IP Library Granted Patent US 12,225,021
Granted Patent B2
US 12,225,021 · App. 17/321,847 · Granted Feb 11, 2025

Classification scheme for detecting illegitimate account creation

Inventors: Andreas Varnavas (Patra, GR); Ananthaneni Sai Teja Chowdary (Bangalore, IN); Nikolaos Tsapakis (Patra, GR); Premkumar S J (Bangalore, IN); Manikam Muthiah (Banglore, IN)
Assignee: Citrix Systems, Inc.
H04L63/1416G06F21/50H04L63/1425H04L63/1483H04W12/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,225,021
App. No.
17/321,847
Granted
Feb 11, 2025
Kind
B2
Abstract

A system and method that detects malicious account creation in a web-based platform. A method includes detecting suspicious events associated with an account creation process using a username classifier that evaluates a username used to create a new account, an IP address classifier that evaluates an IP address used to create the new account, and a domain classifier that evaluates a domain from an email address used to create the new account; analyzing each detected suspicious event with a density analysis classifier to determine if each detected suspicious event comprises a malicious event based on a density of detected suspicious events from a collections of account creation processes; and determining an alert condition based on at least one malicious event detection.

Claims (48)

1. A system, comprising:

a memory; and

a processor coupled to the memory and configured to execute instructions that detect a malicious account in a web-based platform, wherein the instructions cause the processor to:

detect suspicious events associated with an account creation process using a username classifier that evaluates a username used to create a new account, an internet protocol (IP) address classifier that evaluates an IP address used to create the new account, and a domain classifier that evaluates a domain from an email address used to create the new account;

analyze each detected suspicious event with a density analysis classifier to determine if each detected suspicious event comprises a malicious event based on a density of detected suspicious events from a collection of account creation processes; and

determine an alert condition based on at least one malicious event detection,

wherein the domain classifier is trained by evaluating domains used to create prior accounts in order to determine a threshold, and wherein domain classifier:

obtains the domain used for the new account;

determines a number of accounts created with the domain during a predefined time period; and

generates a suspicious event if the number of accounts exceeds the threshold.

2. The system of claim 1 , wherein the username classifier is trained with a first dataset of legitimate usernames and a second dataset of illegitimate usernames, and wherein the username classifier:

analyzes the username structure of a new username to predict whether the new username is legitimate or illegitimate; and

flags an illegitimate username as a suspicious event.

3. The system of claim 2 , wherein the username classifier is trained using N-grams in combination with a Naïve Bayes classifier.

4. The system of claim 1 , wherein the username classifier is trained to predict whether the username comprises a suspicious event based on a number of characters in the username.

5. The system of claim 1 , wherein the IP address classifier is trained by evaluating IP addresses used to create prior accounts in order to determine a threshold, and wherein IP address classifier:

obtains the IP address used for the new account;

determines a number of accounts created with the IP address during a predefined time period; and

generates a suspicious event if the number of accounts exceeds the threshold.

6. The system of claim 1 , wherein the density analysis classifier:

evaluates a detected suspicious event relative to an associated time series of events within an associated time window in which the events are generated by at least one of the username classifier, IP address classifier and domain classifier; and

classifies the detected suspicious event as a malicious event if a threshold number of events were flagged as suspicious events within the associated time window.

7. The system of claim 1 , wherein each of the username classifier, IP address classifier, domain classifier and density analysis classifier are tuned to produce an overall target specificity that dictates a precision as a function of recall, wherein the precision is a ratio of correctly detected malicious events relative to a total number of detected events and recall is a probability that a malicious event will be detected.

8. The system of claim 7 , wherein the overall target specificity is determined based on a historical prevalence of correctly detected malicious events.

9. The system of claim 7 , wherein the overall target specificity is determined based on an assumption about a prevalence of malicious events in the web-based platform.

10. A computerized method, comprising:

detecting suspicious events associated with an account creation process using a username classifier that evaluates a username used to create a new account, an internet protocol (IP) address classifier that evaluates an IP address used to create the new account, and a domain classifier that evaluates a domain from an email address used to create the new account;

analyzing each detected suspicious event with a density analysis classifier to determine if each detected suspicious event comprises a malicious event based on a density of detected suspicious events from a collection of account creation processes; and

determining an alert condition based on at least one malicious event detection,

wherein the domain classifier is trained by evaluating domains used to create prior accounts in order to determine a threshold, and wherein domain classifier:

obtains the domain used for the new account;

determines a number of accounts created with the domain during a predefined time period; and

generates a suspicious event if the number of accounts exceeds the threshold.

11. The method of claim 10 , wherein the username classifier is trained with a first dataset of legitimate usernames and a second dataset of illegitimate usernames, and wherein the username classifier:

analyzes the username structure of a new username to predict whether the new username is legitimate or illegitimate; and

flags an illegitimate username as a suspicious event.

12. The method of claim 11 , wherein the username classifier is trained using N-grams in combination with a Naïve Bayes classifier.

13. The method of claim 10 , wherein the username classifier is trained to predict whether the username comprises a suspicious event based on a number of characters in the username.

14. The method of claim 10 , wherein the IP address classifier is trained by evaluating IP addresses used to create prior accounts in order to determine a threshold, and wherein IP address classifier:

obtains the IP address used for the new account;

determines a number of accounts created with the IP address during a predefined time period; and

generates a suspicious event if the number of accounts exceeds the threshold.

15. The method of claim 10 , wherein the density analysis classifier:

evaluates a detected suspicious event relative to an associated time series of events within an associated time window in which the events are generated by at least one of the username classifier, IP address classifier and domain classifier; and

classifies the detected suspicious event as a malicious event if a threshold number of events were flagged as suspicious events within the associated time window.

16. The method of claim 10 , wherein each of the username classifier, IP address classifier, domain classifier and density analysis classifier are tuned to produce an overall target specificity that dictates a precision as a function of recall, wherein the precision is a ratio of correctly detected malicious events relative to a total number of detected events and recall is a probability that a malicious event will be detected.

17. The method of claim 16 , wherein the overall target specificity is determined based on a historical prevalence of correctly detected malicious events.

18. The method of claim 16 , wherein the overall target specificity is determined based on an assumption about a prevalence of malicious events in the web-based platform.

Assignments (10)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SECOND INVENTOR'S NAME PREVIOUSLY RECORDED AT REEL: 056260 FRAME: 0188. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded May 24, 2021
From: VARNAVAS, ANDREAS; SAI TEJA CHOWDARY, ANANTHANENI; TSAPAKIS, NIKOLAOS; SJ, PREMKUMAR; MUTHIAH, MANIKAM
To: CITRIX SYSTEMS, INC.
Reel/Frame 056350/0368 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2021
From: VARNAVAS, ANDREAS; SAI TEJA CHOWDARY, ANATHANENI; TSAPAKIS, NIKOLAOS; SJ, PREMKUMAR; MUTHIAH, MANIKAM
To: CITRIX SYSTEMS, INC.
Reel/Frame 056260/0188 →
Continuity (2)
Continuation PCTGR2021000027 · May 5, 2021
Related Publication 20220360596A1 · Nov 10, 2022
References Cited (19)
US 8601548B1 · Shen · 2013 [cited by examiner]
US 11087087B1 · Mayer · 2021 [cited by examiner]
US 20100077043A1 · Ramarao · 2010 [cited by examiner]
US 20200169558A1 · Gordon · 2020 [cited by examiner]
US 20210126938A1 · Trost et al. · 2021 [cited by applicant]
US 20220019888A1 · Aggarwal · 2022 [cited by examiner]
US 20220083397A1 · Moser · 2022 [cited by examiner]
Unknown; “About Fake Signups”; Printed Feb. 25, 2021; pp. 7; Copyright 2001-2021 Mailchimp; <https://mailchimp.com/help/about-fake-signups>. [cited by applicant]
Unknown; “How to detect and prevent fake account creation on your websites and apps”; Printed Apr. 14, 2021; pp. 10; Copyright 2021 DataDome; <https://datadome.co/bot-mangement-protection/how-to-detect-prevent-fake-acco… [cited by applicant]
Beskow, David et al.; “Its All in a Name: Detecting and Labeling Bots by Their Names”; Computational and Mathematical Organization Theory; Mar. 2019; Printed Feb. 25, 2021; pp. 9; Copyright 2008-2021 ResearchGate GmbH; … [cited by applicant]
Wybieralska, Anna; “How to Stop bots from Spamming your sign up forms”; How to Stop Bots from Filing Out & Submitting Forms?/Elastic Email; Mar. 12, 2018; Printed Feb. 25, 2021; pp. 10; <https://wlasticemail.com/blog/ma… [cited by applicant]
Freeman, David Mandell; “Using Naive Bayes to Detect Spammy Names in Social Networks”; Nov. 4, 2013; Copyright help by owner/author; pp. 10. [cited by applicant]
International Search Report and Written Opinion mailed Jan. 14, 2022 for PCT/GR2021/000027 filed May 5, 2021; pp. 15. [cited by applicant]
Sangho, Lee et al.; “Early filtering of ephemeral malicious accounts on Twitter”; Computer Communications; vol. 54; Dec. 1, 2014; pp. 48-57, XP055876114; ISSN: 0140-3664; DOI: 10.1016/j.comcom; Abstract; <https://www.sc… [cited by applicant]
Yuan, Dong et al.; “Detecting Fake Accounts in Online Social Networks at the Time of Registrations”; Designing Interactive Systems Conference; ACM; 2 Penn Plaza, Suite 701, New York, NY10121-0701 USA; Nov. 6, 2019; pp. … [cited by applicant]
Canali, Daivde et al.; “Prophiler”; World Wide Web; ACM; 2 Penn Plaza, Suite 701 New York NY 10121-0701 USA; Mar. 28, 2011; pp. 197-206; XP058001392; DOI: 10.1145/1963405.1963436 ISBN: 978-1-4503-0632-4; Abstract; Secti… [cited by applicant]
Gong, Qingyuan et al; “Detecting Malicious Accounts in Online Developer Communities Using Deep Learning”; Proceedings of the 28th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Founda… [cited by applicant]
Gowtham, R. et al.; “A comprehensive and efficacious architecture for detecting phishing webpages”; Computers & Security; Elsevier Science Publishers; Amsterdam, NL; vol. 40; Nov. 11, 2013, pp. 23-37; XP028818427; ISSN:… [cited by applicant]
Latah, Majd et al.; “Detection of malicious social bots: A survey and a refined taxonomy”; Expert Systems With Applications; Elsevier; Amsterdam, NL; vol. 151; Mar. 14, 2020; XP086150888; ISSN: 0957-4174; DOI: 10.1016/J… [cited by applicant]