IP Library Granted Patent US 12,737,437
Granted Patent B2
US 12,737,437 · App. 18/575,468 · Granted Sep 15, 2026

Systems and methods for mapping a networked environment with cross account clustering to monitoring and/or detect fraudulent entity networks

Inventors: Timothy Allen Elton (Meridian, ID); Oleg V. Polishchuk (Chevy Chase, MD); Sassan Shahriary (Pleasanton, CA); Chun-Ying Lee (Fremont, CA); Daryle S. Fong (Santa Clara, CA); Sanjeev Karigowdanakoppalu (San Francisco, CA)
Assignee: OpSec Online Limited
G06F21/10H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,737,437
App. No.
18/575,468
Granted
Sep 15, 2026
Kind
B2
Abstract

Systems, methods, and non-transitory computer-readable media are provided for detecting and monitoring fraudulent entity networks in a networked environment. The networked environment can be mapped with cross account clustering to identify nodes associated with one or more entity networks in the networked environment and can identify whether the one or more entity networks are fraudulent entity networks based on a determination that one or more nodes in the one or more entity networks is a source of malignant content. Upon detecting the fraudulent entity networks, embodiments of the present disclosure can alert parties that may be affected by the one or more fraudulent entity networks and/or can initiate one or more actions against the fraudulent entity network.

Claims (69)

1 . A system for detecting and monitoring fraudulent entity networks in a networked environment, the system comprising:

a computing system communicatively coupled to data sources in a networked environment, the data sources including one or more remote servers that are configured to host digital content;

one or more processors being disposed in the computing system, the one or more processors being programmed to:

establish separate and distinct client accounts;

search, for each client account, the digital content hosted by the one or more remote servers in the networked environment to generate separate harvested data sets for each client account;

tag each search result in the harvested data sets as legitimate or malignant based on an analysis of each search result;

generate a network graph by combining data from each search result in the harvested data sets for the client accounts, wherein the client accounts include confidential or private data that is utilized to generate the network graph;

generate clusters in the network graph, the clusters including cross-account clusters that include data from two or more client accounts;

prevent disclosure of the confidential or private data for each of the client accounts to other ones of the client accounts by modifying the cross-account clusters in the network graph to obfuscate the confidential or private data;

in response to receiving a selection or request, alter the scope of the network graph so that only nodes that have been tagged as being associated with malignant content are included in the network graph;

identify one or more fraudulent entity networks based on the clusters in the network graph; and

initiate a removal action against the identified one or more fraudulent entity networks, wherein the removal action includes a removal engine initiating an automated takedown against the identified one or more fraudulent entity networks.

2 . The system of claim 1 , wherein the one or more processors are programmed to:

analyze, for each search result in the harvested data sets for each client account, whether the search result corresponds to legitimate or malignant content; and

tag each search result in the harvested data sets for each client as legitimate or malignant based on the analysis.

3 . The system of claim 1 , wherein the one or more processors are programmed to:

create a plurality of records in a relational database for each for each unique search result in the harvested data sets for each client account; and

store data extracted from each result in harvested data set for each client account in data fields of a corresponding one of the plurality of records.

4 . The system of claim 3 , wherein the one or more processors are further programmed to:

create a graph database;

define a graph data model for the graph database;

copy the plurality of records from the relational database to documents of the graph database;

copy the data fields from the plurality of records in the relational database to keys of documents in the graph database; and

generate at least one of node collections or edge collections in the graph database based on the documents and the keys of the documents.

5 . The system of claim 4 , wherein the data forming the keys are at least one of transformed into their canonical form or converted by a hash algorithm.

6 . The system of claim 1 , wherein the one or more remote servers in the networked environment are webservers and the digital content hosted by the one or more remote servers is websites including webpages.

7 . The system of claim 1 , wherein the one or more processors are further programmed to generate at least one of the network graph or the clusters in response to execution of an entity resolution algorithm, wherein the entity resolution algorithm is a connected components algorithm.

8 . The system of claim 1 , wherein the one or more processors are programmed to:

detect formation of one of the cross-account clusters; and

alert a user of one of the client accounts associated with the one of the cross-account clusters.

9 . A method for detecting and monitoring fraudulent entity networks in a networked environment, the method implemented via a computing system communicatively coupled to data sources in the networked environment, the data sources including one or more remote servers that are configured to host digital content, and one or more processors being disposed in the computing system, the method comprising:

establishing separate and distinct client accounts;

searching, for each client account, the digital content hosted by the one or more remote servers in the networked environment to generate separate harvested data sets for each client account;

tagging each search result in the harvested data sets as legitimate or malignant based on an analysis of each search result;

generating a network graph by combining data from each search result in the harvested data sets for the client accounts, wherein the client accounts include confidential or private data that is utilized to generate the network graph;

generating clusters in the network graph, the clusters including cross-account clusters that include data from two or more client accounts;

preventing disclosure of the confidential or private data for each of the client accounts to other ones of the client accounts by modifying the cross-account clusters in the network graph to obfuscate the confidential or private data;

in response to receiving a selection or request, altering the scope of the network graph so that only nodes that have been tagged as being associated with malignant content are included in the network graph;

identifying one or more fraudulent entity networks based on the clusters in the network graph; and

initiating a removal action against the identified one or more fraudulent entity networks, including initiating, by a removal engine, an automated takedown against the identified one or more fraudulent entity networks.

10 . A non-transitory computer-readable medium storing instructions for detecting and monitoring fraudulent entity networks in a networked environment that when executed by one or more processors causes the one or more processors to:

establish separate and distinct client accounts;

search, for each client account, digital content hosted by one or more remote servers in the networked environment to generate separate harvested data sets for each client account;

tag each search result in the harvested data sets as legitimate or malignant based on an analysis of each search result;

generate a network graph by combining data from each search result in the harvested data sets for the client accounts, wherein the client accounts include confidential or private data that is utilized to generate the network graph;

generate clusters in the network graph, the clusters including cross-account clusters that include data from two or more client accounts;

prevent disclosure of the confidential or private data for each of the client accounts to other ones of the client accounts by modifying the cross-account clusters in the network graph to obfuscate the confidential or private data;

in response to receiving a selection or request, alter the scope of the network graph so that only nodes that have been tagged as being associated with malignant content are included in the network graph;

identify one or more fraudulent entity networks based on the clusters in the network graph; and

initiate a removal action against the identified one or more fraudulent entity networks, wherein the removal action includes a removal engine initiating an automated takedown against the identified one or more fraudulent entity networks.

11 . The medium of claim 10 , wherein the client accounts include confidential or private data is utilized to generate the network graph and execution of the instructions causes the one or more processors to:

prevent disclosure of the confidential or private data for each of the client accounts to other ones of the client accounts by modifying the cross-account clusters in the graph to at least one of obfuscate the confidential or private data or remove the confidential or private data.

12 . The medium of claim 10 , wherein execution of the instructions causes the one or more processors to:

analyze, for each search result in the harvested data sets for each client account, whether the search result corresponds to legitimate or malignant content; and

tag each search result in the harvested data sets for each client as legitimate or malignant based on the analysis.

13 . The medium of claim 10 , wherein execution of the instructions causes the one or more processors to:

create a plurality of records in a relational database for each for each unique search result in the harvested data sets for each client account; and

store data extracted from each result in harvested data set for each client account in data fields of a corresponding one of the plurality of records.

14 . The medium of claim 13 , wherein execution of the instructions causes the one or more processors to:

create a graph database;

define a graph data model for the graph database;

copy the plurality of records from the relational database to documents of the graph database copy the data fields from the plurality of records in the relational database to keys of documents in the graph database; and

generate at least one of node collections or edge collections in the graph database based on the documents and the keys of the documents.

15 . The medium of claim 14 , wherein the data forming the keys are at least one of transformed into their canonical form or converted by a hash algorithm.

16 . The medium of claim 10 , wherein the one or more remote servers in the networked environment are webservers and the digital content hosted by the one or more remote servers is websites including webpages.

17 . The medium of claim 10 , wherein execution of the instructions causes the one or more processors to generate at least one of the network graph or the clusters in response to execution of an entity resolution algorithm, wherein the entity resolution algorithm is a connected components algorithm.

18 . The medium of claim 10 , wherein execution of the instructions causes the one or more processors to:

detect formation of one of the cross-account clusters; and

alert a user of one of the client accounts associated with the one of the cross-account clusters.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2026
From: ELTON, TIMOTHY ALLEN; POLISHCHUK, OLEG V.; SHAHRIARY, SASSAN; LEE, CHUN-YING; FONG, DARYLE S.; KARIGOWDANAKOPPALU, SANJEEV
To: OPSEC ONLINE LIMITED
Reel/Frame 074419/0560 →
Continuity (2)
Provisional Application 63216878 · Jun 30, 2021
Related Publication 20240297897A1 · Sep 5, 2024
References Cited (32)
US 9912695B1 · Chao et al. · 2018 [cited by applicant]
US 10187408B1 · Call et al. · 2019 [cited by applicant]
US 11074362B2 · Conikee · 2021 [cited by examiner]
US 11334692B2 · Farrell · 2022 [cited by examiner]
US 11610588B1 · Grichnik · 2023 [cited by examiner]
US 11809593B2 · Irish · 2023 [cited by examiner]
US 20130073473A1 · Heath · 2013 [cited by examiner]
US 20160149936A1 · Pegna · 2016 [cited by examiner]
US 20180091537A1 · Uggirala · 2018 [cited by examiner]
US 20180316683A1 · Larkina et al. · 2018 [cited by applicant]
US 20190114649A1 · Wang et al. · 2019 [cited by applicant]
US 20190199519A1 · Goyal · 2019 [cited by examiner]
US 20190278855A1 · Kallas et al. · 2019 [cited by applicant]
US 20200004964A1 · Soumenkov et al. · 2020 [cited by applicant]
US 20200169565A1 · Badawy et al. · 2020 [cited by applicant]
US 20200394313A1 · Ionescu · 2020 [cited by examiner]
US 20210058352A1 · Fogu et al. · 2021 [cited by applicant]
US 20210183479A1 · Lopez · 2021 [cited by examiner]
US 20220210657A1 · Desai · 2022 [cited by examiner]
CN 109726318A · 2019 [cited by applicant]
CN 110138763A · 2019 [cited by applicant]
CN 110352427A · 2019 [cited by applicant]
JP 2016530586A · 2016 [cited by applicant]
JP 2018190370A · 2018 [cited by applicant]
WO 2015006180A1 · 2015 [cited by applicant]
WO 2016081516A2 · 2016 [cited by applicant]
WO 2018125984A1 · 2018 [cited by applicant]
NPL Search Terms (Year: 2025). [cited by examiner]
International Search Report and Written Opinion mailed Nov. 8, 2022 for International Application No. PCT/US2022/035813, 11 pages. [cited by applicant]
Extended European Search Report dated Apr. 22, 2025, in connection with European Application No. 22834257.2, 10 pages. [cited by applicant]
Notice of Reasons for Refusal dated Jun. 24, 2025, in connection with Japanese Application No. 2023-580363, 11 pages. [cited by applicant]
First Office Action dated May 20, 2026, in connection with Chinese Application No. 202280047136.0, 25 pages. [cited by applicant]