User device profiling in transaction authentications
Abstract
A real-time fraud prevention system enables merchants and commercial organizations on-line to assess and protect themselves from high-risk users. A centralized database is configured to build and store dossiers of user devices and behaviors collected from subscriber websites in real-time. Real, low-risk users have webpage click navigation behaviors that are assumed to be very different than those of fraudsters. Individual user devices are distinguished from others by hundreds of points of user-device configuration data each independently maintains. A client agent provokes user devices to volunteer configuration data when a user visits respective webpages at independent websites. A collection of comprehensive dossiers of user devices is organized by their identifying information, and used calculating a fraud score in real-time. Each corresponding website is thereby assisted in deciding whether to allow a proposed transaction to be concluded with the particular user and their device.
Claims
exact text as granted — not AI-modifiedThe invention claimed is:
1 . A webserver process for identifying, tracking, and authenticating users by the devices they employ in online transactions, and comprising steps of:
inputting user log-on and webpage clickstream navigation information provided by a user device to a web-service over a network connection; extracting user-device identifying parameters from said log-on and webpage clickstream navigation information for use in recognizing, tracking, and authenticating the devices of individual users; provoking said user devices to supply even more user-device identifying parameters with webserver messages back to the user devices if needed to recognize, track, and authenticate the devices of said individual users; cataloging and recording a current sequence of said webpage clickstream navigation information of a particular user device then being employed to browse through a subject webpage and a website maintained by a consumer website server, wherein said webpage clickstream navigation information is presumed to be characteristic of a corresponding particular user; collecting and maintaining a database of comprehensive dossiers of user device identifications (ID's) obtained from many user-device visits to a variety of webpages maintained by many websites over a period of time; matching a user device currently visiting a website by identifying characteristics obtainable through a user device browser, and forwarding these over a network to a dossier file already maintained in said database, if possible; and calculating a fraud score in real-time based on results obtained in the steps of analyzing and collecting; and configuring the calculation as a signal output useful to assist each consumer website server in determining whether to allow a proposed transaction to be concluded by a particular user computing device.
2 . The webserver process of claim 1 , wherein:
if data describing a particular user's computing device cannot be matched by the network server to corresponding data already stored in an existing dossier file in said database, then a new dossier file is opened up in said database to be used later to track activities of such user computing device according to any user device identification parameters then obtainable; and the step to calculate said fraud score is principally determined according to results obtainable from analyzing said sequence of webpage clickstream behaviors.
3 . The webserver process of claim 1 , further comprising software instructions for enabling the network server to:
embed an endpoint client in a webpage presented on a website, and configured to provoke a browser in a user computing device to report back user device information (device ID), capabilities, extensions, add-ons, configurations, and user device locations, and other data useful for a machine to sort through and contribute to corresponding user device dossier files maintained in said database.
4 . The webserver process of claim 1 , further comprising software instructions for enabling the network server to:
centralize the collecting and maintaining a database of comprehensive dossiers of user device ID's obtained from many user-device visits to many webpages maintained by many websites over a period of time; wherein, a number of independent and unrelated websites are each programmed to forward user device activity reports to the network server for its sole control and maintenance of said database.
5 . The webserver process of claim 1 , further comprising software instructions for enabling the network server to:
centralize the analyzing a sequence of webpage clickstream behaviors of each user device then being employed to visit particular webpages; wherein, a number of independent and unrelated websites are each programmed to forward user device activity reports in real-time as they occur to a single centralized server for analyses of said webpage clickstream behaviors.
6 . The webserver process of claim 1 , further comprising software instructions for enabling the network server to:
centralize the production of fraud scores in real-time based on results calculated in the steps of analyzing and collecting, and configuring the results as a signal output which useful to assist each website in determining whether to allow a proposed transaction to be concluded by a particular user device; wherein, a number of independent and unrelated websites are each programmed to forward user device activity reports in real-time as they occur to a single centralized server for its calculation and return of said fraud score.
7 . A computer program product for building behavioral device identifications (ID) of user devices visiting websites monitored by a network server, comprising software instructions for enabling the network server to:
extract a clickstream behavior related to the particular paths and order of webpages an individual user follows with a sequence of user clicks; identify distinctive users according to their past clickstream behaviors and user device configurations and attributes; record said clickstream behavior and comparing it to previously determined patterns of normal, suspicious, and fraudulent activity; track session activity and pattern-match said clickstream behavior to normal-suspect-abnormal-malware patterns; monitor and analyze online transactions according to pre-determined business rules and statistical models, and to update profiles of users and accounts; correlate alerts and activities; and search for relationships amongst users and channels; wherein, a consumer website can be warned with a signal over the network of high risk users in real-time.
8 . A network server adapted to provide real-time fraud prevention, comprising a processor, database, and memory including instructions that cause the network server to:
build and store dossiers of user devices and behaviors from user-device configuration data and clickstream behavior descriptors collected from subscriber websites in real-time; distinguish individual user devices from others with said user-device configuration data; embed a client agent to compel user devices to volunteer configuration data when a user visits respective webpages at independent websites; and organize a collection of comprehensive dossiers of user devices by their identifying information, and calculating a fraud score in real-time; wherein, each corresponding website is assisted with a signal in deciding whether to allow a proposed transaction to be concluded with the particular user and their device.
9 . The network server of claim 9 , further comprising instructions that cause the network server to:
run an iSecure client in a sandbox to access information about browser settings, plugins, JavaScript and Flash properties in discovering device attributes field-by-field; store profiles of user devices in device fields of a database; compare possible matches from the database to either find a matching device or create a new device record, and if an old device was found, its fields are updated with the new data; configure an end-point client to comprise a kernel of JavaScript, Flash Player video, and related technologies and to embed it in a webpage viewable by a user; wherein, the end-point client is configured to run in background and gather data for forwarding to an iSecure server for user identification, and the server uses an iPrevent software service to compare possible matches from its database to either find a matching device or create a new device, if an old device was found, its fields are updated with the new data; and including a Flash Player video in the endpoint client and configuring it to trigger a report back from the browser on what kind of screen, audio, and video formats a particular user device supports, and to survey the character of each of the peripherals, printers, touch screens, screen readers, and other peripherals this particular Flash Player has access to.Join the waitlist — get patent alerts
Track US2015039513A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.