IP Library Granted Patent US 12,373,842
Granted Patent B2
US 12,373,842 · App. 18/767,005 · Granted Jul 29, 2025

System and method for identifying suspicious destinations

Inventors: Jamie Gamble (Toronto, CA); Gadi Shpits (Toronto, CA); Ilya Kolmanovich (Toronto, CA); Cormac O′Keeffe (Toronto, CA)
Assignee: Royal Bank of Canada
G06Q20/4016G06Q20/4014H04L63/0876H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,373,842
App. No.
18/767,005
Granted
Jul 29, 2025
Kind
B2
Abstract

Transaction destinations are identified by identifying requests for a login page of a web server for a financial institution and determining a referring website for each of the requests; classifying the referring websites into classes, each of the classes having a risk rating; identifying logins to access the web server and determining a user associated with each login; associating each of the logins with one of the requests and the referring website for that request; for each of the users, identifying transactions occurring within a time period from when the login was initiated; for each of the transactions occurring within the time period, associating a transaction destination of that transaction with the referring website for that login; and assigning a risk rating to each of the transaction destinations based at least in part on a risk rating of the class of the associated referring website.

Claims (33)

1. A computer-implemented method for facilitating electronic financial transactions, the method performed by a web server, the method comprising:

identifying requests for a login page of the web server, wherein the requests include HTTP requests;

upon identifying the requests, determining a referring website for each of the identified requests based on an HTTP referrer header of each of said requests, said HTTP referrer header including an address of said referring website;

scanning, by a site classifier, each of said referring websites to extract keywords from each respective referring website;

identifying, by said site classifier using natural language processing, an industry of each respective referring website;

classifying the referring websites into classes based on a classification system, each of the classes having a risk rating;

identifying logins to access the web server;

upon identifying the logins, determining a user associated with each of the logins;

associating each of the logins with one of the identified requests and with the referring website for that identified request;

for each of the users, identifying transactions occurring within a time period from when the one of the logins was initiated;

for each of the transactions occurring within the time period, associating a transaction destination of that transaction with the referring website for that one of the logins;

assigning a risk rating to each of the transaction destinations based at least in part on a risk rating of the class of the associated referring website; and

permitting or blocking an electronic financial transaction of the transactions occurring within the time period based on the risk rating of the transaction destination associated with that transaction.

2. The computer-implemented method of claim 1 , wherein the determining the referring website comprises extracting an identifier of the referring website web server logs from the financial institution.

3. The computer-implemented method of claim 1 , wherein the associating each of the logins with one of the requests and the referring website for that request is based at least in part on comparing a time stamp of the login and a time stamp of the request.

4. The computer-implemented method of claim 1 , wherein the associating each of the logins with one of the requests and the referring website for that request is based at least in part on a cookie upon login linking an account of the user with a browser of the user.

5. The computer-implemented method of claim 1 , wherein the determining the user associated with each login is based at least in part on an IP address in a web server log.

6. The computer-implemented method of claim 1 , wherein the determining the user associated with each login is based at least in part on an IP address in a HTTP request.

7. The computer-implemented method of claim 1 , further comprising, grouping users from a common class of the referring websites and identifying, for each of the groups of users, a common transaction destination.

8. The computer-implemented method of claim 7 , wherein the common transaction destination is identified from the destinations containing a common word.

9. The computer-implemented method of claim 1 , wherein the time period is between ten and thirty minutes.

10. The computer-implemented method of claim 9 , wherein the time period is twenty minutes.

11. The computer-implemented method of claim 1 , wherein the risk ratings of the classes are based at least in part on a whitelist of websites.

12. The computer-implemented method of claim 1 , wherein the transaction destination of at least one of the transactions is an identification of an entity.

13. The computer-implemented method of claim 1 , wherein the transaction destination of at least one of the transactions is a bank account.

14. The computer-implemented method of claim 1 , further comprising identifying additional transactions that send funds to one or more of the transaction destinations.

15. The computer-implemented method of claim 14 , further comprising assigning a risk rating to the additional transactions based at least in part on the risk ratings of the transaction destinations.

16. The computer-implemented method of claim 1 , further comprising for each of the transactions, identifying a transaction type and assigning a risk rating to the transaction type based at least in part on the risk rating of the transaction destination.

17. The computer-implemented method of claim 1 , wherein said generating classifications is based on said classification system and said industry.

18. A computer system comprising:

a processor; and

a memory in communication with the processor, the memory storing instructions that, when executed by the processor cause the processor to perform the method of claim 1 .

19. A non-transitory computer-readable medium having computer executable instructions stored thereon for execution by one or more computing devices, that when executed perform the method of claim 1 .

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2024
From: GAMBLE, JAMIE
To: ROYAL BANK OF CANADA
Reel/Frame 068058/0627 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2024
From: SHPITS, GADI; KOLMANOVICH, ILYA; O’KEEFFE, CORMAC
To: ROYAL BANK OF CANADA
Reel/Frame 068058/0853 →
Continuity (3)
Continuation 17162039 · Jan 29, 2021
Provisional Application 62968192 · Jan 31, 2020
Related Publication 20240362643A1 · Oct 31, 2024
References Cited (6)
US 8170953B1 · Tullis · 2012 [cited by examiner]
US 9767449B2 · Brody · 2017 [cited by examiner]
US 10104113B1 · Stein · 2018 [cited by examiner]
US 10567402B1 · Comeaux et al. · 2020 [cited by applicant]
US 20160239831A1 · Saunders · 2016 [cited by applicant]
US 20180197182A1 · Nidamanuri et al. · 2018 [cited by applicant]