Identification of and Countermeasures Against Forged Websites
    1.
    发明申请
    Identification of and Countermeasures Against Forged Websites 有权
    对伪造网站的识别和对策

    公开(公告)号:US20090228780A1

    公开(公告)日:2009-09-10

    申请号:US12043130

    申请日:2008-03-05

    申请人: Ryan McGeehan

    发明人: Ryan McGeehan

    IPC分类号: G06F21/00 G06F17/00

    摘要: A system, a method, and computer program product identify a website that is a forgery of a primary website. Client side executable code is included in a page of the primary website, which page is copied in the forged website. The client side code, when executed by a client device, determines whether the domain from which the page is served is an authorized domain. Where the serving domain is not authorized, the client device is configured to alter the execute countermeasures against the forged website, such as altering operation of the forged page.

    摘要翻译: 系统,方法和计算机程序产品标识作为主要网站伪造的网站。 客户端可执行代码包含在主网站的页面中,该页面被复制在伪造的网站中。 客户端代码在由客户端设备执行时确定该页面被服务的域是否是授权域。 如果服务域未被授权,则客户端设备被配置为改变针对伪造网站的执行对策,例如改变伪造页面的操作。

    Identification of and countermeasures against forged websites
    2.
    发明授权
    Identification of and countermeasures against forged websites 有权
    对伪造网站的识别和对策

    公开(公告)号:US09325731B2

    公开(公告)日:2016-04-26

    申请号:US12043130

    申请日:2008-03-05

    申请人: Ryan McGeehan

    发明人: Ryan McGeehan

    摘要: A system, a method, and computer program product identify a website that is a forgery of a primary website. Client side executable code is included in a page of the primary website, which page is copied in the forged website. The client side code, when executed by a client device, determines whether the domain from which the page is served is an authorized domain. Where the serving domain is not authorized, the client device is configured to alter the execute countermeasures against the forged website, such as altering operation of the forged page.

    摘要翻译: 系统,方法和计算机程序产品标识作为主要网站伪造的网站。 客户端可执行代码包含在主网站的页面中,该页面被复制在伪造的网站中。 客户端代码在由客户端设备执行时确定该页面被服务的域是否是授权域。 如果服务域未被授权,则客户端设备被配置为改变针对伪造网站的执行对策,例如改变伪造页面的操作。

    Authenticating user sessions based on reputation of user locations
    3.
    发明授权
    Authenticating user sessions based on reputation of user locations 有权
    基于用户位置的声誉验证用户会话

    公开(公告)号:US08869243B2

    公开(公告)日:2014-10-21

    申请号:US12646803

    申请日:2009-12-23

    IPC分类号: G06F7/04 G06F21/31

    摘要: User sessions are authenticated based on locations associated with a user account used for sending a request for creating a session. Examples of locations of a source of a request include a geographical location, a network address, or a machine cookie associated with a device sending the request. Locations of the request are compared with stored safe locations associated with the user account and a suspiciousness index is determined for the session. The level of authentication required for the session is determined based on the suspiciousness index. Locations are associated with a reputation based on past history of sessions originating from the locations. A location associated with a history of creating suspicious session is considered an unsafe location. Reputation of the location originating the session is used to determine the level of authentication required for the session.

    摘要翻译: 用户会话基于与用于发送创建会话的请求的用户帐户相关联的位置进行身份验证。 请求源的位置的示例包括与发送请求的设备相关联的地理位置,网络地址或机器cookie。 将请求的位置与与用户帐户相关联的存储的安全位置进行比较,并为会话确定可疑索引。 会话所需的认证级别是根据可疑指数确定的。 位置与基于来自该地点的会话历史的声誉相关联。 与创建可疑会话的历史相关联的位置被认为是不安全的位置。 使用发起会话的位置的声望来确定会话所需的认证级别。

    Preventing phishing attacks based on reputation of user locations
    4.
    发明授权
    Preventing phishing attacks based on reputation of user locations 有权
    基于用户位置的声誉防止网络钓鱼攻击

    公开(公告)号:US09576119B2

    公开(公告)日:2017-02-21

    申请号:US12646800

    申请日:2009-12-23

    IPC分类号: G06F21/00 G06F21/31

    摘要: User sessions are authenticated based on locations associated with a user account used for sending a request for creating a session. Examples of locations of a source of a request include a geographical location, a network address, or a machine cookie associated with a device sending the request. Locations of the request are compared with stored safe locations associated with the user account and a suspiciousness index is determined for the session. The level of authentication required for the session is determined based on the suspiciousness index. Locations are associated with a reputation based on past history of sessions originating from the locations. A location associated with a history of creating suspicious session is considered an unsafe location. Reputation of the location originating the session is used to determine the level of authentication required for the session.

    摘要翻译: 用户会话基于与用于发送创建会话的请求的用户帐户相关联的位置进行身份验证。 请求源的位置的示例包括与发送请求的设备相关联的地理位置,网络地址或机器cookie。 将请求的位置与与用户帐户相关联的存储的安全位置进行比较,并为会话确定可疑索引。 会话所需的认证级别是根据可疑指数确定的。 位置与基于来自该地点的会话历史的声誉相关联。 与创建可疑会话的历史相关联的位置被认为是不安全的位置。 使用发起会话的位置的声望来确定会话所需的认证级别。

    Social Age Verification Engine
    6.
    发明申请
    Social Age Verification Engine 有权
    社会年龄验证引擎

    公开(公告)号:US20120047560A1

    公开(公告)日:2012-02-23

    申请号:US12858403

    申请日:2010-08-17

    IPC分类号: G06F21/00

    摘要: A social networking system obtains parental authorization from a parent for a child to access a computing resource, where the parent and the child are users of the social networking system. The child user may request the authorization by identifying a purported parent user. The social networking system attempts to verify the validity of the purported parent user's account, the age of the user associated with the purported parent's account, and/or the existence of a parent-child relationship between users of the accounts associated with the purported parent and the child. The social networking system makes these determinations, at least in part, using social and transactional information associated with the purported parent user's account and the child user's account in the social networking system. Upon verification of these items, the social networking system may allow the purported parent to provide authorization responsive to the child's request to access the computing resource.

    摘要翻译: 社交网络系统从父母为孩子获取父母授权以访问计算资源,父母和孩子是社交网络系统的用户。 子用户可以通过识别所声称的父用户来请求授权。 社交网络系统尝试验证所声称的父用户帐户的有效性,与所声称的父母的帐户相关联的用户的年龄,和/或与被声称的父母相关联的帐户的用户之间存在亲子关系的存在;以及 孩子 社交网络系统至少部分地使用与所声称的父用户帐户相关联的社交和交易信息以及社交网络系统中的子用户帐户进行这些确定。 在验证这些项目时,社交网络系统可以允许所声称的父级提供响应于孩子访问计算资源的请求的授权。

    Authenticating user sessions based on information obtained from mobile devices
    7.
    发明授权
    Authenticating user sessions based on information obtained from mobile devices 有权
    基于从移动设备获取的信息验证用户会话

    公开(公告)号:US09578499B2

    公开(公告)日:2017-02-21

    申请号:US13590806

    申请日:2012-08-21

    摘要: An online system determines whether a request for creating a session with the online system is suspicious. The online system associates a user account with a mobile key of a mobile device and geographical locations of the mobile device. The mobile key comprises unique identifier of the mobile device that is permanently stored on the mobile device. Upon receiving a request to create a session for the user account, the online system compares information associated with the user request with information describing the mobile device. For example, information associated with the user request can be a location determined by mapping internet protocol addresses obtained from the request. The online system determines whether the request is suspicious based on the comparison. If the online system determines that the request is suspicious, the online system may require enhanced authentication before granting the request.

    摘要翻译: 在线系统确定与在线系统建立会话的请求是否可疑。 在线系统将用户帐户与移动设备的移动密钥和移动设备的地理位置相关联。 移动密钥包括永久存储在移动设备上的移动设备的唯一标识符。 在接收到为用户帐户创建会话的请求时,在线系统将与用户请求相关联的信息与描述移动设备的信息进行比较。 例如,与用户请求相关联的信息可以是通过映射从请求获得的互联网协议地址来确定的位置。 在线系统基于比较来确定请求是否可疑。 如果在线系统确定请求是可疑的,则在授予请求之前,在线系统可能需要增强认证。

    Social age verification engine
    8.
    发明授权
    Social age verification engine 有权
    社会年龄验证引擎

    公开(公告)号:US08671453B2

    公开(公告)日:2014-03-11

    申请号:US12858403

    申请日:2010-08-17

    IPC分类号: G06F7/04

    摘要: A social networking system obtains parental authorization from a parent for a child to access a computing resource, where the parent and the child are users of the social networking system. The child user may request the authorization by identifying a purported parent user. The social networking system attempts to verify the validity of the purported parent user's account, the age of the user associated with the purported parent's account, and/or the existence of a parent-child relationship between users of the accounts associated with the purported parent and the child. The social networking system makes these determinations, at least in part, using social and transactional information associated with the purported parent user's account and the child user's account in the social networking system. Upon verification of these items, the social networking system may allow the purported parent to provide authorization responsive to the child's request to access the computing resource.

    摘要翻译: 社交网络系统从父母为孩子获取父母授权以访问计算资源,父母和孩子是社交网络系统的用户。 子用户可以通过识别所声称的父用户来请求授权。 社交网络系统尝试验证所声称的父用户帐户的有效性,与所声称的父母的帐户相关联的用户的年龄,和/或与被声称的父母相关联的帐户的用户之间存在亲子关系的存在;以及 孩子 社交网络系统至少部分地使用与所声称的父用户帐户相关联的社交和交易信息以及社交网络系统中的子用户帐户进行这些确定。 在验证这些项目时,社交网络系统可以允许所声称的父级提供响应于孩子访问计算资源的请求的授权。

    AUTHENTICATING USER SESSIONS BASED ON REPUTATION OF USER LOCATIONS
    9.
    发明申请
    AUTHENTICATING USER SESSIONS BASED ON REPUTATION OF USER LOCATIONS 有权
    基于用户位置的声明来验证用户会话

    公开(公告)号:US20100211997A1

    公开(公告)日:2010-08-19

    申请号:US12646803

    申请日:2009-12-23

    IPC分类号: G06F21/00

    摘要: User sessions are authenticated based on locations associated with a user account used for sending a request for creating a session. Examples of locations of a source of a request include a geographical location, a network address, or a machine cookie associated with a device sending the request. Locations of the request are compared with stored safe locations associated with the user account and a suspiciousness index is determined for the session. The level of authentication required for the session is determined based on the suspiciousness index. Locations are associated with a reputation based on past history of sessions originating from the locations. A location associated with a history of creating suspicious session is considered an unsafe location. Reputation of the location originating the session is used to determine the level of authentication required for the session.

    摘要翻译: 用户会话基于与用于发送创建会话的请求的用户帐户相关联的位置进行身份验证。 请求源的位置的示例包括与发送请求的设备相关联的地理位置,网络地址或机器cookie。 将请求的位置与与用户帐户相关联的存储的安全位置进行比较,并为会话确定可疑索引。 会话所需的认证级别是根据可疑指数确定的。 位置与基于来自该地点的会话历史的声誉相关联。 与创建可疑会话的历史相关联的位置被认为是不安全的位置。 使用发起会话的位置的声望来确定会话所需的认证级别。

    PREVENTING PHISHING ATTACKS BASED ON REPUTATION OF USER LOCATIONS
    10.
    发明申请
    PREVENTING PHISHING ATTACKS BASED ON REPUTATION OF USER LOCATIONS 有权
    基于用户位置的声明防止发生攻击

    公开(公告)号:US20100211996A1

    公开(公告)日:2010-08-19

    申请号:US12646800

    申请日:2009-12-23

    IPC分类号: G06F21/00

    摘要: User sessions are authenticated based on locations associated with a user account used for sending a request for creating a session. Examples of locations of a source of a request include a geographical location, a network address, or a machine cookie associated with a device sending the request. Locations of the request are compared with stored safe locations associated with the user account and a suspiciousness index is determined for the session. The level of authentication required for the session is determined based on the suspiciousness index. Locations are associated with a reputation based on past history of sessions originating from the locations. A location associated with a history of creating suspicious session is considered an unsafe location. Reputation of the location originating the session is used to determine the level of authentication required for the session.

    摘要翻译: 用户会话基于与用于发送创建会话的请求的用户帐户相关联的位置进行身份验证。 请求源的位置的示例包括与发送请求的设备相关联的地理位置,网络地址或机器cookie。 将请求的位置与与用户帐户相关联的存储的安全位置进行比较,并为会话确定可疑索引。 会话所需的认证级别是根据可疑指数确定的。 位置与基于来自该地点的会话历史的声誉相关联。 与创建可疑会话的历史相关联的位置被认为是不安全的位置。 使用发起会话的位置的声望来确定会话所需的认证级别。