US 12,074,891 B1
Systems and methods of detecting and mitigating malicious network activity
Jansey Comeaux, Youngsville, LA (US); Michael Scott McQuarrie, San Antonio, TX (US); Gregory Sansone, San Antonio, TX (US); and Veronica Santiago, San Antonio, TX (US)
Assigned to United Services Automobile Association (USAA), San Antonio, TX (US)
Filed by United Services Automobile Association (USAA), San Antonio, TX (US)
Filed on Feb. 15, 2023, as Appl. No. 18/169,351.
Application 18/169,351 is a continuation of application No. 17/028,971, filed on Sep. 22, 2020, granted, now 11,606,370.
Application 17/028,971 is a continuation of application No. 15/952,523, filed on Apr. 13, 2018, granted, now 10,812,503.
Claims priority of provisional application 62/485,124, filed on Apr. 13, 2017.
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 29/06 (2006.01); G06F 16/955 (2019.01); G06Q 20/40 (2012.01); H04L 9/40 (2022.01)
CPC H04L 63/1416 (2013.01) [G06F 16/955 (2019.01); G06Q 20/4016 (2013.01); H04L 63/1425 (2013.01); H04L 63/1433 (2013.01)] 14 Claims
OG exemplary drawing
 
1. A computer-implemented method comprising:
receiving, by at least one computer, a record of a new transaction associated with a fraud alert, wherein the new transaction is associated with a client from a system database;
analyzing the fraud alert associated with the new transaction by:
tagging, by the at least one computer, one or more attributes in historical transactions matching one or more attributes of the new transaction;
identifying, by the at least one computer, a transaction session record of the client, wherein the transaction session record comprises one or more transaction session attributes that match the tagged one or more attributes;
identifying, by the at least one computer, one or more session records associated with one or more additional clients having session attributes matching the one or more transaction session attributes of the transaction session record;
in response to identifying the one or more session records, determining that a number of the one or more additional clients is greater than a predetermined threshold;
in response to the number of the one or more additional clients being greater than the predetermined threshold, determining, by the at least one computer, whether the session attributes matching the one or more transaction session attributes are in a whitelist; and
in response to determining the session attributes are in the whitelist, permitting the new transaction to occur.