IP Library Granted Patent US 12,526,298
Granted Patent B2
US 12,526,298 · App. 18/133,594 · Granted Jan 13, 2026

System and method for fraud identification

Inventor: Donald J McQueen (Leesburg, VA)
Assignee: Yahoo Assets LLC
H04L63/1425H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,526,298
App. No.
18/133,594
Granted
Jan 13, 2026
Kind
B2
Abstract

In an example, first-tier Internet Protocol (IP) address reputation scores, including a first first-tier IP address reputation score associated with a first first-tier IP address group and a second first-tier IP address reputation score associated with a second first-tier IP address group, may be determined based upon a plurality of events. A second-tier IP address reputation score associated with a second-tier IP address group may be determined based upon the plurality of first-tier IP address reputation scores. The second-tier IP address group may include the first first-tier IP address group and the second first-tier IP address group. An IP address reputation profile may be generated based upon the first-tier IP address reputation scores and the second-tier IP address reputation score. Whether or not a request for content associated with a first IP address is fraudulent may be determined based upon the IP address reputation profile and the first IP address.

Claims (76)

1 . A method, comprising:

analyzing network activity to identify a plurality of events;

determining, based upon the plurality of events, a plurality of first-tier Internet Protocol (IP) address reputation scores, wherein determining the plurality of first-tier IP address reputation scores comprises:

determining a first first-tier IP address reputation score for a first first-tier IP address group based upon one or more first events, of the plurality of events, associated with the first first-tier IP address group; and

determining a second first-tier IP address reputation score for a second first-tier IP address group based upon one or more second events, of the plurality of events, associated with the second first-tier IP address group;

determining, based upon the plurality of first-tier IP address reputation scores, a second-tier IP address reputation score for a second-tier IP address group comprising the first first-tier IP address group and the second first-tier IP address group;

generating an IP address reputation profile based upon the plurality of first-tier IP address reputation scores and the second-tier IP address reputation score for the second-tier IP address group;

receiving a request for content associated with a first IP address; and

determining, based upon the IP address reputation profile and the first IP address, whether or not the request for content is fraudulent.

2 . The method of claim 1 , wherein determining whether or not the request for content is fraudulent comprises:

analyzing the IP address reputation profile to identify one or more IP address reputation scores associated with the first IP address; and

determining whether or not the request for content is fraudulent based upon the one or more IP address reputation scores.

3 . The method of claim 1 , wherein determining whether or not the request for content is fraudulent comprises:

analyzing the IP address reputation profile to determine an availability of a first-tier IP address reputation score associated with the first IP address; and

based upon (i) the first-tier IP address reputation score associated with the first IP address not being available in the IP address reputation profile and (ii) the second-tier IP address group comprising the first IP address, using the second-tier IP address reputation score to determine whether or not the request for content is fraudulent.

4 . The method of claim 1 , wherein:

each of the first first-tier IP address group and the second first-tier IP address group spans a first range of IP addresses of a first size; and

the second-tier IP address group spans a second range of IP addresses of a second size at least twice the first size.

5 . The method of claim 1 , wherein determining the first first-tier IP address reputation score comprises:

determining, based upon the one or more first events, one or more features associated with the first first-tier IP address group; and

determining the first first-tier IP address reputation score based upon the one or more features.

6 . The method of claim 5 , wherein the one or more features comprise at least one of:

a measure of successful authentication events associated with the first first-tier IP address group; or

a measure of unsuccessful authentication events associated with the first first-tier IP address group.

7 . The method of claim 5 , wherein the one or more features comprise at least one of:

a measure of successful user validation events associated with the first first-tier IP address group; or

a measure of unsuccessful user validation events associated with the first first-tier IP address group.

8 . The method of claim 1 , comprising:

determining a short-term IP address reputation score associated with the first first-tier IP address group based upon one or more third events that occur within a period of time that starts after the first first-tier IP address reputation score is determined; and

updating the first first-tier IP address reputation score based upon the short-term IP address reputation score.

9 . The method of claim 1 , comprising:

in response to determining that the request for content is not fraudulent, transmitting a content item to a client device associated with the first IP address.

10 . The method of claim 1 , comprising:

in response to determining that the request for content is fraudulent, not transmitting a content item to a client device associated with the first IP address.

11 . The method of claim 1 , comprising:

in response to determining that the request for content is fraudulent, providing, for display on a client device associated with the first IP address, an authentication interface.

12 . A computing device comprising:

a processor; and

memory comprising processor-executable instructions that when executed by the processor cause performance of operations, the operations comprising:

analyzing network activity to identify a plurality of events;

determining, based upon the plurality of events, a plurality of first-tier Internet Protocol (IP) address reputation scores, wherein determining the plurality of first-tier IP address reputation scores comprises:

determining a first first-tier IP address reputation score for a first first-tier IP address group based upon one or more first events, of the plurality of events, associated with the first first-tier IP address group; and

determining a second first-tier IP address reputation score for a second first-tier IP address group based upon one or more second events, of the plurality of events, associated with the second first-tier IP address group;

determining, based upon the plurality of first-tier IP address reputation scores, a second-tier IP address reputation score for a second-tier IP address group comprising the first first-tier IP address group and the second first-tier IP address group;

generating an IP address reputation profile based upon the plurality of first-tier IP address reputation scores and the second-tier IP address reputation score for the second-tier IP address group;

receiving a request for content associated with a first IP address; and

determining, based upon the IP address reputation profile and the first IP address, a fraud risk score associated with the request for content.

13 . The computing device of claim 12 , wherein determining the fraud risk score comprises:

analyzing the IP address reputation profile to identify one or more IP address reputation scores associated with the first IP address; and

determining the fraud risk score based upon the one or more IP address reputation scores.

14 . The computing device of claim 12 , wherein determining the fraud risk score comprises:

analyzing the IP address reputation profile to determine an availability of a first-tier IP address reputation score associated with the first IP address; and

based upon (i) the first-tier IP address reputation score associated with the first IP address not being available in the IP address reputation profile and (ii) the second-tier IP address group comprising the first IP address, using the second-tier IP address reputation score to determine the fraud risk score.

15 . The computing device of claim 12 , wherein:

each of the first first-tier IP address group and the second first-tier IP address group spans a first range of IP addresses of a first size; and

the second-tier IP address group spans a second range of IP addresses of a second size at least twice the first size.

16 . The computing device of claim 12 , wherein determining the first first-tier IP address reputation score comprises:

determining, based upon the one or more first events, one or more features associated with the first first-tier IP address group; and

determining the first first-tier IP address reputation score based upon the one or more features.

17 . The computing device of claim 16 , wherein:

the first first-tier IP address group corresponds to a first subscriber endpoint;

the second first-tier IP address group corresponds to a second subscriber endpoint; and

the second-tier IP address group corresponds to a provider site providing service to the first subscriber endpoint and the second subscriber endpoint.

18 . The computing device of claim 16 , wherein the second-tier IP address group corresponds to a geographical area comprising both the first first-tier IP address group and the second first-tier IP address group.

19 . A non-transitory machine readable medium having stored thereon processor-executable instructions that when executed cause performance of operations, the operations comprising:

analyzing network activity to identify a plurality of events;

determining, based upon the plurality of events, a plurality of first-tier client identifier reputation scores, wherein determining the plurality of first-tier client identifier reputation scores comprises:

determining a first first-tier client identifier reputation score for a first first-tier client identifier group based upon one or more first events, of the plurality of events, associated with the first first-tier client identifier group; and

determining a second first-tier client identifier reputation score for a second first-tier client identifier group based upon one or more second events, of the plurality of events, associated with the second first-tier client identifier group;

determining, based upon the plurality of first-tier client identifier reputation scores, a second-tier client identifier reputation score for a second-tier client identifier group comprising the first first-tier client identifier group and the second first-tier client identifier group;

generating a client identifier reputation profile based upon the plurality of first-tier client identifier reputation scores and the second-tier client identifier reputation score for the second-tier client identifier group;

receiving a request for content associated with a first client identifier; and

determining, based upon the client identifier reputation profile and the first client identifier, a fraud risk score associated with the request for content.

20 . The non-transitory machine readable medium of claim 19 , wherein determining the fraud risk score comprises:

analyzing the client identifier reputation profile to identify one or more client identifier reputation scores associated with the first client identifier; and

determining the fraud risk score based upon the one or more client identifier reputation scores.

Assignments (2)
SUPPLEMENTAL PATENT SECURITY AGREEMENT Recorded Sep 17, 2025
From: YAHOO ASSETS LLC
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 072915/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2023
From: MCQUEEN, DONALD J
To: YAHOO ASSETS LLC
Reel/Frame 063298/0189 →
Continuity (1)
Related Publication 20240348630A1 · Oct 17, 2024
References Cited (10)
US 20200153854A1 · McQueen et al. · 2020 [cited by applicant]
US 20220191173A1 · Karpovsky · 2022 [cited by examiner]
US 20230199002A1 · Kaidi · 2023 [cited by examiner]
Federal Communication Commission: Internet Protocol Version 6 (IPv6), https://www.fcc.gov/consumers/guides/internet-protocol-version-6-ipv6-consumers, Oct. 31, 2016, retrieved on Apr. 11, 2023, 3 pages. [cited by applicant]
Wikipedia: “Classless Inter-Domain Routing”, https://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing, retrieved on Apr. 11, 2023, 7 pages. [cited by applicant]
“XGBoost Documentation”, https://xgboost.readthedocs.io/en/stable, retrieved on Apr. 11, 2023, 3 pages. [cited by applicant]
T. Narten, G. Huston, L. Roberts: “IPV6 Address Assignment to End Sites”, Internet Engineering Task Force (IETF), ISSN: 2070-1721, Mar. 2011, https://www.rfc-editor.org/rfc/rfc6177.html, retrieved on Apr. 11, 2023, 9 pa… [cited by applicant]
Wikipedia: “Autonomous System (Internet)”, https://en.wikipedia.org/wiki/Autonomous_system_(Internet), retrieved on Apr. 11, 2023, 5 pages. [cited by applicant]
Penny Hoelscher: “Spam vs. Phishing: Definitions, Overview and Examples”, Infosec, Jul. 9, 2018, https://resources.infosecinstitute.com/spam-vs-phishing-definitions-overview-examples, retrieved on Apr. 11, 2023, 9 pages. [cited by applicant]
“8 IP Reputation Checkers that Work [2023]”, https://www.sendx.io/resources/ip-reputation-checker, retrieved on Jul. 12, 2023, 10 pages. [cited by applicant]