON, WILLIAM JENNINGS; GRAY, JUSTIN SOMMERS
To: UIPCO
Reel/Frame 063319/0500 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2023
From: UIPCO, LLC
To: UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
Reel/Frame 063319/0710 →
Continuity (2)
Continuation 15789302 · Oct 20, 2017
Provisional Application 62410606 · Oct 20, 2016