IP Library › Granted Patent US 12,026,683
Granted Patent B2
US 12,026,683 · App. 15/691,565 · Granted Jul 2, 2024

System and method for risk assessment of a third party application for controlling competitive migration

Inventors: Venkata Nagabhushan Rao Varagani (Bangalore, IN); Sudeep Gangadharan (Bangalore, IN)
Assignee: Intuit Inc.
G06Q20/02G06F16/2455G06Q20/10G06Q20/3829G06Q20/4016G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,026,683
App. No.
15/691,565
Granted
Jul 2, 2024
Kind
B2
Abstract

In general, the invention relates to a method involving allowing access to a financial application by a third-party extension based on a single license to use the financial application, where the third-party extension was developed by a third-party developer using one or more tools in a software development kit (SDK) for the financial application and where the financial application stores first transaction data obtained for a first user of the financial application, monitoring operations performed on the financial application by the third-party extension to detect operations that migrate transaction data to a competitive application, using distributed computing software adjust a risk index that is associated with the third-party extension, determining that the risk index exceeds a pre-defined threshold, and controlling future access to the financial application by the third-party extension.

Claims (41)

1. A method, comprising operations of:

servicing, by an application, access by a third-party extension, executing on each of a plurality of devices, to the application based on a single license to use the application, wherein the third-party extension was developed by a third-party developer using one or more tools in a software development kit (SDK) for the application and wherein the application stores first transaction data obtained for a first user of the application;

monitoring operations that are performed on the application by the third-party extension to detect operations that migrate transaction data from the application to a competitive application with the third-party extension and generate a plurality of action scores for the third-party extension, wherein the monitored operations include a relatively large number of unique commands written in a structured query language (SQL);

applying a classifier to the plurality of action scores to generate a risk index with a processor that applies the classifier to the plurality of action scores,

wherein training the classifier comprises using a plurality of monitored operations, the plurality of monitored operations performed on the application, the plurality of monitored operations comprising one or more of continuous reads, bulk data extractions, and a number of unique commands written in the structured query language,

wherein the risk index measures a likelihood that the third-party application is being used to migrate transaction data to the competitive application, and

wherein software that maintains the risk index is trained on past monitored operations using unsupervised machine-learning;

using distributed computing software to adjust the risk index that is associated with the third-party extension;

determining that the risk index exceeds a pre-defined threshold; and

denying access, from the third-party extension on each of the plurality of devices using the third-party extension, to the application after determining that the risk index exceeds the pre-defined threshold.

2. The method of claim 1 , wherein the application stores second transaction data obtained for a second user of the application.

3. The method of claim 2 , wherein the monitored operations include a first continuous read of the first transaction data and a second continuous read of the second transaction data.

4. The method of claim 2 , wherein the monitored operations include a first bulk data extraction of the first transaction data and a second bulk data extraction of the second transaction data.

5. The method of claim 1 , wherein denying access includes revoking the single license to use the application.

6. A non-transitory computer-readable storage medium configured to store a program, wherein the program, when executed, performs operations to:

service, by an application, access by a third-party extension, executing on each of a plurality of devices, to the application based on a single license to use the application, wherein the third-party extension was developed by a third-party developer using one or more tools in a software development kit (SDK) for the application and wherein the application stores first transaction data obtained for a first user of the application;

monitor operations that are performed on the application by the third-party extension to detect operations that migrate transaction data from the application to a competitive application with the third-party extension and generate a plurality of action scores for the third-party extension, wherein the monitored operations include a relatively large number of unique commands written in structured query language (SQL);

apply a classifier to the plurality of action scores to generate a risk index with a processor that applies the classifier to the plurality of action scores,

wherein training the classifier comprises using a plurality of monitored operations, the plurality of monitored operations performed on the application, the plurality of monitored operations comprising one or more of continuous reads, bulk data extractions, and a number of unique commands written in the structured query language,

wherein the risk index measures a likelihood that the third-party application is being used to migrate transaction data to the competitive application, and

wherein software that maintains the risk index is trained on past monitored operations using unsupervised machine-learning;

use distributed computing software to adjust the risk index that is associated with the third-party extension, wherein the risk index is based at least in part on the monitored operations;

determine that the risk index exceeds a pre-defined threshold; and

deny access, from the third-party extension on each of the plurality of devices using the third-party extension, to the application after determining that the risk index exceeds the pre-defined threshold.

7. The non-transitory computer-readable storage medium of claim 6 , wherein the application stores second transaction data obtained for a second user of the application.

8. The non-transitory computer-readable storage medium of claim 7 , wherein the monitored operations include a first continuous read of the first transaction data and a second continuous read of the second transaction data.

9. The non-transitory computer-readable storage medium of claim 7 , wherein the monitored operations include a first bulk data extraction of the first transaction data and a second bulk data extraction of the second transaction data.

10. The non-transitory computer-readable storage medium of claim 6 , wherein denying access includes revoking the single license to use the application.

11. The non-transitory computer-readable storage medium of claim 6 , wherein the unsupervised machine-learning is based at least in part on clustering techniques.

12. A system, comprising:

a hardware processor and memory;

software instructions stored in the memory and configured to execute on the hardware processor, which, when executed cause the hardware processor to:

service, by an application, access by a third-party extension, executing on each of a plurality of devices, to the application based on a single license to use the application, wherein the third-party extension was developed by a third-party developer using one or more tools in a software development kit (SDK) for the application and wherein the application stores first transaction data obtained for a first user of the application;

monitor operations that are performed on the application by the third-party extension to detect operations that migrate transaction data from the application to a competitive application with the third-party extension and generate a plurality of action scores for the third-party extension, wherein the monitored operations include a relatively large number of unique commands written in structured query language (SQL);

apply a classifier to the plurality of action scores to generate a risk index with a processor that applies the classifier to the plurality of action scores,

wherein training the classifier comprises using a plurality of monitored operations, the plurality of monitored operations performed on the application, the plurality of monitored operations comprising one or more of continuous reads, bulk data extractions, and a number of unique commands written in the structured query language,

wherein the risk index measures a likelihood that the third-party application is being used to migrate transaction data to the competitive application, and

wherein software that maintains the risk index is trained on past monitored operations using unsupervised machine-learning;

use distributed computing software to adjust the risk index that is associated with the third-party extension, wherein the risk index is based at least in part on the monitored operations;

determine that the risk index exceeds a pre-defined threshold; and

deny access, from the third-party extension on each of the plurality of devices using the third-party extension, to the application after determining that the risk index exceeds the pre-defined threshold.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2017
From: VARAGANI, VENKATA NAGABHUSHAN RAO; GANGADHARAN, SUDEEP
To: INTUIT INC.
Reel/Frame 043536/0679 →
Priority Claims (1)
IN 201731023153 · Jun 30, 2017 · national
Continuity (1)
Related Publication 20190005467A1 · Jan 3, 2019