US2018262534A1PendingUtilityA1

Propagating fraud awareness to hosted applications

Assignee: IBMPriority: Dec 29, 2015Filed: May 11, 2018Published: Sep 13, 2018
Est. expiryDec 29, 2035(~9.4 yrs left)· nominal 20-yr term from priority
H04L 67/025H04L 63/08H04L 63/10H04L 63/20H04L 63/102H04L 67/16H04L 63/1425H04L 67/51
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A policy enforcement point includes fraud prevention information associated with devices and/or users which is collected from: (i) many cloud fraud services located in the cloud; and/or (ii) authorization processing of users and/or devices. The policy enforcement point is consulted when a user/device undergoes authorization processing for a transaction with an application (for example, an application that serves protected content such as financial records, email, etc.). Fraud prevention information is added to session data, associated with the attempted authorization to the application, for the user/device as the user/device proceeds its attempted authorization to the application. In some cases, the authorization to the application may be refused based on the data added to the session data by the policy enforcement point or the policy enforcement point will propagate fraud prevention information to the application to make the decision.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer implemented method comprising:
 collecting, in a fraud related data cache of a policy enforcement point system through a communication network and from a plurality of cloud fraud services, machine readable fraud related data;   intercepting, by the policy enforcement point system, a response being transmitted over a communications network from a cloud fraud service to a client device, with the response being responsive to a request generated by a browser script in a browser of the client device;   determining, by the policy enforcement point system, an authorization related data set, based, at least in part, on the machine readable fraud related data, with the authorization related data set relating to a fraud risk of at least one of the following: the client device, or a user of the client device;   modifying, by the policy enforcement point system and to generate a modified response, session data included in the intercepted response to filter out sensitive data so that any sensitive data that is present in the intercepted response will not be present in the modified response; and   sending, by the policy enforcement point system through the communication network, the modified response to the client device.   
     
     
         2 . The computer implemented method of  claim 1  further comprising:
 sending, by the policy enforcement point system to an application server involved in a communication session with the client device, the authorization related data set. 
 
     
     
         3 . The computer implemented method of  claim 1  further comprising:
 propagating, by the policy enforcement point system, the authorization related data set to the plurality of cloud services. 
 
     
     
         4 . The computer implemented method of  claim 1  wherein the authorization related data set indicates fraud having been conducted against the user or underway on the client device. 
     
     
         5 . The computer implemented method of  claim 1  wherein the authorization related data set includes device information which includes fraud related information related to a plurality of devices that the user of the client device has used in communication network transaction(s) in the past. 
     
     
         6 . The computer implemented method of  claim 1  further comprising:
 authenticating the policy enforcement point system to the cloud fraud service. 
 
     
     
         7 . A computer program product comprising:
 a machine readable data storage device; and   machine readable data stored in the data storage device, the machine readable data including:
 first program instructions programmed to collect, in a fraud related data cache of a policy enforcement point system through a communication network and from a plurality of cloud fraud services, machine readable fraud related data, 
 second program instructions programmed to intercept, by the policy enforcement point system, a response being transmitted over a communications network from a cloud fraud service to a client device, with the response being responsive to a request generated by a browser script in a browser of the client device, 
 third program instructions programmed to determine, by the policy enforcement point system, an authorization related data set, based, at least in part, on the machine readable fraud related data, with the authorization related data set relating to a fraud risk of at least one of the following: the client device, or a user of the client device, 
 fourth program instructions programmed to modify, by the policy enforcement point system and to generate a modified response, session data included in the intercepted response to filter out sensitive data so that any sensitive data that is present in the intercepted response will not be present in the modified response, and 
 fifth program instructions programmed to send, by the policy enforcement point system through the communication network, the modified response to the client device. 
   
     
     
         8 . The computer program product of  claim 7  wherein the machine readable data further includes:
 sixth program instructions programmed to send, by the policy enforcement point system to an application server involved in a communication session with the client device, the authorization related data set. 
 
     
     
         9 . The computer program product of  claim 7  wherein the machine readable data further includes:
 sixth program instructions programmed to propagate, by the policy enforcement point system, the authorization related data set to the plurality of cloud services. 
 
     
     
         10 . The computer program product of  claim 7  wherein the authorization related data set indicates fraud having been conducted against the user or underway on the client device. 
     
     
         11 . The computer program product of  claim 7  wherein the authorization related data set includes device information which includes fraud related information related to a plurality of devices that the user of the client device has used in communication network transaction(s) in the past. 
     
     
         12 . The computer program product of  claim 7  wherein the machine readable data further comprises:
 sixth program instructions programmed to authenticate the policy enforcement point system to the cloud fraud service. 
 
     
     
         13 . A computer system comprising:
 A set of processor(s)   a machine readable data storage device operatively connected to the set of processor(s) so that the set of processor(s) can execute program instructions stored in the data storage device; and   machine readable data stored in the data storage device, the machine readable data including:
 first program instructions programmed to collect, in a fraud related data cache of a policy enforcement point system through a communication network and from a plurality of cloud fraud services, machine readable fraud related data, 
 second program instructions programmed to intercept, by the policy enforcement point system, a response being transmitted over a communications network from a cloud fraud service to a client device, with the response being responsive to a request generated by a browser script in a browser of the client device, 
 third program instructions programmed to determine, by the policy enforcement point system, an authorization related data set, based, at least in part, on the machine readable fraud related data, with the authorization related data set relating to a fraud risk of at least one of the following: the client device, or a user of the client device, 
 fourth program instructions programmed to modify, by the policy enforcement point system and to generate a modified response, session data included in the intercepted response to filter out sensitive data so that any sensitive data that is present in the intercepted response will not be present in the modified response, and 
 fifth program instructions programmed to send, by the policy enforcement point system through the communication network, the modified response to the client device. 
   
     
     
         14 . The computer system of  claim 13  wherein the machine readable data further includes:
 sixth program instructions programmed to send, by the policy enforcement point system to an application server involved in a communication session with the client device, the authorization related data set. 
 
     
     
         15 . The computer system of  claim 13  wherein the machine readable data further includes:
 sixth program instructions programmed to propagate, by the policy enforcement point system, the authorization related data set to the plurality of cloud services. 
 
     
     
         16 . The computer system of  claim 13  wherein the authorization related data set indicates fraud having been conducted against the user or underway on the client device. 
     
     
         17 . The computer system of  claim 13  wherein the authorization related data set includes device information which includes fraud related information related to a plurality of devices that the user of the client device has used in communication network transaction(s) in the past. 
     
     
         18 . The computer system of  claim 13  wherein the machine readable data further comprises:
 sixth program instructions programmed to authenticate the policy enforcement point system to the cloud fraud service.

Join the waitlist — get patent alerts

Track US2018262534A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.