Dynamic record identification and analysis computer system with event monitoring components

US9973508B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9973508-B2
Application numberUS-201615041802-A
CountryUS
Kind codeB2
Filing dateFeb 11, 2016
Priority dateFeb 11, 2016
Publication dateMay 15, 2018
Grant dateMay 15, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Aspects of the disclosure relate to deploying and utilizing a dynamic record identification and analysis computer system with event monitoring components. In some embodiments, a computing platform may receive, from a contact feed generation computer system, one or more contact feeds comprising contact data identifying one or more contacts associated with one or more user accounts. The computing platform may analyze the one or more contact feeds to identify a first subset of user accounts of the one or more user accounts having one or more attributes associated with one or more predetermined account security concern characteristics. Subsequently, the computing platform may add the first subset of user accounts of the one or more user accounts to an alert table maintained by the computing platform, and may send, to an analyst computer system, alert table listing information identifying contents of the alert table maintained by the computing platform.

First claim

Opening claim text (preview).

What is claimed is: 1. A computing platform comprising: at least one processor; a communication interface communicatively coupled to the at least one processor; and memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: receive, via the communication interface, and from a contact feed generation computer system, one or more contact feeds comprising contact data identifying one or more contacts associated with one or more user accounts; based on receiving the one or more contact feeds comprising the contact data identifying the one or more contacts associated with the one or more user accounts from the contact feed generation computer system, analyze the one or more contact feeds to identify a first subset of user accounts of the one or more user accounts, the first subset of user accounts having one or more attributes associated with one or more predetermined account security concern characteristics; based on identifying the first subset of user accounts of the one or more user accounts, add the first subset of user accounts of the one or more user accounts to an alert table maintained by the computing platform; and based on adding the first subset of user accounts of the one or more user accounts to the alert table maintained by the computing platform, send, via the communication interface, to an analyst computer system, alert table listing information identifying contents of the alert table maintained by the computing platform, wherein sending the alert table listing information identifying the contents of the alert table maintained by the computing platform to the analyst computer system causes the analyst computer system to display a graphical user interface based on the alert table listing information, wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: prior to receiving the one or more contact feeds comprising the contact data identifying the one or more contacts associated with the one or more user accounts from the contact feed generation computer system: receive, via the communication interface, and from an account reconnaissance identification system, blacklist data identifying one or more suspicious telephone numbers associated with one or more account reconnaissance activities; and based on receiving the blacklist data identifying the one or more suspicious telephone numbers associated with the one or more account reconnaissance activities, update one or more local blacklist tables to include the blacklist data identifying the one or more suspicious telephone numbers associated with the one or more account reconnaissance activities, and wherein the account reconnaissance identification system is configured to monitor and analyze call data received from one or more interactive voice response (IVR) systems and one or more call center systems to identify the one or more suspicious telephone numbers associated with the one or more account reconnaissance activities. 2. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: based on adding the first subset of user accounts of the one or more user accounts to the alert table maintained by the computing platform, update one or more flags in the alert table maintained by the computing platform, the one or more flags identifying one or more reasons for adding the first subset of user accounts of the one or more user accounts to the alert table maintained by the computing platform. 3. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: based on adding the first subset of user accounts of the one or more user accounts to the alert table maintained by the computing platform, calculate a temporally dynamic alert score for each user account of the first subset of user accounts added to the alert table. 4. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: receive, via the communication interface, one or more event feeds comprising event data identifying one or more events associated with the one or more user accounts; based on receiving the one or more event feeds comprising the event data identifying the one or more events associated with the one or more user accounts, evaluate the one or more events associated with the one or more user accounts based on one or more temporally dynamic alert scores corresponding to the one or more user accounts; based on evaluating the one or more events associated with the one or more user accounts, generate at least one alert for at least one user account, the at least one alert identifying at least one suspicious event associated with the at least one user account; and based on generating the at least one alert for the at least one user account, perform one or more actions on the at least one user account, the one or more actions performed on the at least one user account being responsive to the at least one suspicious event associated with the at least one user account. 5. The computing platform of claim 4 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: based on generating the at least one alert for the at least one user account, send, via the communication interface, to the analyst computer system, event alert information identifying the at least one alert generated for the at least one user account. 6. The computing platform of claim 1 , wherein the contact data comprises information indicating that a first user account associated with a first user was contacted by a first telephone number, and wherein the contact data comprises information indicating that a second user account associated with a second user was contacted by a second telephone number. 7. The computing platform of claim 1 , wherein the contact data comprises information indicating that a first user account associated with a first user was contacted by a first mobile malware application. 8. The computing platform of claim 1 , wherein the contact data comprises information indicating that a first user account associated with a first user was contacted by a first suspicious network address. 9. The computing platform of claim 1 , wherein the contact data comprises information indicating that a first user account associated with a first user was contacted by a first suspicious cookie. 10. The computing platform of claim 1 , wherein the contact data comprises information indicating that a first user account associated with a first user was contacted by a first suspicious email address. 11. The computing platform of claim 1 , wherein the contact data comprises information indicating that a first user account associated with a first user was contacted by a first suspicious text chat session. 12. The computing platform of claim 1 , wherein the first subset of user accounts have at least one attribute indicative of previous unauthorized activity. 13. The computing platform of claim 1 , wherein the first subset of user accounts have at least one attribute indicative of at least one previous account takeover event. 14. A method comprising: at a computing platform comprising at least one processor, memory, an

Assignees

Inventors

Classifications

  • Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists · CPC title

  • H04L63/101Primary

    Access control lists [ACL] · CPC title

  • Event detection, e.g. attack signature detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9973508B2 cover?
Aspects of the disclosure relate to deploying and utilizing a dynamic record identification and analysis computer system with event monitoring components. In some embodiments, a computing platform may receive, from a contact feed generation computer system, one or more contact feeds comprising contact data identifying one or more contacts associated with one or more user accounts. The computing…
Who is the assignee on this patent?
Bank Of America
What technology area does this patent fall under?
Primary CPC classification H04L63/101. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 15 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).