US2014195368A1PendingUtilityA1

Detecting a suspicious transaction within a network-based facility

Assignee: EBAY INCPriority: Nov 15, 2000Filed: Jan 13, 2014Published: Jul 10, 2014
Est. expiryNov 15, 2020(expired)· nominal 20-yr term from priority
G06Q 30/08G06Q 20/382G06Q 40/04
61
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods and associated computer-readable media to detect fraudulent activities made over a network-based facility using a machine are disclosed. Responsive to a first event with respect to the network-based facility and initiated either under a first user identity or a first set of user transaction preferences from the machine which is coupled to the network-based facility via a network, the method causes a first identifier associated with either the first user identity or the first set of user transaction preferences to be stored on the machine. Responsive to a second event initiated under either a second user identity or a second set of user transaction preferences, detecting a potentially fraudulent activity occurs by detecting a lack of correspondence between the first identifier stored on the machine and a second identifier associated with either the second user identity or the second set of user transaction preferences.

Claims

exact text as granted — not AI-modified
1 . A method of detecting fraudulent activity, the method comprising:
 causing a first identifier associated with a first user identity to be stored on a machine responsive to a first event with respect to a network-based facility and initiated under the first user identity from the machine that is coupled to the network-based facility via a network; and   detecting, one or more processors, a potentially fraudulent activity by detecting a lack of correspondence between the first identifier stored on the machine and a second identifier associated with a second user identity responsive to a second event with respect to the network-based facility and initiated under the second user identity from the machine.   
     
     
         2 . The method of  claim 1 , further comprising storing the first identifier in a shill cookie on the machine. 
     
     
         3 . The method of  claim 2 , further comprising generating the second identifier associated with the second user identity and storing the second user identifier in the shill cookie on the machine. 
     
     
         4 . The method of  claim 2 , further comprising encoding the shill cookie. 
     
     
         5 . The method of  claim 2 , further comprising encrypting the shill cookie. 
     
     
         6 . The method of  claim 1 , further comprising generating and storing a new shill cookie on the machine or adding to an existing shill cookie stored on the machine each time one of a plurality of triggering events occurs. 
     
     
         7 . The method of  claim 3 , wherein the plurality of triggering events includes at least one type of event selected from a group of events including registering with the network-based facility, communicating with the network-based facility to offer a good or service for sale, communicating with the network-based facility to purchase a good or service, communicating with the network-based facility to present feedback regarding a transaction, and updating a profile maintained by the network-based facility. 
     
     
         8 . The method of  claim 1 , wherein the network-based facility is a network-based transaction facility. 
     
     
         9 . The method of  claim 1 , wherein the network-based facility is a network-based auction facility. 
     
     
         10 . The method of  claim 1 , further comprising recording a set of transaction preferences for the first user identity. 
     
     
         11 . The method of  claim 10 , wherein the set of transaction preferences include a plurality of items selected from items including credit card numbers, bidding histories, payment methods, and shipping addresses. 
     
     
         12 . The method of  claim 1 , further comprising recording the potentially fraudulent activity at the network-based facility responsive to the detection of the lack of correspondence between the first identifier and the second identifier. 
     
     
         13 . The method of  claim 1 , further comprising:
 generating a potential fraudulent activities table having a fraudulent activity field, a cookie identifier field, a user identifier field, and a frequency field;   recording each of a plurality of potentially fraudulent activities and corresponding information into the potential fraudulent activities table;   updating the potential fraudulent activities table on at least a periodic basis; and   providing an updated report of the potential fraudulent activities table to an investigation team.   
     
     
         14 . The method of  claim 1 , further comprising providing a priority ranking system having a low priority for a low potential fraudulent activity frequency, a medium priority for a medium potential fraudulent activity frequency, and a high priority for a high potential fraudulent activity frequency. 
     
     
         15 . A method of detecting fraudulent activity, the method comprising:
 generating a first identifier associated with a first set of transaction preferences, the first identifier to be stored on a first client machine, the first identifier being generated responsive to at least one of a plurality of triggering events with respect to a network-based facility;   generating a second identifier associated with a second set of transaction preferences, the second identifier to be stored with either the first identifier on the first client machine or on a second client machine, the second identifier being generated responsive to at least one of the plurality of triggering events with respect to the network-based facility;   receiving information stored in one or both of the first identifier and the second identifier at the network-based facility; and   detecting, using one or more hardware processors, potentially fraudulent activity by detecting a lack of correspondence between the first set of transaction preferences and the second set of transaction preferences.   
     
     
         16 . The method of  claim 15 , wherein the plurality of triggering events includes at least one type of event selected from a group of events including registering with the network-based facility, communicating with the network-based facility to offer a good or service for sale, communicating with the network-based facility to purchase a good or service, communicating with the network-based facility to present feedback regarding a transaction, and updating a profile maintained by the network-based facility. 
     
     
         17 . The method of  claim 15 , wherein the potentially fraudulent activity includes at least one of shill bidding and shill feedback. 
     
     
         18 . The method of  claim 15 , wherein the detection of the potentially fraudulent activity is responsive to a matching of a plurality of user transaction preferences from a plurality of different user identifies. 
     
     
         19 . The method of  claim 15 , further comprising:
 generating a first shill cookie and a second shill cookie for the first user identifier and the second user identifier, respectively; and   transmitting information stored on the first shill cookie and the second shill cookie to the network-based facility responsive to one of the plurality of triggering events with respect to a network-based facility and associated with the first identifier and the second identifier, respectively.   
     
     
         20 . A computer-readable storage medium comprising no transitory signals, the computer-readable storage medium having instructions that, when executed by at least one processor causes the at least one processor to perform operations, the operations comprising:
 generating a first identifier associated with a first set of transaction preferences, the first identifier to be stored on a first client machine, the first identifier being generated responsive to at least one of a plurality of triggering events with respect to a network-based facility;   generating a second identifier associated with a second set of transaction preferences, the second identifier to be stored with either the first identifier on the first client machine or on a second client machine, the second identifier being generated responsive to at least one of the plurality of triggering events with respect to the network-based facility;   receiving information stored in one or both of the first identifier and the second identifier at the network-based facility; and   detecting potentially fraudulent activity by detecting a lack of correspondence between the first set of transaction preferences and the second set of transaction preferences.

Join the waitlist — get patent alerts

Track US2014195368A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.