US 12,242,649 B2
Super-cookie identification for stolen cookie detection
Matan Marudi, Or Yehuda (IL); Yuval Bercovich, Givatayim (IL); and Yarden Raiskin, Petaá-Tiqwa (IL)
Assigned to PAYPAL, INC., San Jose, CA (US)
Filed by PAYPAL, INC., San Jose, CA (US)
Filed on Jul. 29, 2022, as Appl. No. 17/816,111.
Prior Publication US 2024/0037279 A1, Feb. 1, 2024
Int. Cl. G06F 21/62 (2013.01); G06F 21/60 (2013.01); H04L 9/40 (2022.01)
CPC G06F 21/6263 (2013.01) [G06F 21/602 (2013.01); H04L 63/0876 (2013.01); H04L 63/1416 (2013.01)] 20 Claims
OG exemplary drawing
 
8. A method comprising:
receiving, via a network from a device of a user, an authentication request for the user to access a website using a web browser executable at the device;
responsive to the received authentication request, identifying a series of storage locations available on the device for storing web cookies, wherein the series of storage locations are sorted in order of increasing risk of fraud starting from a first storage location;
determining that the user has previously visited the website based on at least one web cookie stored at the first storage location in the series of storage locations;
retrieving, via the network from the device, a cookie value for each storage location in the series of storage locations;
determining whether the retrieved cookie value for each storage location after the first storage location in the series of storage locations matches an expected cookie value for that storage location;
calculating a score representing a level of fraud risk for the authentication request when there is a mismatch between the retrieved cookie value and the expected cookie value for at least one storage location in the series of storage locations, wherein the score is based on a position of the at least one storage location in the series of storage locations; and
authenticating the user, based on the calculated score.