IP Library Granted Patent US 10,296,918
Granted Patent B1
US 10,296,918 · App. 14/662,372 · Granted May 21, 2019

Providing risk assessments to compromised payment cards

Inventor: Daniel T. Cohen (Even Yehuda, IL)
Assignee: EMC IP Holding Company LLC
G06Q30/0185G06Q40/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,296,918
App. No.
14/662,372
Filed
Mar 19, 2015
Granted
May 21, 2019
Kind
B1
Art Unit
3687
USPC
705/30
Abstract

A computer-implemented technique provides a compromised payment card risk assessment. The technique involves gathering, by processing circuitry, compromised payment card data. The technique further involves identifying, by the processing circuitry, a set of compromised payment cards from the compromised payment card data. The technique further involves providing, in response to identifying the set of compromised payment cards and by the processing circuitry, a compromised payment card assessment report which includes a set of payment card entries corresponding to the set of compromised payment cards. Each payment card entry includes (i) identification data which identifies a respective compromised payment card and (ii) a score which indicates an estimated likelihood that the respective compromised payment card will actually be used for fraud. Such scores may be based on summations of different sub-scores and serve as overall numerical measures of risk.

Claims (52)

1. A computer-implemented method of providing a compromised payment card risk assessment, the computer-implemented method comprising:

gathering, by processing circuitry, compromised payment card data, the gathering of the compromised payment card data including automatically crawling content of a web page containing the compromised payment card data, and scraping the compromised payment card data from the web page, the web page being associated with an online store selling stolen payment card data;

identifying, by the processing circuitry, a set of compromised payment cards from the compromised payment card data;

in response to identifying the set of compromised payment cards, providing, by the processing circuitry, a compromised payment card assessment report that includes a set of payment card entries corresponding to the set of compromised payment cards, each payment card entry including (i) identification data that identifies a respective compromised payment card and (ii) a score that indicates an estimated likelihood that the respective compromised payment card will actually be used for fraud,

wherein the gathering of the compromised payment card data includes automatically crawling the content of the web page to collect compromised payment card inventories from the online store at different collection times,

wherein the identifying of the set of compromised payment cards from the compromised payment card data includes performing comparison operations between the compromised payment card inventories that were collected from the online store at the different times, and identifying which compromised payment cards were sold by the online store based on results of the comparison operations, and

wherein the providing of the compromised payment card assessment report includes identifying a set of trends in purchases of the compromised payment cards that were sold by the online store, and generating, as the score of each payment card entry included in the compromised payment card assessment report, a numerical value based on the set of trends in the purchases of the compromised payment cards, the numerical value serving as a measure of how likely the respective compromised payment card identified by the identification data of that payment card entry will be used for fraud; and

transmitting, over one or more networks, the compromised payment card assessment report to a card organization, the transmitting of the compromised payment card assessment report to the card organization causing contact to be established between the card organization and an owner of the respective compromised payment card to enable the respective compromised payment card to be replaced based on the numerical value of the score.

2. A computer-implemented method as in claim 1 wherein gathering the compromised payment card data includes:

collecting (i) a first compromised payment card inventory from the online store at a first inventory collection time and (ii) a second compromised payment card inventory from the online store at a second inventory collection time, the second inventory collection time occurring after the first inventory collection time.

3. A computer-implemented method as in claim 2 wherein identifying the set of compromised payment cards from the compromised payment card data includes:

performing comparison operations between the first compromised payment card inventory and the second compromised payment card inventory and identifying which compromised payment cards were sold by the online store based on results of the comparison operations.

4. A computer-implemented method as in claim 3 wherein providing the compromised payment card assessment report includes:

identifying a location trend in purchases of the compromised payment cards which were sold by the online store, and

generating a respective location sub-score for each payment card entry included in the compromised payment card assessment report, the respective location sub-score being based on a correlation strength between a location identified by the identification data of that payment card entry and the location trend identified in the purchases of the compromised payment cards which were sold by the online store.

5. A computer-implemented method as in claim 3 wherein providing the compromised payment card assessment report includes:

identifying a card organization trend in purchases of the compromised payment cards which were sold by the online store, and

generating a respective card organization sub-score for each payment card entry included in the compromised payment card assessment report, the respective card organization sub-score being based on a correlation strength between the card organization identified by the identification data of that payment card entry and the card organization trend identified in the purchases of the compromised payment cards which were sold by the online store.

6. A computer-implemented method as in claim 3 wherein providing the compromised payment card assessment report includes:

identifying a card age trend in purchases of the compromised payment cards which were sold by the online store, and

generating a respective card age sub-score for each payment card entry included in the compromised payment card assessment report, the respective card age sub-score being based on a correlation strength between a card age and the card age trend identified in the purchases of the compromised payment cards which were sold by the online store.

7. A computer-implemented method as in claim 3 wherein providing the compromised payment card assessment report includes:

identifying a bank number trend in purchases of the compromised payment cards which were sold by the online store, and

generating a respective bank number sub-score for each payment card entry included in the compromised payment card assessment report, the respective card bank number sub-score being based on a correlation strength between a bank number identified by the identification data of that payment card entry and the bank number trend identified in the purchases of the compromised payment cards which were sold by the online store.

8. A computer-implemented method as in claim 3 wherein providing the compromised payment card assessment report includes:

identifying a card source trend in purchases of the compromised payment cards which were sold by the online store, and

generating a respective card source sub-score for each payment card entry included in the compromised payment card assessment report, the respective card source sub-score being based on a correlation strength between a card source identified by the identification data of that payment card entry and the card source trend identified in the purchases of the compromised payment cards which were sold by the online store.

9. A computer-implemented method as in claim 3 wherein providing the compromised payment card assessment report includes:

identifying, in purchases of the compromised payment cards which were sold by the online store, a location trend, a card organization trend, a card age trend, a bank number trend, and a card source trend, and

generating a location sub-score, a card organization sub-score, a card age sub-score, a bank number sub-score, and a card source sub-score for each payment card entry included in the compromised payment card assessment report, and aggregating the sub-scores for each payment card entry to form, for that payment card entry, the score which indicates the estimated likelihood that the respective compromised payment card will actually be used for fraud.

10. An electronic apparatus, comprising:

a communications interface;

memory; and

control circuitry coupled to the communications interface and the memory, the memory storing instructions that, when carried out by the control circuitry, cause the control circuitry to:

gather compromised payment card data through the communications interface, including automatically crawl content of a web page containing the compromised payment card data, and scrape the compromised payment card data from the web page, the web page being associated with an online store selling stolen payment card data;

identify a set of compromised payment cards from the compromised payment card data;

in response to identifying the set of compromised payment cards, provide a compromised payment card assessment report that includes a set of payment card entries corresponding to the set of compromised payment cards, each payment card entry including (i) identification data that identifies a respective compromised payment card and (ii) a score that indicates an estimated likelihood that the respective compromised payment card will actually be used for fraud,

wherein the control circuitry, when gathering the compromised payment card data, is constructed and arranged to automatically crawl the content of the web page to collect compromised payment card inventories from the online store through the communications interface at different collection times,

wherein the control circuitry, when identifying the set of compromised payment cards from the compromised payment card data, is constructed and arranged to perform comparison operations between the compromised payment card inventories that were collected from the online store at the different times and identifying which compromised payment cards were sold by the online store based on results of the comparison operations, and

wherein the control circuitry, when providing the compromised payment card assessment report, is constructed and arranged to identify a set of trends in purchases of the compromised payment cards that were sold by the online store, and generate, as the score of each payment card entry included in the compromised payment card assessment report, a numerical value based on the set of trends in the purchases of the compromised payment cards, the numerical value serving as a measure of how likely the respective compromised payment card identified by the identification data of that payment card entry will be used for fraud; and

transmit, over one or more networks, the compromised payment card assessment report to a card organization, the transmitting of the compromised payment card assessment report to the card organization causing contact to be established between the card organization and an owner of the respective compromised payment card to enable the respective compromised payment card to be replaced based on the numerical value of the score.

11. A computer program product having a non-transitory computer readable medium which stores a set of instructions to provide a compromised payment card risk assessment, the set of instructions, when carried out by computerized circuitry, causing the computerized circuitry to perform a method of:

gathering compromised payment card data, the gathering of the compromised payment card data including automatically crawling content of a web page containing the compromised payment card data, and scraping the compromised payment card data from the web page, the web page being associated with an online store selling stolen payment card data;

identifying a set of compromised payment cards from the compromised payment card data;

in response to identifying the set of compromised payment cards, providing a compromised payment card assessment report which includes a set of payment card entries corresponding to the set of compromised payment cards, each payment card entry including (i) identification data which identifies a respective compromised payment card and (ii) a score which indicates an estimated likelihood that the respective compromised payment card will actually be used for fraud,

wherein the gathering of the compromised payment card data includes automatically crawling the content of the web page to collect compromised payment card inventories from the online store at different collection times,

wherein the identifying of the set of compromised payment cards from the compromised payment card data includes performing comparison operations between the compromised payment card inventories which were collected from the online store at the different times and identifying which compromised payment cards were sold by the online store based on results of the comparison operations, and

wherein the providing of the compromised payment card assessment report includes identifying a set of trends in purchases of the compromised payment cards which were sold by the online store, and generating, as the score of each payment card entry included in the compromised payment card assessment report, a numerical value based on the set of trends in the purchases of the compromised payment cards, the numerical value serving as a measure of how likely the respective compromised payment card identified by the identification data of that payment card entry will be used for fraud; and

transmitting, over one or more networks, the compromised payment card assessment report to a card organization, the transmitting of the compromised payment card assessment report to the card organization causing contact to be established between the card organization and an owner of the respective compromised payment card to enable the respective compromised payment card to be replaced based on the numerical value of the score.

12. A computer-implemented method as in claim 1 further comprising:

obtaining a rank of each of the compromised payment cards based on the numerical value associated with the score of the payment card entry; and

in response to the transmitting of the compromised payment card assessment report to the card organization, causing a predetermined percentage of highest ranked compromised payment cards to be replaced with new payment cards, respectively.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2015
From: COHEN, DANIEL T.
To: EMC CORPORATION
Reel/Frame 035534/0195 →
Cited By (1)
US 12,619,784