IP Library Granted Patent US 12,475,218
Granted Patent B2
US 12,475,218 · App. 17/973,004 · Granted Nov 18, 2025

Method and system for identifying a compromised point-of-sale terminal network

Inventor: Ruslan Chebesov (Desnogorsk, RU)
Assignee: GROUP-IB GLOBAL PRIVATE LIMITED
G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,475,218
App. No.
17/973,004
Granted
Nov 18, 2025
Kind
B2
Abstract

A method and a system for identifying a compromised Point-of-Sale (POS) terminal network are provided. The method comprises: receiving identifiers of a plurality of compromised geographical areas identifying, in a given compromised geographical area of the plurality of compromised geographical areas, at least one respective POS terminal network of a plurality of POS terminal networks; determining, for the at least one respective POS terminal network, a plurality of compromise parameters; determining, based on the plurality of compromise parameters, a respective compromise probability value for the at least one respective POS terminal network; ranking, by the processor, the plurality of POS terminal networks according to respective compromise probability values associated therewith; and determining a top-ranked POS terminal network as being the compromised POS terminal network.

Claims (58)

1 . A computer-implementable method of identifying a compromised Point-of-Sale (POS) terminal network, the method comprising:

generating a commercial entities database for a given geographical area of a plurality of geographical areas by executing a pre-configured script as a search robot, wherein the commercial entities database includes entries having (i) a respective identifier of the given geographical area and (ii commercial entities present in the given geographical area, and the entries are obtained from results of a plurality of search queries sent by the search robot to crawl and parse a communication network for the given geographical area;

accessing one or more card dump databases which include: (i) card dumps and (ii) respective identifiers of geographical areas where the card dumps were obtained;

identifying, using the one or more card dump databases and the commercial entities database, identifiers of a plurality of compromised geographical areas;

identifying in a given compromised geographical area of the plurality of compromised geographical areas, at least one respective POS terminal network of a plurality of POS terminal networks,

the at least one respective POS terminal network including a plurality of POS terminals in the given compromised geographical area associated with a respective commercial entity;

using the commercial entities database, identifying, for a given commercial entity present in the given compromised geographical area, based on the respective identifier thereof, POS terminal networks associated with the given commercial entity;

generating a potentially compromised POS terminal networks database including, for the given commercial entity, the POS terminal networks associated therewith;

determining, for the at least one respective POS terminal network, a plurality of compromise parameters, the plurality of compromise parameters including:

a frequency of occurrence of POS terminal networks associated with the respective commercial entity in the plurality of compromised geographical areas; and

a probability of occurrence of the POS terminal networks associated with the respective commercial entity in the plurality of compromised geographical areas;

determining, based on the plurality of compromise parameters, a respective compromise probability value for each POS terminal network of the plurality of POS terminal networks according to at least one equation selected from a group of equations consisting of:

sort_ kf =zip_ kf*cmp _ kf{circumflex over ( )} 2,

sort_ kf =zip_ kf{circumflex over ( )} 3* cmp _ kf,

where sort_kf is the respective compromise probability value,

zip_kf is the frequency of occurrence of the POS terminal networks associated with the respective commercial entity in the plurality of compromised geographical areas, and

cmp_kf is the probability of occurrence of the POS terminal networks associated with the respective commercial entity in the plurality of compromised geographical areas;

ranking the plurality of POS terminal networks according to respective compromise probability values determined therefor, thereby generating a ranked list of POS terminal networks;

determining a top-ranked POS terminal network in the ranked list of POS terminal networks as being the compromised POS terminal network; and

causing generation of a warning message of the top-ranked POS terminal network being compromised for display thereof on a screen of an electronic device.

2 . The method of claim 1 , wherein: prior to the generating the commercial entities database, the method comprises generating a first database including for the given geographical area the respective identifier of the given geographical area;

and

after the identifying the identifiers of the plurality of compromised geographical areas, the method further comprises determining, by submitting a respective query to the first database, a respective territorial unit of a plurality of territorial units, with which the plurality of compromised geographical areas is associated.

3 . The method of claim 1 , wherein the determining the plurality of compromise parameters comprises querying the commercial entities database.

4 . The method of claim 1 , wherein the potentially compromised POS terminal networks database is configured to store at least one selected from a group consisted of:

the identifiers of the plurality of compromised geographical areas;

names of respective commercial entities, whose POS terminal networks are located in respective ones of the plurality of compromised geographical areas;

addresses of the respective commercial entities, whose POS terminal networks are located in the respective ones of the plurality of compromised geographical areas, and territorial units corresponding to each one of the plurality of the compromised geographical areas.

5 . The method of claim 1 , wherein the determining the plurality of compromise parameters of the at least one respective POS terminal network comprises determining:

a number of compromised geographical areas having at least one POS terminal network associated with the respective commercial entity;

a total number of compromised geographical areas in the plurality of compromised geographical areas;

a number of POS terminal networks associated with the respective commercial entity in the plurality of compromised geographical areas, and

a total number of POS terminal networks associated with the respective commercial entity, located in each one of a plurality of territorial units,

a respective one of the plurality of territorial units including the plurality of compromised geographical areas.

6 . The method of claim 5 , wherein the frequency of occurrence of the POS terminal networks associated with the respective commercial entity in the plurality of compromised geographical areas is determined as a ratio between the number of compromised geographical areas having at least one POS terminal network associated with the respective commercial entity and the total number of compromised geographical areas in the plurality of compromised geographical areas.

7 . The method of claim 5 , wherein the probability of occurrence of the POS terminal networks associated with the respective commercial entity in the plurality of compromised geographical areas is determined as a ratio between the number of POS terminal networks associated with the respective commercial entity in the plurality of compromised geographical areas and the total number of the POS terminal networks associated with the respective commercial entity, located in each one of the plurality of territorial units.

8 . The method of claim 1 , wherein the determining the respective compromise probability value for the at least one respective POS terminal network comprises multiplying between the frequency and the probability of occurrence of the POS terminal networks associated with the respective commercial entity in the plurality of compromised geographical areas.

9 . The method of claim 1 , wherein the determining the top-ranked POS terminal network comprises determining a sub-set of top-ranked POS terminal networks in the ranked list of POS terminal networks whose respective compromise probability values do not exceed a predetermined compromise probability threshold value.

10 . A system for identifying a compromised Point-of-Sale (POS) terminal network, the system comprising at least one processor and a non-transitory computer-readable memory storing instructions, which, when executed by the at least one processor, cause the system to:

generate a commercial entities database for a given geographical area of a plurality of geographical areas by executing a pre-configured script as a search robot, wherein the commercial entities database includes entries having (i) a respective identifier of the given geographical area and (ii) commercial entities present in the given geographical area, and the entries are obtained from results of a plurality of search queries sent by the search robot to crawl and parse a communication network for the given geographical area;

access one or more card dump databases which include: (i) card dumps and (ii) respective identifiers of geographical areas where the card dumps were obtained;

identify, using the one or more card dump databases and the commercial entities database, identifiers of a plurality of compromised geographical areas;

identify in a given compromised geographical area of the plurality of compromised geographical areas, at least one respective POS terminal network of a plurality of POS terminal networks,

the at least one respective POS terminal network including a plurality of POS terminals in the given compromised geographical area associated with a respective commercial entity;

use the commercial entities database to identify, for a given commercial entity present in the given compromised geographical area, based on the respective identifier thereof, POS terminal networks associated with the given commercial entity;

generate a potentially compromised POS terminal networks database including, for the given commercial entity, the POS terminal networks associated therewith;

determine, for the at least one respective POS terminal network, a plurality of compromise parameters, the plurality of compromise parameters including:

a frequency of occurrence of POS terminal networks associated with the respective commercial entity in the plurality of compromised geographical areas; and

a probability of occurrence of the POS terminal networks associated with the respective commercial entity in the plurality of compromised geographical areas;

determine, based on the plurality of compromise parameters, a respective compromise probability value for each POS terminal network of the plurality of POS terminal networks according to at least one equation selected from a group of equations consisting of:

sort_ kf =zip_ kf*cmp _ kf{circumflex over ( )} 2,

sort_ kf =zip_ kf{circumflex over ( )} 3* cmp _ kf,

where sort_kf is the respective compromise probability value,

zip_kf is the frequency of occurrence of the POS terminal networks associated with the respective commercial entity in the plurality of compromised geographical areas, and

cmp_kf is the probability of occurrence of the POS terminal networks associated with the respective commercial entity in the plurality of compromised geographical areas;

rank the plurality of POS terminal networks according to respective compromise probability values determined therefor, thereby generating a ranked list of POS terminal networks;

determine a top-ranked POS terminal network in the ranked list of POS terminal networks as being the compromised POS terminal network; and

cause generation of a warning message of the top-ranked POS terminal network being compromised for display thereof on a screen of an electronic device.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2025
From: F.A.C.C.T. LLC
To: GROUP-IB GLOBAL PRIVATE LIMITED
Reel/Frame 071439/0282 →
CHANGE OF NAME Recorded Jul 19, 2024
From: TRUST LTD.
To: F.A.C.C.T. LLC
Reel/Frame 068462/0883 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2022
From: CHEBESOV, RUSLAN
To: TRUST LTD.
Reel/Frame 061536/0260 →
Priority Claims (1)
RU RU2021133879 · Nov 22, 2021 · national
Continuity (1)
Related Publication 20230161876A1 · May 25, 2023
References Cited (30)
US 9773227B2 · Zoldi · 2017 [cited by examiner]
US 10607228B1 · Gai et al. · 2020 [cited by applicant]
US 10749892B2 · Araujo · 2020 [cited by examiner]
US 10777047B1 · Hamchuck · 2020 [cited by examiner]
US 11062317B2 · Adjaoute · 2021 [cited by examiner]
US 11132686B2 · Nightengale et al. · 2021 [cited by applicant]
US 20100063917A1 · Pettitt · 2010 [cited by examiner]
US 20110307382A1 · Siegel · 2011 [cited by examiner]
US 20160364727A1 · DeLawter · 2016 [cited by examiner]
US 20170237759A1 · Bell · 2017 [cited by examiner]
US 20180005243A1 · Zovi et al. · 2018 [cited by applicant]
US 20190318126A1 · Mascaro · 2019 [cited by examiner]
US 20190385170A1 · Arrabothu · 2019 [cited by examiner]
US 20200211022A1 · Allbright · 2020 [cited by examiner]
US 20210125182A1 · Jain · 2021 [cited by examiner]
US 20220353275A1 · Syngal · 2022 [cited by examiner]
US 20230069999A1 · Duan · 2023 [cited by examiner]
AU 2012230299A1 · 2013 [cited by applicant]
AU 2012230299B2 · 2016 [cited by applicant]
RU 2697953C2 · 2019 [cited by applicant]
WO WO2012127023A1 · 2012 [cited by examiner]
WO WO2020107053A1 · 2020 [cited by examiner]
Murray, A. (Aug. 20, 2021). Excel COUNTIF and COUNTIFS Function [How-To Guide]. CareerFoundry. https://careerfoundry.com/en/blog/data-analytics/countifs-function-excel/ (Year: 2021). [cited by examiner]
Illowsky, B., & Dean, S. (Mar. 27, 2020b). 1.3 Frequency, frequency tables, and levels of measurement—Statistics | OpenStax. https://openstax.org/books/statistics/pages/1-3-frequency-frequency-tables-and-levels-of-measu… [cited by examiner]
Jacquette, D. (2008). Boole's logic. In Handbook of the history of logic (pp. 331-379). https://doi.org/10.1016/s1874-5857(08)80011-8 (Year: 2008). [cited by examiner]
Search Report with regard to the counterpart NL Patent Application No. 2032025 completed Jan. 24, 2023. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2021133879 completed Oct. 10, 2022. [cited by applicant]
“Nearly All U.S. Home Depot Stores Hit. Krebsonsecurity”, Sep. 3, 2014, accessed on https://krebsonsecurity.com/2014/09/data-nearly-all-u-s-home-depot-stores-hit/, pdf 4 pages. [cited by applicant]
“Sally Beauty Hit By Credit Card Breach”, Mar. 5, 2014, retrieved on krebsonsecurity.com/2014/03/sally-beauty-hit-by-credit-card-breach on Sep. 23, 2022, pdf 23 pages. [cited by applicant]
“ZIP Codes Show Extent of Sally Beauty Breach”, Mar. 25, 2014, retrieved on https://krebsonsecurity.com/2014/03/zip-codes-show-extent-of-sally-beauty-breach/comment-page-1/ on Sep. 23, 2022, pdf 18 pages. [cited by applicant]