IP Library Granted Patent US 12,477,002
Granted Patent B2
US 12,477,002 · App. 18/498,446 · Granted Nov 18, 2025

Credential-stuffing anomaly detection

Inventors: Michael Brantley Lewis (Nashville, NC); Jonathan Zeederberg (Clayton, NC); Jordan Berry (Charlotte, NC)
Assignee: Truist Bank
H04L63/1466G06F21/31G06F21/554H04L63/08H04L63/083H04L63/1416H04L63/1441H04L63/1491G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,477,002
App. No.
18/498,446
Granted
Nov 18, 2025
Kind
B2
Abstract

A computer-implemented method includes accessing data associated with log-in attempts of an interactive computing environment from attempt logs. The method further includes detecting a success percentage of log-in attempts by an entity. Additionally, the method includes identifying the entity as a credential-stuffing attacker based at least in part on the success percentage of log-in attempts by the entity. Moreover, the method includes restricting access to the interactive computing environment by the entity.

Claims (55)

1 . A computing device comprising:

a processor; and

a non-transitory computer-readable medium comprising instructions that are executable by the processor to cause the processor to:

access data associated with log-in attempts of an interactive computing environment from attempt logs;

identify known entities from the data associated with the log-in attempts;

remove data associated with the known entities from the data associated with the log-in attempts to generate a set of scrutinized log-in attempts of a first entity and a second entity;

detect a first success percentage of a first subset of the set of scrutinized log-in attempts by the first entity;

detect a second success percentage of a second subset of the set of scrutinized log-in attempts by the second entity;

identify the first entity as a credential-stuffing attacker based at least in part on the first success percentage of the first subset of the set of scrutinized log-in attempts by the first entity not exceeding a first threshold associated with a first geographical location of the first subset of the set of scrutinized log-in attempts;

identify the second entity as performing legitimate bot activities based at least in part on the second success percentage of the set of scrutinized log-in attempts by the second entity exceeding a second threshold associated with a second geographical location of the second subset of the set of scrutinized log-in attempts, wherein the first threshold is lower than the second threshold; and

restrict access to the interactive computing environment by the first entity.

2 . The computing device of claim 1 , wherein the non-transitory computer-readable medium further comprises instructions that are executable by the processor to cause the processor to:

allow access to the interactive computing environment by the second entity.

3 . The computing device of claim 1 , wherein identifying the known entities comprises comparing the log-in attempts against a known exclusions list to determine that the data associated with the known entities is excludable from the set of scrutinized log-in attempts.

4 . The computing device of claim 1 , wherein the non-transitory computer-readable medium further comprises instructions that are executable by the processor to cause the processor to:

determine a number of usernames attempted by the first entity in the set of scrutinized log-in attempts; and

determine the first geographical location of the first entity during the set of scrutinized log-in attempts, wherein identifying the first entity as the credential-stuffing attacker is further based on the number of usernames attempted and the first geographical location of the first entity.

5 . The computing device of claim 4 , wherein using the first success percentage of the first subset of the set of scrutinized log-in attempts of the first entity to identify the first entity as the credential-stuffing attacker comprises using a sliding-threshold success percentage, and wherein a threshold success percentage of the sliding-threshold success percentage is adjusted using the number of usernames attempted and the first geographical location of the first entity.

6 . The computing device of claim 1 , wherein using the first success percentage of the first subset of the set of scrutinized log-in attempts of the first entity to identify the first entity as the credential-stuffing attacker comprises determining that the first success percentage is 95 percent when the attempts originate in a first country or is 97 percent when the attempts originate in a second country.

7 . The computing device of claim 1 , wherein identifying the credential-stuffing attacker comprises identifying that the first entity is performing invalid bot traffic.

8 . A computer-implemented method comprising:

accessing, by a processor, data associated with log-in attempts of an interactive computing environment from attempt logs;

identifying, by the processor, known entities from the data associated with the log-in attempts;

removing, by the processor, data associated with the known entities from the data associated with the log-in attempts to generate a set of scrutinized log-in attempts of a first entity and a second entity;

detecting, by the processor, a first success percentage of a first subset of the set of scrutinized log-in attempts by the first entity;

detecting, by the processor, a second success percentage of a second subset of the set of scrutinized log-in attempts by the second entity;

identifying, by the processor, the first entity as a credential-stuffing attacker based at least in part on the first success percentage of the first subset of the set of log-in attempts by the first entity not exceeding a first threshold associated with a first geographical location of the first subset of the set of scrutinized log-in attempts;

identifying, by the processor, the second entity as performing legitimate bot activities based at least in part on the second success percentage of the set of scrutinized log-in attempts by the second entity exceeding a second threshold associated with a second geographical location of the second subset of the set of scrutinized log-in attempts, wherein the first threshold is lower than the second threshold; and

restricting, by the processor, access to the interactive computing environment by the first entity.

9 . The computer-implemented method of claim 8 , further comprising:

allowing, by the processor, access to the interactive computing environment by the second entity.

10 . The computer-implemented method of claim 8 , wherein identifying the known entities comprises comparing the log-in attempts against a known exclusions list to determine that the data associated with the known entities is excludable from the set of scrutinized log-in attempts.

11 . The computer-implemented method of claim 8 , further comprising:

determining, by the processor, a number of usernames attempted by the first entity in the first subset of the set of scrutinized log-in attempts; and

determining, by the processor, the geographical location of the first entity during the first subset of the set of scrutinized log-in attempts, wherein identifying the first entity as the credential-stuffing attacker is further based on the number of usernames attempted and the first geographical location of the first entity.

12 . The computer-implemented method of claim 11 , wherein using the first success percentage of the first subset of the set of scrutinized log-in attempts of the first entity to identify the first entity as the credential-stuffing attacker comprises using a sliding-threshold success percentage, and wherein a threshold success percentage of the sliding-threshold success percentage is adjusted using the number of usernames attempted and the first geographical location of the first entity.

13 . The computer-implemented method of claim 8 , wherein using the first success percentage of the first subset of the set of scrutinized log-in attempts of the first entity to identify the first entity as the credential-stuffing attacker comprises determining that the first success percentage is 95 percent when the attempts originate in a first country or is 97 percent when the attempts originate in a second country.

14 . The computer-implemented method of claim 8 , wherein identifying the credential-stuffing attacker comprises identifying that the first entity is performing invalid bot traffic.

15 . A non-transitory computer-readable medium comprising instructions that are executable by a processing device for causing the processing device to:

access data associated with log-in attempts of an interactive computing environment from attempt logs;

identify known entities from the data associated with the log-in attempts;

remove data associated with the known entities from the data associated with the log-in attempts to generate a set of scrutinized log-in attempts of a first entity and a second entity;

detect a first success percentage of a first subset of the set of scrutinized log-in attempts by the first entity;

detect a second success percentage of a second subset of the set of scrutinized log-in attempts by the second entity;

identify the first entity as a credential-stuffing attacker based at least in part on the first success percentage of the first subset of the set of scrutinized log-in attempts by the first entity not exceeding a first threshold associated with a first geographical location of the first subset of the set of scrutinized log-in attempts;

identify the second entity as performing legitimate bot activities based at least in part on the second success percentage of the set of scrutinized log-in attempts by the second entity exceeding a second threshold associated with a second geographical location of the second subset of the set of scrutinized log-in attempts, wherein the first threshold is lower than the second threshold; and

restrict access to the interactive computing environment by the first entity.

16 . The non-transitory computer-readable medium of claim 15 , further comprising instructions that are executable by the processing device to cause the processing device to:

allow access to the interactive computing environment by the second entity.

17 . The non-transitory computer-readable medium of claim 15 , wherein identifying the known entities comprises comparing the log-in attempts against a known exclusions list to determine that the data associated with the known entities is excludable from the set of scrutinized log-in attempts.

18 . The non-transitory computer-readable medium of claim 15 , further comprising instructions that are executable by the processing device to:

determine a number of usernames attempted by the first entity in the first subset of the set of scrutinized log-in attempts; and

determine the geographical location of the first entity during the first subset of the set of scrutinized log-in attempts, wherein identifying the first entity as the credential-stuffing attacker is further based on the number of usernames attempted and the first geographical location of the first entity.

19 . The non-transitory computer-readable medium of claim 18 , wherein using the first success percentage of the first subset of the set of scrutinized log-in attempts of the first entity to identify the first entity as the credential-stuffing attacker comprises using a sliding-threshold success percentage, and wherein a threshold success percentage of the sliding-threshold success percentage is adjusted using the number of usernames attempted and the first geographical location of the first entity.

20 . The non-transitory computer-readable medium of claim 15 , wherein identifying the credential-stuffing attacker comprises identifying that the first entity is performing invalid bot traffic.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2024
From: LEWIS, MICHAEL BRANTLEY; ZEEDERBERG, JONATHAN; BERRY, JORDAN
To: TRUIST BANK
Reel/Frame 068131/0401 →
Continuity (2)
Continuation 18498161 · Oct 31, 2023
Related Publication 20250139239A1 · May 1, 2025
References Cited (11)
US 10505991B1 · Yang · 2019 [cited by examiner]
US 11356472B1 · Maiorana · 2022 [cited by examiner]
US 11855989B1 · Hall · 2023 [cited by examiner]
US 20170134362A1 · Randall · 2017 [cited by examiner]
US 20200112585A1 · Keohane · 2020 [cited by examiner]
US 20200213334A1 · Kutner · 2020 [cited by examiner]
US 20210099451A1 · Will · 2021 [cited by examiner]
US 20220263834A1 · Cohen · 2022 [cited by examiner]
US 20230078849A1 · Seletskiy · 2023 [cited by examiner]
US 20230179612A1 · Inon · 2023 [cited by examiner]
US 20240073213A1 · Hadler · 2024 [cited by examiner]
Cited By (1)
US 12,712,741