US 12,355,763 B2
Methods and systems for identifying unauthorized logins
Richard Post, Mechanicsville, VA (US); Aurielle Catron, Richmond, VA (US); Danielle Hagerty, Alexandria, VA (US); Jason Haile, Washington, DC (US); Derek Lafever, Henrico, VA (US); Daniel Parker, Spotsylvania, VA (US); and Nathan Weilbacher, Sherman, TX (US)
Assigned to Capital One Services, LLC, McLean, VA (US)
Filed by Capital One Services, LLC, McLean, VA (US)
Filed on Sep. 17, 2021, as Appl. No. 17/447,981.
Prior Publication US 2023/0089920 A1, Mar. 23, 2023
Int. Cl. G06F 7/04 (2006.01); G06N 20/00 (2019.01); H04L 9/40 (2022.01)
CPC H04L 63/0876 (2013.01) [G06N 20/00 (2019.01); H04L 63/126 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A computer-implemented method of identifying one or more unauthorized logins, the method comprising:
receiving a login request from a user device, the login request including a plurality of login identification data;
using a machine learning model, generating a score corresponding to the login request based on at least one of the plurality of login identification data, the machine learning model being trained to learn associations between the login identification data and scores based at least on (i) a set of prior login requests and (ii) a set of login classifications, each of the set of login classifications corresponding to at least one of the set of prior login requests;
determining whether the score exceeds a predetermined score threshold;
in response to a determination that the score exceeds the predetermined score threshold, rejecting the login request, tracking and recording activity corresponding to the plurality of login identification data, and prompting a user of the user device to submit a renewed login request;
receiving a search query from an agent device, the search query including at least one of the plurality of login identification data;
matching, in response to the search query, one or more of the plurality of login identification data to each of the one or more of the set of prior login requests; and
causing an indication of the one or more of the set of prior login requests to be displayed on the agent device, wherein the indication includes whether the one or more of the set of prior login requests were unauthorized and the one or more of the set of prior login requests caused to be displayed are the one or more of the set of prior login requests that have been matched to the one or more of the plurality of login identification data.