IP Library › Granted Patent US 11,930,034
Granted Patent B2
US 11,930,034 · App. 17/357,866 · Granted Mar 12, 2024

Techniques for determining legitimacy of email addresses for online access control

Inventor: Matthew Lewis Jones (Boise, ID)
Assignee: Kount, Inc.
H04L63/1433H04L63/126
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,930,034
App. No.
17/357,866
Granted
Mar 12, 2024
Kind
B2
Abstract

Various aspects involve determining legitimacy of an email address for risk assessment or other purposes. For instance, a risk assessment computing system receives a risk assessment query that identifies an email address. The risk assessment computing system determines a set of features for the email address. For each feature, the risk assessment computing system calculates an illegitimacy score by calculating a deviation of the feature from an expected safe value for the feature that is determined from historical email addresses. The risk assessment computing system aggregates the illegitimacy scores of the plurality of features into an aggregated illegitimacy score and further transmits a legitimacy risk value to a remote computing system. The legitimacy risk value indicates the aggregated illegitimacy score and can be used in controlling access of a computing device associated with the email address to one or more interactive computing environments.

Claims (71)

1. A method comprising one or more processing devices performing operations comprising:

receiving a risk assessment query that identifies an email address;

determining a plurality of features for the email address, wherein determining the plurality of features comprises determining a feature based on characters contained in the email address;

for each feature of the plurality of features, determining an expected safe value for the feature by calculating a median value of the feature for a set of legitimate historical email addresses, wherein calculating the median value of the feature comprises determining a weight for each legitimate historical email address of the set of legitimate historical email addresses based on a number of interactions of the legitimate historical email address with a risk assessment computing system;

for each feature of the plurality of features, calculating an illegitimacy score by calculating a deviation of the feature from the expected safe value for the feature;

aggregating the illegitimacy scores of the plurality of features into an aggregated illegitimacy score; and

transmitting a legitimacy risk value indicating the aggregated illegitimacy score to a remote computing system for use in controlling access of a computing device associated with the email address to one or more interactive computing environments.

2. The method of claim 1 , further comprising:

pre-processing the email address to standardize the email address.

3. The method of claim 1 , wherein determining the feature based on characters contained in the email address comprises one or more of:

determining the feature based on physical characteristics of the email address;

determining the feature based on compositions of the email address; or

determining the feature based on cross-term compositions of the email address.

4. The method of claim 1 , wherein determining the feature based on characters contained in the email address comprises:

calculating, based on a Markov model, a probability of a character in the email address appearing after one or more characters preceding the character; and

generating the feature based on the calculated probability.

5. The method of claim 1 , wherein determining the plurality of features further comprises determining the feature based on characters contained in the email address and historical data associated with the email address.

6. The method of claim 1 , wherein calculating the deviation of the feature from the expected safe value for the feature that is determined from historical email addresses comprises:

calculating a number of interquartile ranges from the feature to a median value for the feature determined from historical email addresses; or

calculating a number of standard deviations from the feature to a mean value for the feature determined from historical email addresses.

7. The method of claim 1 , wherein aggregating the illegitimacy scores of the plurality of features comprises:

calculating an L2 norm of the illegitimacy scores of the plurality of features;

calculating a sum of the illegitimacy scores of the plurality of features;

calculating a mean of the illegitimacy scores of the plurality of features; or

determining a maximum of the illegitimacy scores of the plurality of features.

8. The method of claim 1 , further comprising:

converting the aggregated illegitimacy score into the legitimacy risk value through a monotonic transform function, wherein the monotonic transform function comprises a logistic function.

9. The method of claim 1 , further comprising:

determining that the email address contains a zip code associated with a user of the email address or that the email address contains solely hexadecimal characters; and

assigning a legitimacy risk value higher than a threshold risk value to the email address, the legitimacy risk value higher than the threshold risk value indicating that the email address is illegitimate.

10. A non-transitory computer-readable storage medium having program code that is executable by a processor device to cause a computing device to perform operations, the operations comprising:

receiving a risk assessment query that identifies an email address;

determining a plurality of features for the email address, wherein determining the plurality of features comprises determining a feature based on characters contained in the email address;

for each feature of the plurality of features, determining an expected safe value for the feature by calculating a median value of the feature for a set of legitimate historical email addresses, wherein calculating the median value of the feature comprises determining a weight for each legitimate historical email address of the set of legitimate historical email addresses based on a number of interactions of the legitimate historical email address with a risk assessment computing system;

for each feature of the plurality of features, calculating an illegitimacy score by calculating a deviation of the feature from the expected safe value for the feature;

aggregating the illegitimacy scores of the plurality of features into an aggregated illegitimacy score; and

transmitting a legitimacy risk value indicating the aggregated illegitimacy score to a remote computing system for use in controlling access of a computing device associated with the email address to one or more interactive computing environments.

11. The non-transitory computer-readable storage medium of claim 10 , the operations further comprising:

pre-processing the email address to standardize the email address.

12. The non-transitory computer-readable storage medium of claim 10 , wherein determining the feature based on characters contained in the email address comprises one or more of:

determining the feature based on physical characteristics of the email address;

determining the feature based on compositions of the email address; or

determining the feature based on cross-term compositions of the email address.

13. The non-transitory computer-readable storage medium of claim 10 , wherein determining the feature based on characters contained in the email address comprises:

calculating, based on a Markov model, a probability of a character in the email address appearing after one or more characters preceding the character; and

generating the feature based on the calculated probability.

14. The non-transitory computer-readable storage medium of claim 10 , wherein determining the plurality of features further comprises determining the feature based on characters contained in the email address and historical data associated with the email address.

15. The non-transitory computer-readable storage medium of claim 10 , wherein calculating the deviation of the feature from the expected safe value for the feature that is determined from historical email addresses comprises:

calculating a number of interquartile ranges from the feature to a median value for the feature determined from historical email addresses; or

calculating a number of standard deviations from the feature a mean value for the feature determined from historical email addresses.

16. A system comprising:

a processing device; and

a memory device in which instructions executable by the processing device are stored for causing the processing device to perform operations comprising:

receiving a risk assessment query that identifies an email address;

determining a plurality of features for the email address, wherein determining the plurality of features comprises determining a feature based on characters contained in the email address;

for each feature of the plurality of features, determining an expected safe value for the feature by calculating a median value of the feature for a set of legitimate historical email addresses, wherein calculating the median value of the feature comprises determining a weight for each legitimate historical email address of the set of legitimate historical email addresses based on a number of interactions of the legitimate historical email address with a risk assessment computing system;

for each feature of the plurality of features, calculating an illegitimacy score by calculating a deviation of the feature from the expected safe value for the feature;

aggregating the illegitimacy scores of the plurality of features into an aggregated illegitimacy score; and

transmitting a legitimacy risk value indicating the aggregated illegitimacy score to a remote computing system for use in controlling access of a computing device associated with the email address to one or more interactive computing environments.

17. The system of claim 16 , wherein determining the feature based on characters contained in the email address comprises one or more of:

determining the feature based on physical characteristics of the email address;

determining the feature based on compositions of the email address; or

determining the feature based on cross-term compositions of the email address.

18. The system of claim 16 , wherein the operations further comprise:

converting the aggregated illegitimacy score into the legitimacy risk value through a monotonic transform function, wherein the monotonic transform function comprises a logistic function.

19. The system of claim 16 , wherein calculating the deviation of the feature from the expected safe value for the feature that is determined from historical email addresses comprises:

calculating a number of interquartile ranges from the feature to a median value for the feature determined from historical email addresses; or

calculating a number of standard deviations from the feature a mean value for the feature determined from historical email addresses.

20. The system of claim 16 , wherein determining the feature based on characters contained in the email address comprises:

calculating, based on a Markov model, a probability of a character in the email address appearing after one or more characters preceding the character; and

generating the feature based on the calculated probability.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2021
From: JONES, MATTHEW LEWIS
To: KOUNT, INC.
Reel/Frame 057378/0109 →
Continuity (1)
Related Publication 20220417275A1 · Dec 29, 2022
Cited By (1)
US 12,586,068