Session slicing of mirrored packets
US-12184680-B2 · Dec 31, 2024 · US
US9237167B1 · US · B1
| Field | Value |
|---|---|
| Publication number | US-9237167-B1 |
| Application number | US-18387208-A |
| Country | US |
| Kind code | B1 |
| Filing date | Jul 31, 2008 |
| Priority date | Jan 18, 2008 |
| Publication date | Jan 12, 2016 |
| Grant date | Jan 12, 2016 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method and system for detecting fraud in an electronic session performed over a network, the session including communications between a purported customer and a bank operating system, the communications from the customer including headers. The method including inputting the headers, including header attributes, from the purported customer during the session; comparing the header attributes from different communications during the session; determining that the comparison of the header attributes are irregular; and flagging, based on the determining that the comparison of the header attributes are irregular, the session as suspect.
Opening claim text (preview).
What is claimed is: 1. A method that detects fraud in an electronic communication session performed over a network, the session including data transmissions between a purported customer and a bank operating system, the data transmissions from the purported customer including headers from, and generated by, a purported customer user device of the purported customer, the method performed by at least one computer processor of the bank operating system, the method including: with a first communication from the purported customer user device during the session, inputting a first header by the computer processor, the first header including first header attributes; with a second communication from the purported customer user device during the session, inputting a second header by the computer processor, the second header including second header attributes; comparing the first header attributes with the second header attributes from the different data transmissions with the purported customer user device of the purported customer during the same session, wherein the comparing of header attributes from different data transmissions during the session includes: comparing the first header that is associated with the data transmission from the user device of the purported customer at login with the second header that is associated with a later data transmission from the user device of the purported customer in the same session; determining that the first header attributes are different from the second header attributes; and flagging, based on the determining that the header attributes are different, the session as suspect of fraud; and outputting a communication indicative of such flagging. 2. The method of claim 1 , wherein the headers are in the form of https: headers. 3. The method of claim 1 , wherein the network is the Internet. 4. The method of claim 1 , wherein the session includes the purported customer using a web page of the bank operating system. 5. The method of claim 1 , wherein the comparing header attributes from different data transmissions during the session includes: comparing multiple headers from the purported customer user device input during the session. 6. The method of claim 5 , wherein headers of sequential data transmissions are compared during the session. 7. The method of claim 6 , wherein time attributes of the sequential headers are compared. 8. The method of claim 6 , wherein headers of sequential data transmissions are compared so as to generate an observed pace of the session, the method including comparing the observed pace with known pace information. 9. The method of claim 8 , wherein the known pace information was previously secured based on sessions with the purported customer, who was at such time legitimized. 10. The method of claim 8 , wherein the known pace information was previously secured based on sessions with other customers. 11. The method of claim 8 , wherein the known pace information was previously secured based on capabilities of the legitimate technologies involved and human traits. 12. The method of claim 1 , further including comparing header between communications of different customers to detect fraud. 13. A computer processing system that detects fraud in an electronic session performed over a network, the session including communications between a purported customer and a bank operating system, the communications from the purported customer including headers from, and generated by, a purported customer user device of the purported customer, the system comprising: a header processor, that: with a first communication from the purported customer user device during the session, inputs a first header that includes first header attributes, the first header attributes comprising a first device signature of the purported customer user device; with a second communication from the purported customer user device during the session, inputs a second header that includes second header attributes, the second header attributes comprising a second device signature of the purported customer user device; compares the first device signature with the second device signature from the different communications with the purported customer user device of the purported customer during the session; determines that the comparison of the first device signature with the second device signature is irregular; and flags, based on the determining that the device signatures are irregular, the session as suspect of fraud; and a flagged session processor that performs processing on the flagged session so as to investigate fraud; and wherein the comparison of the device signatures from different communications with the user device of the purported customer during the session includes: comparing the first header that is associated with a communication from the user device of the purported customer at login with the second header that is associated with a later communication from the user device of the purported customer in the same session. 14. The computer processing system of claim 13 , wherein the headers are in the form of https: headers. 15. The computer processing system of claim 13 , wherein the flagged session processor terminates the session with the customer based on the flagging of the session. 16. The computer processing system of claim 13 , wherein the flagged session processor performs an out of band challenge based on the flagging of the session. 17. A non-transitory computer readable medium that detects fraud in an electronic session performed over a network, the session including communications between a purported customer and a bank operating system, the communications from the purported customer including headers from a purported customer user device of the purported customer, the computer readable medium comprising: a first computer readable medium portion that when executed causes at least one processor to: with a first communication from the purported customer user device during the session, input a first header that includes first header attributes, the first header attributes comprising a first device signature of the purported customer user device; with a second communication from the purported customer user device during the session, input a second header that includes second header attributes, the second header attributes comprising a second device signature of the purported customer user device; compare the first device signature with the second device signature from the different communications with the purported customer user device of the purported customer during the session; determine that the comparison of the first device signature with the second device signature is irregular; and flag, based on the determining that the device signatures are irregular, the session as suspect of fraud; and a second computer readable medium portion that when executed cause the at least one processor to perform processing on the flagged session so as to investigate fraud; and wherein the comparison of the device signatures from different communications with the user device of the purported customer during the session includes: comparing the first header associated with a communication from the user device of the purported customer at login with the second header associated with a later communication from the user device of the purported customer in the same session. 18. A method that detects fraud in an electronic session performed over a network, the session including different communications between a pu
Session management (for real-time applications in data packet communications networks H04L65/1066) · CPC title
using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title
Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks · CPC title
Electricity · mapped topic
Tracking the activity of the user (network monitoring arrangements H04L43/00; recording of computer activity G06F11/34) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.