发明名称 Systems and methods for detection of session tampering and fraud prevention
摘要 The invention provides methods and apparatus for detecting when an online session is compromised. A plurality of device fingerprints may be collected from a user computer that is associated with a designated Session ID. A server may include pages that are delivered to a user for viewing in a browser at which time device fingerprints and Session ID information are collected. By collecting device fingerprints and session information at several locations among the pages delivered by the server throughout an online session, and not only one time or at log-in, a comparison between the fingerprints in association with a Session ID can identify the likelihood of session tampering and man-in-the middle attacks.
申请公布号 US9196004(B2) 申请公布日期 2015.11.24
申请号 US201414473818 申请日期 2014.08.29
申请人 The 41st Parameter, Inc. 发明人 Eisen Ori
分类号 H04L29/06;G06F21/00;G06Q30/06;H04L29/08;G06Q20/40 主分类号 H04L29/06
代理机构 Wilson Sonsini Goodrich & Rosati 代理人 Wilson Sonsini Goodrich & Rosati
主权项 1. A method for detecting an online transaction tampering, the method comprising: establishing a Session ID for activity between a computer and a user device over a network, wherein the Session ID is associated with at least two device fingerprints collected while an article is in a virtual shopping cart; instructing the computer to collect the at least two device fingerprints, while the article is in the virtual shopping cart, from the user device for the corresponding Session ID, wherein the at least two device fingerprints are collected from at least two different pre-selected pages displaying different content that are configured for an online transaction tampering comparison; and comparing the at least two device fingerprints, and if the at least two device fingerprints collected from the at least two different pre-selected pages are not identical, detecting the online transaction tampering and providing an alert.
地址 Scottsdale AZ US