IP Library › Granted Patent US 11,658,987
Granted Patent B2
US 11,658,987 · App. 17/142,664 · Granted May 23, 2023

Dynamic fraudulent user blacklist to detect fraudulent user activity with near real-time capabilities

Inventors: Jeremy Edward Goodsitt (Champaign, IL); Austin Grant Walters (Savoy, IL); Reza Farivar (Champaign, IL); Vincent Pham (Champaign, IL)
Assignee: Capital One Services, LLC
H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,658,987
App. No.
17/142,664
Granted
May 23, 2023
Kind
B2
Abstract

Various embodiments are generally directed to detecting fraudulent activity on a user account based at least in part on a dynamic fraudulent user blacklist. The fraudulent activity may be identified based on a similarity of forensic profiling across multiple user accounts, for example, fraudulent activity occurring by the same fraudster or perpetrator may have a similar or identical fraudulent pattern across the multiple user accounts. By identifying the fraudulent user patterns associated the same fraudster and dynamically updating a blacklist to include these fraudulent user patterns, the same types of attacks may be prevented on the other existing user accounts.

Claims (67)

1. An apparatus comprising:

one or more processors operable to execute stored instructions that, when executed, cause the one or more processors to:

determine a first fraudulent user pattern in response to a notification from a first user account of a first fraudulent access, the first fraudulent user pattern comprising a fraudster sequentially performing a first action and a second action via an account interface;

add the first fraudulent user pattern to a blacklist;

determine a second fraudulent user pattern indicating an abnormal user pattern likely to be fraudulent, the second fraudulent user pattern being determined without notification from any user account;

dynamically update the blacklist to add the second fraudulent user pattern and generate an updated blacklist;

perform a fraud analysis by analyzing a plurality of user accounts by comparing at least the first and second fraudulent user patterns of the blacklist to user account activities associated with the plurality of user accounts;

detect that a second fraudulent access associated with a second user account has occurred based on the performed fraud analysis; and

alert the second user account of the second fraudulent access,

wherein the determination of the second fraudulent user pattern comprises the one or more processors to:

detect that the abnormal user pattern likely to be fraudulent is similarly or identically associated with multiple user accounts;

perform a second fraud analysis by analyzing the abnormal user pattern across the multiple accounts; and

determine that there is a probability that the multiple accounts are being fraudulently accessed by a same fraudster based at least in part on the performed second fraud analysis.

2. The apparatus of claim 1 , wherein the one or more processors further caused to:

receive the notification from the first user account of the first fraudulent access,

wherein the first action and the second action are related actions performed by the fraudster after the fraudster has gained access to the first user account, and

wherein the first fraudulent user pattern is specifically attributable to the fraudster.

3. The apparatus of claim 1 , wherein the first action or the second action includes the following: (i) selecting a first icon on the account interface associated with the first user account, (ii) selecting a second icon on the account interface associated with the first user account, (iii) selecting or performing a specific transaction, (iv) entering a specific amount corresponding to the specific transaction, (v) requesting funds in the specific amount to be sent to a specific account, and/or (vi) transferring or emptying funds from the first user account.

4. The apparatus of claim 1 , wherein the one or more processors further caused to:

detect that a third fraudulent access associated with a third user account has occurred based at least in part on the performed fraud analysis; and

alert the third user account of the third fraudulent access, and wherein the detection of the third fraudulent access is simultaneous to the detection of the second fraudulent access.

5. The apparatus of claim 4 , wherein the second and third fraudulent accesses are associated with a same fraudster.

6. The apparatus of claim 1 , wherein the notification of the first fraudulent access is provided by an authorized user of the first user account.

7. A method comprising:

determining, via one or more processors, a first fraudulent user pattern in response to a notification from a first user account of a first fraudulent access, the first fraudulent user pattern comprising: a fraudster sequentially selecting a first icon and a second icon via an account interface, the fraudster performing a specific transaction via the account interface, and/or the fraudster moving or emptying funds via the account interface;

adding the first fraudulent user pattern to a blacklist;

determining, via the one or more processors, a second fraudulent user pattern indicating abnormal user pattern likely to be fraudulent, the second fraudulent user pattern being determined without notification from any user account;

dynamically updating, via the one or more processors, the blacklist to add the second fraudulent user pattern and generating an updated blacklist;

performing a fraud analysis by analyzing, via the one or more processors, a plurality of user accounts by comparing at least the first and second fraudulent user patterns of the blacklist to user account activities associated with the plurality of user accounts;

detecting, via the one or more processors, that a second fraudulent access associated with a second user account has occurred based on the performed fraud analysis; and

alerting the second user account of the second fraudulent access,

wherein the determining of the second fraudulent user pattern further comprises:

detecting, via the one or more processors, that the abnormal user pattern likely to be fraudulent is similarly or identically associated with multiple user accounts;

performing a second fraud analysis by analyzing, via the one or more processors, the abnormal user pattern across the multiple accounts; and

determining, via the one or more processors, that there is a probability that the multiple accounts are being fraudulently accessed by a same fraudster based at least in part on the performed second fraud analysis.

8. The method of claim 7 , further comprising:

receiving the notification from the first user account of the first fraudulent access,

wherein the first action and the second action are related actions performed by the fraudster after the fraudster has gained access to the first user account, and

wherein the first fraudulent user pattern is specifically attributable to the fraudster.

9. The method of claim 7 , further comprising:

detecting, via the one or more processors, that a third fraudulent access associated with a third user account has occurred based at least in part on the performed fraud analysis; and

alerting the third user account of the third fraudulent access, and

wherein the detection of the third fraudulent access is simultaneous to the detection of the second fraudulent access.

10. The method of claim 9 , wherein the second and third fraudulent accesses are associated with a same fraudster.

11. The method of claim 7 , wherein the notification of the first fraudulent access is provided by an authorized user of the first user account.

12. At least one non-transitory computer-readable storage medium storing program code executable by at least one processor to:

determine a first fraudulent user pattern in response to a notification from a first user account of a first fraudulent access, the first fraudulent user pattern comprising a fraudster sequentially performing a first action and a second action via an account interface;

determine a second fraudulent user pattern indicating an abnormal user pattern likely to be fraudulent, the second fraudulent user pattern being determined without notification from any user account;

dynamically add the first and second fraudulent user patterns to a blacklist;

perform a fraud analysis by analyzing a plurality of user accounts by comparing at least the first and second fraudulent user patterns of the blacklist to user account activities associated with the plurality of user accounts; and

detect that a second fraudulent access associated with a second user account has occurred based on the performed fraud analysis,

wherein the stored program code causes the at least one processor to:

detect that the abnormal user pattern likely to be fraudulent is similarly or identically associated with multiple user accounts;

perform a second fraud analysis by analyzing the abnormal user pattern across the multiple accounts; and

determine that there is a probability that the multiple accounts are being fraudulently accessed by a same fraudster based at least in part on the performed second fraud analysis.

13. The at least one non-transitory computer-readable storage medium of claim 12 , wherein the stored program code causes the at least one processor to:

receive the notification from the first user account of the first fraudulent access; and

alert the second user account of the second fraudulent access, and

wherein the first action and the second action are related actions performed by the fraudster after the fraudster has gained access to the first user account, and

wherein the first fraudulent user pattern is specifically attributable to the fraudster.

14. The at least one non-transitory computer-readable storage medium of claim 13 , wherein the first action or the second action includes the following: (i) selecting a first icon on the account interface associated with the first user account, (ii) selecting a second icon on the account interface associated with the first user account, (iii) selecting or performing a specific transaction, (iv) entering a specific amount corresponding to the specific transaction, (v) requesting funds in the specific amount to be sent to a specific account, and/or (vi) transferring or emptying funds from the first user account.

15. The at least one non-transitory computer-readable storage medium of claim 13 , wherein the stored program code causes the at least one processor to:

detect that a third fraudulent access associated with a third user account has occurred based at least in part on the performed fraud analysis; and

alert the third user account of the third fraudulent access, and

wherein the detection of the third fraudulent access is simultaneous to the detection of the second fraudulent access.

16. The at least one non-transitory computer-readable storage medium of claim 15 , wherein the second and third fraudulent accesses are associated with a same fraudster.

17. The at least one non-transitory computer-readable storage medium of claim 13 , wherein the notification of the first fraudulent access is provided by an authorized user of the first user account.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2021
From: GOODSITT, JEREMY EDWARD; WALTERS, AUSTIN GRANT; FARIVAR, REZA; PHAM, VINCENT
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 054831/0538 →
Continuity (2)
Continuation 16549306 · Aug 23, 2019
Related Publication 20210126930A1 · Apr 29, 2021