System and methods for detection of fraudulent online transactions

US9363286B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9363286-B2
Application numberUS-201414264501-A
CountryUS
Kind codeB2
Filing dateApr 29, 2014
Priority dateMar 20, 2014
Publication dateJun 7, 2016
Grant dateJun 7, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Disclosed are some aspects of systems and methods for providing security for online transactions. An example method includes determining, at a security service, that an online transaction related to a payment service has been initiated at a computer by a user of the computer, collecting first information from the computer and second information from the payment service, and determining, based on the collected information, whether the online transaction is suspicious These aspects further include, when the online transaction is determined to be suspicious, determining whether a malicious program can be identified on the computer and when the malicious program is identified, performing corresponding remedial actions with respect to the detected malicious program.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for providing security for online transactions, comprising: determining, by a computer processor, that an online transaction related to a payment service has been initiated by a user computer; collecting, by the computer processor, first information from the user computer and second information from the payment service, where the first information includes: (1) capabilities of an antivirus program installed on the user computer based on at least a current version of the antivirus program, and (2) a status of the antivirus program indicating at least a date of a last scan of the user computer by the antivirus program and an identification of prior malicious programs found by the last scan; determining, by the computer processor, based on both the first information from the user computer and the second information from the payment service, whether the online transaction is suspicious and processing the online transaction when the online transaction is not determined to be suspicious, including a determination that no prior malicious programs were found by the last scan of the user computer; when the computer processor determines that the online transaction is suspicious, analyzing, by the computer processor, the capabilities and the status of the antivirus program to determine whether the antivirus program is currently configured to detect one or more malicious programs on the user computer; when the computer processor determines that the antivirus program is currently configured to detect the one or more malicious programs and the one or more malicious programs is detected by the antivirus program, performing, by the computer processor, one or more remedial actions with respect to the detected one or more malicious programs, including cancelling the online transaction; when the computer processor determines that the antivirus program is not currently configured to detect the one or more malicious programs, performing additional actions to detect the one or more malicious programs on the user computer, the additional actions including downloading a latest version of the antivirus program to perform an updated scan of the user computer and rebooting the user computer with checks for rootkits and bootkits; if the one or more malicious programs is detected in response to the additional actions, performing, by the computer processor, one or more remedial actions of the detected one or more malicious programs; and cancelling the online transaction if the additional actions do not identify the one or more malicious programs. 2. The method of claim 1 , wherein the online transaction is determined to be initiated when one or more of the following events occur: the user starts a browser on the user computer, the user goes on a website associated with the online transaction, the user enters a user login and password at the website, and the user directly requests provision of security for the online transaction. 3. The method of claim 1 , wherein the first information includes one or more of: an antivirus database version of the user computer, events related to detection of malicious programs at the computer in a period of time, antivirus components being used at the user computer, data input modules and entry patterns used by the user of the user computer, a detection log of an anti-phishing module at the user computer, an identifier of the user computer, processes started at the user computer, file operations at the user computer, registry operations at the user computer, a list of network connections of the user computer, a list of devices connected to the user computer, vulnerabilities at the user computer, and installed updates for the operating system or applications of the user computer. 4. The method of claim 1 , wherein the second information includes one or more of: information on the online transaction, information on the browser of the user computer, an identifier of the user computer, structure information of a webpage seen by the user of the user computer, and data input modules and entry patterns used by the user of the user computer. 5. The method of claim 1 , wherein the online transaction is determined to be suspicious further based on third information obtained from a network provider and fourth information obtained from a security service. 6. The method of claim 5 , wherein the fourth information includes one or more of: transaction information related to the online transaction, a history of transactions related to an account of the user of the user computer, and possible risks associated with the online transaction. 7. The method of claim 5 , wherein the third information includes a network traffic route from the user computer to the payment service. 8. The method of claim 1 , wherein the one or more remedial actions include one or more of: performing a rollback of an operating system of the user computer to a preceding state from a backup copy; removing the one or more malicious programs and performing a rollback of the changes made by the one or more malicious programs; warning the user of the user computer as to a possible substitution of the online transaction by a fraudulent transaction; and notifying the payment service as to transactions from the user of the user computer or from the user computer as being possibly suspicious. 9. A system for providing security for online transactions, comprising: a computer processor configured to: determine that an online transaction related to a payment service has been initiated by a user computer; collect first information from the user computer and second information from the payment service, where the first information includes: (1) capabilities of an antivirus program installed on the user computer based on at least a current version of the antivirus program, and (2) a status of the antivirus program indicating at least a date of a last scan of the user computer by the antivirus program and an identification of prior malicious programs found by the last scan; determine, based on both the first information from the user computer and the second information from the payment service, whether the online transaction is suspicious and process the online transaction when the online transaction is not determined to be suspicious, including a determination that no prior malicious programs were found by the last scan of the user computer; when the computer processor determines that the online transaction is suspicious, analyze the capabilities and the status of the antivirus program to determine whether the antivirus program is currently configured to detect one or more malicious programs on the user computer; when the computer processor determines that the antivirus program is currently configured to detect the one or more malicious programs and the one or more malicious programs is detected by the antivirus program, perform one or more remedial actions with respect to the detected one or more malicious programs, including cancelling the online transaction; when the computer processor determines that the antivirus program is not currently configured to detect the one or more malicious programs, perform additional actions to detect the one or more malicious programs on the user computer, the additional actions including downloading a latest version of the antivirus program to perform an updated scan of the user computer and rebooting the user computer with checks for rootkits and bootkits; if the one or more malicious programs is detected in response to the additional actions, perform one or more remedial actions of the detected one or more malicious programs; and cancel the online transaction

Assignees

Inventors

Classifications

  • Passive attacks, e.g. eavesdropping or listening without modification of the traffic monitored · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • G06F21/562Primary

    Static detection · CPC title

  • involving fraud or risk level assessment in transaction processing · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9363286B2 cover?
Disclosed are some aspects of systems and methods for providing security for online transactions. An example method includes determining, at a security service, that an online transaction related to a payment service has been initiated at a computer by a user of the computer, collecting first information from the computer and second information from the payment service, and determining, based o…
Who is the assignee on this patent?
Kaspersky Lab Zao, AO Kaspersky Lab
What technology area does this patent fall under?
Primary CPC classification H04L63/1475. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 07 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).