IP Library Granted Patent US 12,725,162
Granted Patent B2
US 12,725,162 · App. 18/506,629 · Granted Sep 1, 2026

Techniques for handling card testing attacks

Inventors: Alexandre Bondoux (Seattle, WA); Elaine Cheng (Mercer Island, WA)
Assignee: Stripe, LLC
G06Q20/4016
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,725,162
App. No.
18/506,629
Granted
Sep 1, 2026
Kind
B2
Abstract

Embodiments may include receiving a request including transaction data to evaluate a transaction as part of a charge path that processes at least a portion of the transaction; processing, by a set of blocking machine learning models, a portion of the transaction data to generate a set of blocking scores for the transaction; retrieving, from a memory, a set of card testing attack (CTA) scores associated with the transaction, the set of CTA scores indicative of an occurrence of a card testing attack, and the set of CTA scores retrieved based on the transaction data; adjusting a set of default blocking score thresholds based on the set of CTA scores to generate a set of adjusted blocking score thresholds; and determining to allow the transaction based on comparison of the set of blocking scores with the set of adjusted blocking score thresholds.

Claims (60)

1 . A computer-implemented method for handling card testing attacks, the method comprising:

receiving, by a server system, a request to evaluate an event as part of a path that processes at least a portion of the event, wherein the request includes event data associated with the event comprising an identifier of a second server system that generated the event;

invoking a set of blocking machine learning (ML) models to process a portion of the event data and to generate a set of blocking scores for the event;

detecting a cache hit for a set of card testing attack (CTA) scores generated asynchronously to the path and associated with the identifier of the second server system, the set of CTA scores being generated by a plurality of ML models operating in parallel; and

subsequent to detecting the cache hit, reconfiguring the server system to selectively block the event by:

retrieving, from a memory, the set of CTA scores based on the event data;

determining whether to adjust a set of default blocking score thresholds based on whether the set of CTA scores is indicative of an occurrence of a card testing attack at the second server system; and

in accordance with a determination to adjust the set of default blocking score thresholds,

generating a set of lowered blocking score thresholds by lowering the set of default blocking score thresholds for a threshold amount of time;

blocking the event in response to determining that at least one blocking score of the set of blocking scores exceeds a blocking score threshold from the set of lowered blocking score thresholds; and

resetting the set of default blocking score thresholds after the threshold amount of time.

2 . The computer-implemented method of claim 1 , wherein the set of CTA scores is generated by a set of CTA ML models outside of the path that processes at least the portion of the event.

3 . The computer-implemented method of claim 1 , wherein the set of blocking scores for the event is generated by the set of blocking ML models as part of the path that processes at least the portion of the event.

4 . The computer-implemented method of claim 1 , wherein the event comprises a current event and the set of CTA scores is generated by a set of CTA ML models based on data associated with a previous event.

5 . The computer-implemented method of claim 4 , wherein the current event and the previous event are associated with a common identifier.

6 . The computer-implemented method of claim 1 , wherein each CTA score in the set of CTA scores is generated by a different CTA model that is trained to detect a different attack pattern indicative of CTAs.

7 . The computer-implemented method of claim 1 , wherein the set of CTA scores include a first set of CTA scores, and the method further comprises:

receiving, by the server system, further event data associated with the event;

processing, by a set of CTA ML models of the server system, a feature set produced based on the further event data to generate a second set of CTA scores; and

storing the second set of CTA scores in the memory.

8 . The computer-implemented method of claim 7 , wherein the second set of CTA scores are generated and stored in the memory in response to a determination that the first set of CTA scores are older than a further threshold amount of time.

9 . A non-transitory computer readable storage medium including instructions that, when executed by a processor, cause the processor to perform operations for handling card testing attacks, the operations comprising:

receiving, by a server system, a request to evaluate an event as part of a path that processes at least a portion of the event, wherein the request includes event data associated with the event comprising an identifier of a second server system that generated the event;

invoking a set of blocking machine learning (ML) models, to process a portion of the event data and to generate a set of blocking scores for the event;

detecting a cache hit for a set of card testing attack (CTA) scores generated asynchronously to the path and associated with the identifier of the second server system, the set of CTA scores being generated by a plurality of ML models operating in parallel; and

subsequent to detecting the cache hit, reconfiguring the server system to selectively block the event by:

retrieving, from a memory, the set of CTA scores based on the event data;

determining whether to adjust a set of default blocking score thresholds based on whether the set of CTA scores is indicative of an occurrence of a card testing attack at the second server system; and

in accordance with a determination to adjust the set of default blocking score thresholds,

generating a set of lowered blocking score thresholds by lowering the set of default blocking score thresholds for a threshold amount of time;

blocking the event in response to determining that at least one blocking score of the set of blocking scores exceeds a blocking score threshold from the set of lowered blocking score thresholds; and

resetting the set of default blocking score thresholds after the threshold amount of time.

10 . The non-transitory computer readable storage medium of claim 9 , wherein the set of CTA scores is generated by a set of CTA ML models outside of the path that processes at least the portion of the event.

11 . The non-transitory computer readable storage medium of claim 9 , wherein the set of blocking scores for the event is generated by the set of blocking ML models as part of the path that processes at least the portion of the event.

12 . The non-transitory computer readable storage medium of claim 9 , wherein the event comprises a current event and the set of CTA scores is generated by a set of CTA ML models based on data associated with a previous event.

13 . The non-transitory computer readable storage medium of claim 9 , wherein the set of CTA scores include a first set of CTA scores, and the operations further comprise:

receiving, by the server system, further event data associated with the event;

processing, by a set of CTA ML models of the server system, a feature set produced based on the further event data to generate a second set of CTA scores; and

storing the second set of CTA scores in the memory.

14 . A server computer system for handling card testing attacks, comprising:

a memory; and

a processor coupled to the memory configured to:

receive a request to evaluate an event as part of a path that processes at least a portion of the event, wherein the request includes event data associated with the event comprising an identifier of a second server system that generated the event;

invoke a set of blocking machine learning (ML) models of the server computer system to process a portion of the event data and to generate a set of blocking scores for the event;

detect a cache hit for a set of card testing attack (CTA) scores generated asynchronously to the path and associated with the identifier of the second server system, the set of CTA scores being generated by a plurality of ML models operating in parallel; and

subsequent to detecting the cache hit, reconfigure the server computer system to selectively block the event by:

retrieving, from a memory, the set of CTA scores based on the event data;

determining whether to adjust a set of default blocking score thresholds based on whether the set of CTA scores is indicative of an occurrence of a card testing attack at the second server system; and

in accordance with a determination to adjust the set of default blocking score thresholds,

generating a set of lowered blocking score thresholds by lowering the set of default blocking score thresholds for a threshold amount of time to generate a set of lowered blocking score thresholds,

blocking the event in response to determining that at least one blocking score of the set of blocking scores exceeds a blocking score threshold from the set of lowered blocking score thresholds; and

resetting the set of default blocking score thresholds after the threshold amount of time.

15 . The server computer system of claim 14 , wherein the set of CTA scores is generated by a set of CTA ML models outside of the path that processes at least the portion of the event.

16 . The server computer system of claim 14 , wherein the set of blocking scores for the event is generated by the set of blocking ML models as part of the path that processes at least the portion of the event.

17 . The server computer system of claim 14 , wherein the event comprises a current event and the set of CTA scores is generated by a set of CTA ML models based on data associated with a previous event.

18 . The server computer system of claim 14 , wherein each CTA score in the set of CTA scores is generated by a different CTA model that is trained to detect a different attack pattern indicative of CTAs.

19 . The server computer system of claim 14 , wherein the set of CTA scores include a first set of CTA scores, and the processor coupled to the memory is further configured to:

receive further event data associated with the event;

process, by a set of CTA ML models, a feature set produced based on the further event data to generate a second set of CTA scores; and

store the second set of CTA scores in the memory.

Assignments (2)
CHANGE OF NAME Recorded Mar 13, 2026
From: STRIPE, INC.
To: STRIPE, LLC
Reel/Frame 075093/0754 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2023
From: BONDOUX, ALEXANDRE; CHENG, ELAINE
To: STRIPE, INC.
Reel/Frame 065528/0551 →
Continuity (1)
Related Publication 20250156870A1 · May 15, 2025
References Cited (3)
US 11205179B1 · Patel · 2021 [cited by examiner]
Anonymous, “Neural network (machine learning)”, Wikipedia, Jun. 1, 2023, 37 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US24/55106, mailed on Mar. 20, 2025, 11 pages. [cited by applicant]