IP Library Granted Patent US 11,949,747
Granted Patent B2
US 11,949,747 · App. 18/069,866 · Granted Apr 2, 2024

Apparatus, method and article to facilitate automatic detection and removal of fraudulent user information in a network environment

Inventors: Thomas Levi (Vancouver, CA); Steve Oldridge (Vancouver, CA)
Assignee: PLENTYOFFISH MEDIA ULC
H04L67/306G06F21/552G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,949,747
App. No.
18/069,866
Granted
Apr 2, 2024
Kind
B2
Abstract

A fraud detection system may obtain a number of known fraudulent end-user profiles and/or otherwise undesirable end-user profiles. Using statistical analysis techniques that include clustering the end-user profiles by attributes and attribute values and/or combinations of attributes and attribute values, the fraud detection system identifies on a continuous, periodic, or aperiodic basis those attribute values and/or attribute value combinations that appear in fraudulent or otherwise undesirable end-user profiles. Using this data, the fraud detection system generates one or more queries to identify those end-user profiles having attribute values or combinations of attribute values that likely indicate a fraudulent or otherwise undesirable end-user profile. The fraud detection system can run these queries against incoming registrations to identify and screen fraudulent end-user profiles from entering the system and can also run these queries against stored end-user profile databases to identify and remove fraudulent or otherwise undesirable end-user profiles from the end-user database.

Claims (250)

1. A method of detecting suspected fraudulently generated user identity profiles in an online network environment using a fraud detection system that includes at least one processor and at least one non-transitory processor-readable medium that stores processor-executable instructions, the method comprising:

determining, via the at least one processor, an attribute value for an attribute associated with the profiles;

determining, via the at least one processor, whether the attribute value is linked to a high conditional probability based on the attribute value that a profile is fraudulently generated or undesirable;

identifying, via the at least one processor, a set of profiles likely to be fraudulently generated or undesirable based on the attribute value and the high conditional probability;

identifying, via the at least one processor, an additional attribute value that occurs frequently in the set of profiles;

querying, using the fraud detection system having at least one processor and at least one non-transitory processor-readable medium that stores processor-executable instructions, a data store containing profile information to identify profiles suspected of being fraudulently generated based at least in part on the attribute value and the additional attribute value;

screening, using the fraud detection system having at least one processor and at least one non-transitory processor-readable medium that stores processor-executable instructions, the identified profiles suspected of being fraudulently generated or undesirable; and

one or more of removing or quarantining the identified profiles.

2. The method of claim 1 , wherein determining whether the attribute value is linked to a high conditional probability of being a fraudulent or undesirable profile includes computing the initial probabilities of a profile being a fraudulent profile [p(S)] or a valid profile [p(V)].

3. The method of claim 1 , wherein determining whether the attribute value is linked to a high conditional probability includes computing the value indicative of a conditional probability that the respective profile is fraudulent according to:

p

(

S

|

{

x

i

}

)

=

p

(

S

)

i

M

p

(

x

i

|

S

)

p

(

S

)

i

M

p

(

x

i

|

S

)

+

p

(

V

)

i

M

p

(

x

i

|

V

)

.

4. The method of claim 1 , wherein the attribute value includes one or more of:

a Hyper Text Transfer Protocol (http) referrer associated with the respective profile;

an Internet Protocol (IP) of signup and last logins associated with the respective profile;

one or more cookies used to track individual computers associated with the respective profile;

one or more cookies that contain a user identifier of the most recent users to log in on using a given instance of a processor-based device; and

IP blocks of signup and at least two most recent logins associated with the respective profile.

5. The method of claim 1 , further comprising:

ranking the profiles into groups.

6. A fraudulent user identity profile detection system to detect at least one of accounts or related profiles suspected of being fraudulently generated, the system comprising:

at least one processor; and

at least one non-transitory processor-readable medium that stores processor-executable instructions, wherein/the at least one processor:

determine an initial probability value based at least in part on historical profile data;

determine whether the initial probability value is linked to a value indicative of a high conditional probability based on the initial probability value that the a profile is one of either fraudulently generated or undesirable;

identify a set of profiles likely to be fraudulently generated or undesirable based on the initial probability value and the high conditional probability;

identify an additional attribute value that occurs frequently in the set of profiles;

query a data store containing profile information to identify profiles suspected of being fraudulently generated based at least in part on the initial probability value and the additional attribute value;

screen the identified profiles suspected of being fraudulently generated or undesirable; and

one or more of remove or quarantine the identified profiles.

7. The system of claim 6 , wherein the at least one processor computes a value indicative of the initial probabilities of a profiles being at least one of a fraudulent profile [p(S)] or a valid profile [p(V)].

8. The system of claim 6 , wherein the at least one processor computes a value indicative of a conditional probability that the respective profile is fraudulent includes computing the value indicative of a conditional probability that the respective profile is fraudulent according to:

p

(

S

|

{

x

i

}

)

=

p

(

S

)

i

M

p

(

x

i

|

S

)

p

(

S

)

i

M

p

(

x

i

|

S

)

+

p

(

V

)

i

M

p

(

x

i

|

V

)

.

9. The system of claim 6 , wherein the at least one processor ranks the profiles into groups using the high conditional probability based on the initial probability value that the profile is one of a either fraudulent or undesirable.

10. The system of claim 6 , wherein the attribute value includes one or more of:

a Hyper Text Transfer Protocol (http) referrer associated with the respective profile;

an Internet Protocol (IP) of signup and last logins associated with the respective profile;

one or more cookies used to track individual computers associated with the respective profile;

one or more cookies that contain a user identifier of the most recent users to log in on using a given instance of a processor-based device; and

IP blocks of signup and at least two most recent logins associated with the respective profile.

11. The system of claim 6 , wherein the at least one processor generates at least one output logically associated with each profile, the at least one output indicative of at least one of the following: a deletion indicator, a clearance indicator, or a further investigation indicator.

12. A fraudulent user identity profile detection system to detect at least one of accounts or related profiles suspected of being fraudulently generated, the system comprising:

at least one processor; and

at least one nontransitory processor-readable medium that stores processor-executable instructions, wherein the at least one processor:

determine an attribute value for an attribute associated with the profiles;

determine whether the attribute value is linked to a high conditional probability based on the attribute value that a profile is fraudulently generated;

identify a set of profiles likely to be fraudulently generated based on the attribute value and the conditional probability;

identify an additional attribute value that occurs frequently in the set of profiles;

query a data store containing profile information to identify profiles suspected of being fraudulently generated based at least in part on the attribute value and the additional attribute value;

screen the identified profiles suspected of being fraudulently generated or undesirable; and

one or more of remove or quarantine the identified profiles.

13. The system of claim 12 , wherein the at least one processor computes a value indicative of an the initial probabilities of a profiles being at least one of a fraudulent profile [p(S)] or a valid profile [p(V)].

14. The system of claim 12 , wherein the at least one processor computes a value indicative of a conditional probability that the respective profile is fraudulent includes computing the value indicative of a conditional probability that the respective profile is fraudulent according to:

p

(

S

|

{

x

i

}

)

=

p

(

S

)

i

M

p

(

x

i

|

S

)

p

(

S

)

i

M

p

(

x

i

|

S

)

+

p

(

V

)

i

M

p

(

x

i

|

V

)

.

15. The system of claim 12 , wherein the at least one processor ranks the profiles into groups using the high conditional probability based on the initial probability value that the profile is one of a either fraudulent or undesirable.

16. The system of claim 12 , wherein the attribute value includes one or more of:

a Hyper Text Transfer Protocol (http) referrer associated with the respective profile;

an Internet Protocol (IP) of signup and last logins associated with the respective profile;

one or more cookies used to track individual computers associated with the respective profile;

one or more cookies that contain a user identifier of the most recent users to log in on using a given instance of a processor-based device; and

IP blocks of signup and at least two most recent logins associated with the respective profile.

17. The system of claim 12 , wherein the at least one processor generates at least one output logically associated with each profile, the at least one output indicative of at least one of the following: a deletion indicator, a clearance indicator, or a further investigation indicator.

Continuity (5)
Continuation 16833427 · Mar 27, 2020
Continuation 15782576 · Oct 12, 2017
Division 14561004 · Dec 4, 2014
Provisional Application 61911908 · Dec 4, 2013
Related Publication 20230125592A1 · Apr 27, 2023