IP Library Granted Patent US 12,432,243
Granted Patent B2
US 12,432,243 · App. 17/211,646 · Granted Sep 30, 2025

Methods of monitoring and protecting access to online services

Inventors: Nicolò Pastore (Pero, IT); Emanuele Parrinello (Crema, IT); Carmine Giangregorio (Milan, IT)
Assignee: CLEAFY SOCIETÀ PER AZIONI
H04L63/1433H04L63/1416H04L63/1425H04L2463/082H04L2463/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,243
App. No.
17/211,646
Granted
Sep 30, 2025
Kind
B2
Abstract

A method of monitoring and protecting access to an online service from Account Take Over may include: providing a Traffic Inspector in communication with at least one device for Internet browsing and with a web server; providing a Traffic Analyzer in communication with the Traffic Inspector; identifying each browsing session of the at least one device; extracting and identifying one or more usernames when a user performs authentication to the service by analyzing traffic exchanged between the at least one device and the web server; collecting first characteristic data concerning unique and/or non-unique technical parameters and associating the first characteristic data with respective identified one or more usernames; identifying each anonymous web beacon generated by the at least one device on the service; and collecting second characteristic data concerning unique and/or non-unique technical parameters and associating the second characteristic data with the anonymous web beacon.

Claims (64)

1. A method of monitoring and protecting access to an online service from Account Take Over, the method comprising:

providing a Traffic Inspector in signal communication with at least one client device for Internet browsing and with a web server having the online service residing therein;

providing a Traffic Analyzer in signal communication with the Traffic Inspector;

identifying, by the Traffic Inspector, each browsing session of the at least one client device on the online service;

extracting and identifying, by the Traffic Analyzer, one or more usernames when a user performs authentication to the online service by analyzing traffic exchanged between the at least one client device and the web server;

collecting, by the Traffic Inspector, first characteristic data concerning unique technical parameters, non-unique technical parameters, or unique and non-unique technical parameters and associating, by the Traffic Analyzer, the first characteristic data with respective identified one or more usernames;

storing the first characteristic data associated with each of the identified one or more usernames in a database associated with the Traffic Analyzer;

identifying, by the Traffic Analyzer, each anonymous web beacon generated by the at least one client device on the online service, wherein the anonymous web beacon indicates that the at least one client device has started a fraudulent browsing session on a phishing web server;

collecting, by the Traffic Inspector, second characteristic data concerning unique technical parameters, non-unique technical parameters, or unique and non-unique technical parameters and associating, by the Traffic Analyzer, the second characteristic data with the anonymous web beacon;

associating an identified username with the anonymous web beacon when the first characteristic data, concerning each of the identified one or more usernames, and the second characteristic data, concerning the anonymous web beacon, compared using a user prediction algorithm residing in the Traffic Analyzer, are at least in part identical or coincident;

entering each identified username associated with the anonymous web beacon, in which a situation involving a risk of credential theft has been detected after a phishing attack, in a watch list by analyzing, using a detection algorithm residing in the Traffic Analyzer, each anonymous web beacon associated with the identified one or more usernames; and

monitoring the browsing sessions in which the risk of credential theft has been detected associated with each identified username in the watch list when the user performs further authentication to the online service, and identifying an Account Take Over attack by the at least one client device and protecting access to the online service when the browsing session relating to the anonymous web beacon and a subsequent authenticated browsing session associated with the same username entered in the watch list occur in a limited time interval.

2. The method of claim 1 , wherein the monitoring of the browsing sessions associated with each identified username in the watch list comprises:

identifying, using the detection algorithm, the browsing sessions at risk associated with each identified username in the watch list when the user performs authentication to the online service; and

protecting the browsing sessions at risk using a protection algorithm residing in the Traffic Analyzer.

3. The method of claim 2 , wherein the protecting of the browsing sessions at risk using the protection algorithm comprises:

locking the username of the user associated with the browsing sessions at risk, executing a Strong Customer Authentication (SCA) algorithm for the username of the user associated with the browsing sessions at risk, or executing a Multi-Factor Authentication (MFA) algorithm for the username of the user associated with the browsing sessions at risk.

4. The method of claim 2 , wherein the monitoring of the browsing sessions associated with each identified username in the watch list comprises:

generating a risk signal indicative of a possible threat associated with a phishing attack in the browsing sessions at risk.

5. The method of claim 1 , further comprising:

removing a username from the watch list when the detection algorithm detects that the phishing attack is over.

6. The method of claim 5 , wherein the removing of the username from the watch list comprises:

removing the username from the watch list when a predetermined time interval has elapsed from a time in which the detection algorithm has detected that the phishing attack is over.

7. The method of claim 1 , wherein the collecting, by the Traffic Inspector, of the first characteristic data concerning unique technical parameters, non-unique technical parameters, or unique and non-unique technical parameters and the associating, by the Traffic Analyzer, of the first characteristic data with the identified one or more usernames comprises:

collecting, by the Traffic Inspector, of the first characteristic data concerning one or more of unique technical parameters, non-unique technical parameters, endpoints, networks, and browsers; and

wherein the collecting, by the Traffic Inspector, of the second characteristic data concerning unique technical parameters, non-unique technical parameters, or unique and non-unique technical parameters and the associating, by the Traffic Analyzer, of the second characteristic data with the anonymous web beacon comprises:

collecting, by the Traffic Inspector, of the second characteristic data concerning one or more of unique technical parameters, non-unique technical parameters, endpoints, networks, and browsers.

8. The method of claim 7 , wherein the first characteristic data and the second characteristic data comprise a Universally Unique Identifier (UUID) and Internet Protocol (IP) address.

9. The method of claim 1 , wherein the monitoring of the browsing sessions in which the risk of credential theft has been detected associated with each identified username in the watch list when the user performs the further authentication to the online service comprises:

comparing, using the detection algorithm, of the first characteristic data associated with a username in the watch list with the first characteristic data collected by the Traffic Inspector when the user performs the further authentication to the online service to identify any anomalies.

10. The method of claim 9 , wherein the comparing, using the detection algorithm, of the first characteristic data associated with the username in the watch list with the first characteristic data collected by the Traffic Inspector when the user performs the further authentication to the online service to identify any anomalies, comprises:

generating a warning when the first characteristic data associated with the username in the watch list differs from the first characteristic data collected by the Traffic Inspector when the user performs the further authentication to the online service.

11. The method of claim 1 , wherein the identifying, by the Traffic Analyzer, of each anonymous web beacon generated by the at least one client device on the online service comprises:

identifying, by the Traffic Analyzer, each anonymous web beacon generated by the at least one client device on the online service using session cookies.

12. The method of claim 1 , wherein the identifying, by the Traffic Inspector, of each browsing session of the at least one client device on the online service comprises:

intercepting, by the Traffic Inspector, a Hypertext Transfer Protocol (HTTP) request sent by a web browser residing in the at least one client device to the web server; and

wherein the extracting and identifying, by the Traffic Analyzer, of the one or more usernames when the user performs authentication to the online service comprises:

extracting a username from the HTTP request intercepted by the Traffic Inspector when the user performs authentication to the online service using an extraction algorithm residing in the Traffic Analyzer and based on regular expressions.

13. The method of claim 1 , further comprising:

modifying the online service by introducing a web beacon therein.

14. The method of claim 1 , wherein the anonymous web beacon includes a Hypertext Transfer Protocol (HTTP) request for a resource residing in the web server,

wherein the identifying, by the Traffic Analyzer, of each generated anonymous web beacon of the at least one client device on the online service comprises:

intercepting, by the Traffic Inspector, each HTTP request associated with the anonymous web beacon; and

wherein the collecting, by the Traffic Inspector, of the second characteristic data concerning unique technical parameters, non-unique technical parameters, or unique and non-unique technical parameters and associating, by the Traffic Analyzer, of the second characteristic data with the anonymous web beacon comprises:

sending, by the Traffic Inspector, of the second characteristic data to the Traffic Analyzer, the second characteristic data being associated with the unique technical parameters, non-unique technical parameters, or unique and non-unique technical parameters characteristic of the request for the resource associated with the anonymous web beacon.

15. The method of claim 14 , wherein the entering of each identified username associated with the anonymous web beacon, in which the situation involving the risk of credential theft has been detected after the phishing attack, in the watch list, comprises:

analyzing whether each HTTP request intercepted by the Traffic Inspector and concerning the anonymous web beacon associated with a username comes from a legitimate domain of the online service; and

generating a warning when an HTTP request does not come from the legitimate domain of the online service.

16. The method of claim 1 , wherein the first characteristic data and the second characteristic data are at least in part identical or coincident when at least one of the unique technical parameters, non-unique technical parameters, or unique and non-unique technical parameters of the first characteristic data is identical to at least one of the unique technical parameters, non-unique technical parameters, or unique and non-unique technical parameters of the second characteristic data.

17. The method of claim 1 , wherein the first characteristic data and the second characteristic data are at least in part identical or coincident when at least one of the unique technical parameters of the first characteristic data is identical to at least one of the unique technical parameters of the second characteristic data.

18. The method of claim 1 , wherein the first characteristic data and the second characteristic data are at least in part identical or coincident when at least one of the non-unique technical parameters of the first characteristic data is identical to at least one of the non-unique technical parameters of the second characteristic data.

19. A method of monitoring and protecting access to an online service from Account Take Over, the method comprising:

providing a Traffic Inspector in signal communication with at least one client device for Internet browsing and with a web server having the online service residing therein;

providing a Traffic Analyzer in signal communication with the Traffic Inspector;

identifying, by the Traffic Inspector, each browsing session of the at least one client device on the online service;

extracting and identifying, by the Traffic Analyzer, one or more usernames when a user performs authentication to the online service by analyzing traffic exchanged between the at least one client device and the web server;

collecting, by the Traffic Inspector, first characteristic data concerning unique technical parameters, non-unique technical parameters, or unique and non-unique technical parameters and associating, by the Traffic Analyzer, the first characteristic data with respective identified one or more usernames;

storing the first characteristic data associated with each of the identified one or more usernames in a database associated with the Traffic Analyzer;

identifying, by the Traffic Analyzer, each anonymous web beacon generated by the at least one client device on the online service, wherein the anonymous web beacon indicates that the at least one client device has started a fraudulent browsing session on a phishing web server;

collecting, by the Traffic Inspector, second characteristic data concerning unique technical parameters, non-unique technical parameters, or unique and non-unique technical parameters and associating, by the Traffic Analyzer, the second characteristic data with the anonymous web beacon;

associating an identified username with the anonymous web beacon when the first characteristic data, concerning each of the identified one or more usernames, and the second characteristic data, concerning the anonymous web beacon, compared using a user prediction algorithm residing in the Traffic Analyzer, are at least in part identical or coincident;

entering each identified username associated with the anonymous web beacon, in which a situation involving a risk of credential theft has been detected after a phishing attack, in a watch list by analyzing, using a detection algorithm residing in the Traffic Analyzer, each anonymous web beacon associated with the identified one or more usernames; and

monitoring the browsing sessions in which the risk of credential theft has been detected associated with each identified username in the watch list when the user performs further authentication to the online service, and identifying an Account Take Over attack by the at least one client device and protecting access to the online service when a subsequent authenticated browsing session associated with the same username entered in the watch list is a next browsing session that occurs in a limited time interval after the browsing session relating to the anonymous web beacon.

20. The method of claim 19 , wherein the first characteristic data and the second characteristic data are at least in part identical or coincident when at least one of the unique technical parameters, non-unique technical parameters, or unique and non-unique technical parameters of the first characteristic data is identical to at least one of the unique technical parameters, non-unique technical parameters, or unique and non-unique technical parameters of the second characteristic data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2021
From: PASTORE, NICOLÒ; PARRINELLO, EMANUELE; GIANGREGORIO, CARMINE
To: CLEAFY SOCIETÀ PER AZIONI
Reel/Frame 055888/0573 →
Priority Claims (1)
IT 102020000006340 · Mar 25, 2020 · national
Continuity (1)
Related Publication 20210306369A1 · Sep 30, 2021
References Cited (71)
US 9838384B1 · Kane-Parry et al. · 2017 [cited by applicant]
US 10275613B1 · Olenoski et al. · 2019 [cited by applicant]
US 10346856B1 · Kohli et al. · 2019 [cited by applicant]
US 10496263B2 · So et al. · 2019 [cited by applicant]
US 11140158B1 · Adam · 2021 [cited by examiner]
US 11444962B2 · Crume · 2022 [cited by examiner]
US 11973768B2 · Pastore et al. · 2024 [cited by applicant]
US 20020046170A1 · Gvily · 2002 [cited by applicant]
US 20040059931A1 · Fulkerson, Jr. et al. · 2004 [cited by applicant]
US 20080244076A1 · Shah et al. · 2008 [cited by applicant]
US 20080255944A1 · Shah et al. · 2008 [cited by applicant]
US 20080263197A1 · Stephens · 2008 [cited by applicant]
US 20090089869A1 · Varghese · 2009 [cited by examiner]
US 20090168995A1 · Banga et al. · 2009 [cited by applicant]
US 20090327141A1 · Rabin et al. · 2009 [cited by applicant]
US 20100180775A1 · Kollep et al. · 2010 [cited by applicant]
US 20110022704A1 · Duan · 2011 [cited by examiner]
US 20120291129A1 · Shulman et al. · 2012 [cited by applicant]
US 20130055339A1 · Apostolescu et al. · 2013 [cited by applicant]
US 20130132508A1 · Lucash · 2013 [cited by examiner]
US 20130179982A1 · Bridges et al. · 2013 [cited by applicant]
US 20130183949A1 · Sulmar · 2013 [cited by applicant]
US 20140075014A1 · Chourey · 2014 [cited by applicant]
US 20140298469A1 · Marion et al. · 2014 [cited by applicant]
US 20140337513A1 · Amalapurapu et al. · 2014 [cited by applicant]
US 20150326595A1 · Liu et al. · 2015 [cited by applicant]
US 20150350243A1 · Call et al. · 2015 [cited by applicant]
US 20160034468A1 · Hart et al. · 2016 [cited by applicant]
US 20160057628A1 · Sewall et al. · 2016 [cited by applicant]
US 20160248788A1 · Saito et al. · 2016 [cited by applicant]
US 20170063885A1 · Wardman et al. · 2017 [cited by applicant]
US 20170063889A1 · Muddu · 2017 [cited by examiner]
US 20170289173A1 · Resch et al. · 2017 [cited by applicant]
US 20180033089A1 · Goldman · 2018 [cited by examiner]
US 20180152471A1 · Jakobsson · 2018 [cited by applicant]
US 20180212993A1 · Call · 2018 [cited by examiner]
US 20180217850A1 · Kolesnikov et al. · 2018 [cited by applicant]
US 20180309721A1 · Ashley · 2018 [cited by examiner]
US 20180316665A1 · Caldera et al. · 2018 [cited by applicant]
US 20190058719A1 · Kar et al. · 2019 [cited by applicant]
US 20190182214A1 · Liu et al. · 2019 [cited by applicant]
US 20190349351A1 · Verma · 2019 [cited by examiner]
US 20200137105A1 · Endler · 2020 [cited by applicant]
US 20200137580A1 · Yang · 2020 [cited by examiner]
US 20200153836A1 · Johnson et al. · 2020 [cited by applicant]
US 20200177623A1 · Call et al. · 2020 [cited by applicant]
US 20210021637A1 · Srivastava · 2021 [cited by examiner]
US 20210029137A1 · Wright et al. · 2021 [cited by applicant]
US 20210243207A1 · Crume · 2021 [cited by applicant]
US 20210258318A1 · Greene · 2021 [cited by applicant]
US 20210306355A1 · Pastore et al. · 2021 [cited by applicant]
US 20210306376A1 · Pastore et al. · 2021 [cited by applicant]
US 20210329451A1 · Jun et al. · 2021 [cited by applicant]
US 20220303293A1 · Pastore et al. · 2022 [cited by applicant]
US 20230034910A1 · Engelberg et al. · 2023 [cited by applicant]
EP 3021550A1 · 2016 [cited by applicant]
EP 3021551A1 · 2016 [cited by applicant]
EP 3885945B1 · 2023 [cited by applicant]
EP 4068125B1 · 2024 [cited by applicant]
WO 2012166669A2 · 2012 [cited by applicant]
U.S. Appl. No. 17/211,323, filed Mar. 24, 2021. [cited by applicant]
U.S. Appl. No. 17/211,577, filed Mar. 24, 2021. [cited by applicant]
U.S. Appl. No. 17/696,721, filed Mar. 16, 2022. [cited by applicant]
International Search Report and Written Opinion in corresponding Italian Application No. 102020000006340 mailed on Nov. 10, 2020, 13 pages. [cited by applicant]
Office Action mailed Jan. 19, 2023, in U.S. Appl. No. 17/211,323. [cited by applicant]
Office Action mailed May 1, 2023, in U.S. Appl. No. 17/211,577. [cited by applicant]
InnovationQ Plus—IP.com (2023). [cited by applicant]
Extended European Search Report mailed Aug. 13, 2021, corresponding to U.S. Appl. No. 17/211,646. [cited by applicant]
Final Office Action mailed Aug. 2, 2023, in U.S. Appl. No. 17/211,323. [cited by applicant]
Final Office Action mailed Nov. 21, 2023, in U.S. Appl. No. 17/211,577. [cited by applicant]
Office Action mailed Feb. 23, 2024, in U.S. Appl. No. 17/696,721. [cited by applicant]