Systems and methods for performing network counter measures

US9237167B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9237167-B1
Application numberUS-18387208-A
CountryUS
Kind codeB1
Filing dateJul 31, 2008
Priority dateJan 18, 2008
Publication dateJan 12, 2016
Grant dateJan 12, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method and system for detecting fraud in an electronic session performed over a network, the session including communications between a purported customer and a bank operating system, the communications from the customer including headers. The method including inputting the headers, including header attributes, from the purported customer during the session; comparing the header attributes from different communications during the session; determining that the comparison of the header attributes are irregular; and flagging, based on the determining that the comparison of the header attributes are irregular, the session as suspect.

First claim

Opening claim text (preview).

What is claimed is: 1. A method that detects fraud in an electronic communication session performed over a network, the session including data transmissions between a purported customer and a bank operating system, the data transmissions from the purported customer including headers from, and generated by, a purported customer user device of the purported customer, the method performed by at least one computer processor of the bank operating system, the method including: with a first communication from the purported customer user device during the session, inputting a first header by the computer processor, the first header including first header attributes; with a second communication from the purported customer user device during the session, inputting a second header by the computer processor, the second header including second header attributes; comparing the first header attributes with the second header attributes from the different data transmissions with the purported customer user device of the purported customer during the same session, wherein the comparing of header attributes from different data transmissions during the session includes: comparing the first header that is associated with the data transmission from the user device of the purported customer at login with the second header that is associated with a later data transmission from the user device of the purported customer in the same session; determining that the first header attributes are different from the second header attributes; and flagging, based on the determining that the header attributes are different, the session as suspect of fraud; and outputting a communication indicative of such flagging. 2. The method of claim 1 , wherein the headers are in the form of https: headers. 3. The method of claim 1 , wherein the network is the Internet. 4. The method of claim 1 , wherein the session includes the purported customer using a web page of the bank operating system. 5. The method of claim 1 , wherein the comparing header attributes from different data transmissions during the session includes: comparing multiple headers from the purported customer user device input during the session. 6. The method of claim 5 , wherein headers of sequential data transmissions are compared during the session. 7. The method of claim 6 , wherein time attributes of the sequential headers are compared. 8. The method of claim 6 , wherein headers of sequential data transmissions are compared so as to generate an observed pace of the session, the method including comparing the observed pace with known pace information. 9. The method of claim 8 , wherein the known pace information was previously secured based on sessions with the purported customer, who was at such time legitimized. 10. The method of claim 8 , wherein the known pace information was previously secured based on sessions with other customers. 11. The method of claim 8 , wherein the known pace information was previously secured based on capabilities of the legitimate technologies involved and human traits. 12. The method of claim 1 , further including comparing header between communications of different customers to detect fraud. 13. A computer processing system that detects fraud in an electronic session performed over a network, the session including communications between a purported customer and a bank operating system, the communications from the purported customer including headers from, and generated by, a purported customer user device of the purported customer, the system comprising: a header processor, that: with a first communication from the purported customer user device during the session, inputs a first header that includes first header attributes, the first header attributes comprising a first device signature of the purported customer user device; with a second communication from the purported customer user device during the session, inputs a second header that includes second header attributes, the second header attributes comprising a second device signature of the purported customer user device; compares the first device signature with the second device signature from the different communications with the purported customer user device of the purported customer during the session; determines that the comparison of the first device signature with the second device signature is irregular; and flags, based on the determining that the device signatures are irregular, the session as suspect of fraud; and a flagged session processor that performs processing on the flagged session so as to investigate fraud; and wherein the comparison of the device signatures from different communications with the user device of the purported customer during the session includes: comparing the first header that is associated with a communication from the user device of the purported customer at login with the second header that is associated with a later communication from the user device of the purported customer in the same session. 14. The computer processing system of claim 13 , wherein the headers are in the form of https: headers. 15. The computer processing system of claim 13 , wherein the flagged session processor terminates the session with the customer based on the flagging of the session. 16. The computer processing system of claim 13 , wherein the flagged session processor performs an out of band challenge based on the flagging of the session. 17. A non-transitory computer readable medium that detects fraud in an electronic session performed over a network, the session including communications between a purported customer and a bank operating system, the communications from the purported customer including headers from a purported customer user device of the purported customer, the computer readable medium comprising: a first computer readable medium portion that when executed causes at least one processor to: with a first communication from the purported customer user device during the session, input a first header that includes first header attributes, the first header attributes comprising a first device signature of the purported customer user device; with a second communication from the purported customer user device during the session, input a second header that includes second header attributes, the second header attributes comprising a second device signature of the purported customer user device; compare the first device signature with the second device signature from the different communications with the purported customer user device of the purported customer during the session; determine that the comparison of the first device signature with the second device signature is irregular; and flag, based on the determining that the device signatures are irregular, the session as suspect of fraud; and a second computer readable medium portion that when executed cause the at least one processor to perform processing on the flagged session so as to investigate fraud; and wherein the comparison of the device signatures from different communications with the user device of the purported customer during the session includes: comparing the first header associated with a communication from the user device of the purported customer at login with the second header associated with a later communication from the user device of the purported customer in the same session. 18. A method that detects fraud in an electronic session performed over a network, the session including different communications between a pu

Assignees

Inventors

Classifications

  • Session management (for real-time applications in data packet communications networks H04L65/1066) · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks · CPC title

  • Electricity · mapped topic

  • Tracking the activity of the user (network monitoring arrangements H04L43/00; recording of computer activity G06F11/34) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9237167B1 cover?
A method and system for detecting fraud in an electronic session performed over a network, the session including communications between a purported customer and a bank operating system, the communications from the customer including headers. The method including inputting the headers, including header attributes, from the purported customer during the session; comparing the header attributes fr…
Who is the assignee on this patent?
Manion Amanda Marie, Szwalbenest Stanley A, Jpmorgan Chase Bank Na
What technology area does this patent fall under?
Primary CPC classification H04L63/1466. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 12 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).