Network security path identification and validation
US-12170668-B2 · Dec 17, 2024 · US
US9973508B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9973508-B2 |
| Application number | US-201615041802-A |
| Country | US |
| Kind code | B2 |
| Filing date | Feb 11, 2016 |
| Priority date | Feb 11, 2016 |
| Publication date | May 15, 2018 |
| Grant date | May 15, 2018 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Aspects of the disclosure relate to deploying and utilizing a dynamic record identification and analysis computer system with event monitoring components. In some embodiments, a computing platform may receive, from a contact feed generation computer system, one or more contact feeds comprising contact data identifying one or more contacts associated with one or more user accounts. The computing platform may analyze the one or more contact feeds to identify a first subset of user accounts of the one or more user accounts having one or more attributes associated with one or more predetermined account security concern characteristics. Subsequently, the computing platform may add the first subset of user accounts of the one or more user accounts to an alert table maintained by the computing platform, and may send, to an analyst computer system, alert table listing information identifying contents of the alert table maintained by the computing platform.
Opening claim text (preview).
What is claimed is: 1. A computing platform comprising: at least one processor; a communication interface communicatively coupled to the at least one processor; and memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: receive, via the communication interface, and from a contact feed generation computer system, one or more contact feeds comprising contact data identifying one or more contacts associated with one or more user accounts; based on receiving the one or more contact feeds comprising the contact data identifying the one or more contacts associated with the one or more user accounts from the contact feed generation computer system, analyze the one or more contact feeds to identify a first subset of user accounts of the one or more user accounts, the first subset of user accounts having one or more attributes associated with one or more predetermined account security concern characteristics; based on identifying the first subset of user accounts of the one or more user accounts, add the first subset of user accounts of the one or more user accounts to an alert table maintained by the computing platform; and based on adding the first subset of user accounts of the one or more user accounts to the alert table maintained by the computing platform, send, via the communication interface, to an analyst computer system, alert table listing information identifying contents of the alert table maintained by the computing platform, wherein sending the alert table listing information identifying the contents of the alert table maintained by the computing platform to the analyst computer system causes the analyst computer system to display a graphical user interface based on the alert table listing information, wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: prior to receiving the one or more contact feeds comprising the contact data identifying the one or more contacts associated with the one or more user accounts from the contact feed generation computer system: receive, via the communication interface, and from an account reconnaissance identification system, blacklist data identifying one or more suspicious telephone numbers associated with one or more account reconnaissance activities; and based on receiving the blacklist data identifying the one or more suspicious telephone numbers associated with the one or more account reconnaissance activities, update one or more local blacklist tables to include the blacklist data identifying the one or more suspicious telephone numbers associated with the one or more account reconnaissance activities, and wherein the account reconnaissance identification system is configured to monitor and analyze call data received from one or more interactive voice response (IVR) systems and one or more call center systems to identify the one or more suspicious telephone numbers associated with the one or more account reconnaissance activities. 2. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: based on adding the first subset of user accounts of the one or more user accounts to the alert table maintained by the computing platform, update one or more flags in the alert table maintained by the computing platform, the one or more flags identifying one or more reasons for adding the first subset of user accounts of the one or more user accounts to the alert table maintained by the computing platform. 3. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: based on adding the first subset of user accounts of the one or more user accounts to the alert table maintained by the computing platform, calculate a temporally dynamic alert score for each user account of the first subset of user accounts added to the alert table. 4. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: receive, via the communication interface, one or more event feeds comprising event data identifying one or more events associated with the one or more user accounts; based on receiving the one or more event feeds comprising the event data identifying the one or more events associated with the one or more user accounts, evaluate the one or more events associated with the one or more user accounts based on one or more temporally dynamic alert scores corresponding to the one or more user accounts; based on evaluating the one or more events associated with the one or more user accounts, generate at least one alert for at least one user account, the at least one alert identifying at least one suspicious event associated with the at least one user account; and based on generating the at least one alert for the at least one user account, perform one or more actions on the at least one user account, the one or more actions performed on the at least one user account being responsive to the at least one suspicious event associated with the at least one user account. 5. The computing platform of claim 4 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: based on generating the at least one alert for the at least one user account, send, via the communication interface, to the analyst computer system, event alert information identifying the at least one alert generated for the at least one user account. 6. The computing platform of claim 1 , wherein the contact data comprises information indicating that a first user account associated with a first user was contacted by a first telephone number, and wherein the contact data comprises information indicating that a second user account associated with a second user was contacted by a second telephone number. 7. The computing platform of claim 1 , wherein the contact data comprises information indicating that a first user account associated with a first user was contacted by a first mobile malware application. 8. The computing platform of claim 1 , wherein the contact data comprises information indicating that a first user account associated with a first user was contacted by a first suspicious network address. 9. The computing platform of claim 1 , wherein the contact data comprises information indicating that a first user account associated with a first user was contacted by a first suspicious cookie. 10. The computing platform of claim 1 , wherein the contact data comprises information indicating that a first user account associated with a first user was contacted by a first suspicious email address. 11. The computing platform of claim 1 , wherein the contact data comprises information indicating that a first user account associated with a first user was contacted by a first suspicious text chat session. 12. The computing platform of claim 1 , wherein the first subset of user accounts have at least one attribute indicative of previous unauthorized activity. 13. The computing platform of claim 1 , wherein the first subset of user accounts have at least one attribute indicative of at least one previous account takeover event. 14. A method comprising: at a computing platform comprising at least one processor, memory, an
Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists · CPC title
Access control lists [ACL] · CPC title
Event detection, e.g. attack signature detection · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.