发明名称 PREVENTING PHISHING ATTACKS BASED ON REPUTATION OF USER LOCATIONS
摘要 User sessions are authenticated based on locations associated with a user account used for sending a request for creating a session. Examples of locations of a source of a request include a geographical location, a network address, or a machine cookie associated with a device sending the request. Locations of the request are compared with stored safe locations associated with the user account and a suspiciousness index is determined for the session. The level of authentication required for the session is determined based on the suspiciousness index. Locations are associated with a reputation based on past history of sessions originating from the locations. A location associated with a history of creating suspicious session is considered an unsafe location. Reputation of the location originating the session is used to determine the level of authentication required for the session.
申请公布号 US2017118225(A1) 申请公布日期 2017.04.27
申请号 US201715400876 申请日期 2017.01.06
申请人 Facebook, Inc. 发明人 McGeehan Ryan;Popov Lev Timourovich;Palow Christopher William;Read Robert J.;Keyani Pedram
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A computer implemented method comprising: maintaining a safe locations database storing safe locations for user accounts, the safe locations database associating each user account with a set of safe locations; and updating the safe locations database by adding safe locations for a user account based on social networking connections of the user accounts, comprising: receiving a request to create a session associated with the user account;identifying one or more locations associated with a source of the request;retrieving one or more stored safe locations of social networking connections of the user account from the safe locations database;matching locations from the identified one or more locations with the one or more stored safe locations retrieved from the safe locations database;determining that the request is authorized if at least one of the identified one or more locations associated with the source of the request matches a stored safe location retrieved from the safe locations database;responsive to determining that the request is authorized, selecting at least one of the identified one or more locations associated with the source of the request; andadding the selected location to the set of safe locations associated with the user account stored in the safe locations database.
地址 Menlo Park CA US