Finance processing system and finance processing method
The financial processing system addresses the inadequacies in preventing phishing scams by using a non-remitted account list to discard fraudulent transfer requests within the financial processing system, thereby reducing the damage caused by such scams.
Patent Information
- Application Number
- JP2023188828
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-02
- Publication Date
- 2025-05-16
AI Technical Summary
Existing methods for preventing online fraud, such as phishing scams, are inadequate in reducing the damage caused by these fraudulent activities.
A financial processing system and method that involves connecting user terminals and servers via a communication network, where successful authentication to a specific financial account triggers the server to acquire information about the intended transfer account, register it in a non-remitted account list, and discard any transfer requests matching this list, thereby preventing fraudulent transfers.
This approach effectively reduces the damage caused by phishing scams by preventing unauthorized transfers to fraudulent accounts, thereby enhancing the security of financial transactions.
Smart Images

Figure 2025076888000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a financial processing system and a financial processing method. [Background technology]
[0002] Conventionally, there has been known a method for dealing with online fraud in the relationship between a fraud prevention provider and a customer (for example, Patent Document 1).
[0003] Patent document 1 describes a method in which a decoy email address and a safe account associated with the decoy email address are created, it is determined whether an email received by the decoy email address is phishing, data related to the safe account is mapped to a page indicated by a URL included in the phishing email, and the phisher's use of the mapped data is tracked to take action against the phisher. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Special Publication No. 2008-507005 Summary of the Invention [Problem to be solved by the invention]
[0005] Conventional techniques leave room for improvement in terms of reducing damage caused by phishing scams.
[0006] An object of the present invention is to provide a financial processing system and a financial processing method that can reduce damage caused by phishing fraud. [Means for solving the problem]
[0007] In order to achieve the above-mentioned object, the financial processing system of the first invention is a financial processing system in which a user terminal and a server are connected to each other via a communication network so that they can communicate with each other, and when the authentication process for a specific financial account by the user terminal is successful, the server, upon receiving a request to transfer money from the specific financial account to another financial account, obtains information about the other financial account and discards the request to transfer money to the other financial account without performing the transfer process to the other financial account, and the server registers the information about the other financial account in a prohibited transfer account list, and when a request to transfer money from a source financial account to a destination financial account is received from the user terminal, the server compares the destination financial account with the prohibited transfer account list, and if the destination financial account matches a financial account registered in the prohibited transfer account list, discards the request to transfer money to the destination financial account without performing the transfer process to the destination financial account.
[0008] In this way, when the authentication process for a specific financial account by the user terminal is successful, the server, upon receiving a request to transfer money from the specific financial account to another financial account, obtains information about the other financial account and registers it in a prohibited transfer account list, compares the destination financial account with the prohibited transfer account list, and if the destination financial account matches a financial account registered in the prohibited transfer account list, discards the transfer request to the destination financial account without performing the transfer process to the destination financial account, thereby reducing the damage caused by phishing fraud.
[0009] A financial processing method according to a second invention is a financial processing method in a financial processing system in which a user terminal and a server are connected to each other via a communications network so that they can communicate with each other, and when authentication processing for a specific financial account by the user terminal is successful, the server, upon receiving a request to transfer from the specific financial account to another financial account, obtains information about the other financial account and discards the request to transfer to the other financial account without performing the transfer processing to the other financial account, and the server registers the information about the other financial account in a prohibited transfer account list, and upon receiving a request to transfer from the user terminal from a source financial account to a destination financial account, the server compares the destination financial account with the prohibited transfer account list, and if the destination financial account matches a financial account registered in the prohibited transfer account list, discards the request to transfer to the destination financial account without performing the transfer processing to the destination financial account. Effect of the Invention
[0010] As described above, the financial processing system and method of the present invention have the effect of reducing damage caused by phishing fraud. [Brief description of the drawings]
[0011] [Figure 1] 1 is a diagram for explaining an overview of processing in a financial processing system according to an embodiment of the present invention; [Diagram 2] 1 is a schematic diagram showing a configuration of a financial processing system according to an embodiment of the present invention. [Diagram 3] FIG. 2 is a schematic block diagram of an example of a computer functioning as a user terminal according to an embodiment of the present invention. [Figure 4] FIG. 2 is a block diagram showing a configuration of a server according to an embodiment of the present invention. [Diagram 5] FIG. 2 is a sequence diagram showing processing in a financial processing system according to an embodiment of the present invention. [Figure 6] FIG. 1 is a diagram for explaining a method for preventing phishing attacks. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0012] Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings.
[0013] [Outline of the embodiment of the present invention] In the embodiment of the present invention, phishing fraud is prevented by using a decoy account with a balance. Specifically, as shown in Figure 1, a vendor monitors phishing sites (S1) and provides phishing site information to a bank that has a server (S2).
[0014] The bank operates a server to access the phishing site and input the decoy account information (S3). This allows the perpetrator of the phishing scam to obtain the decoy account information. The server may be one that automatically obtains the decoy account information using a program or the like, without the bank having to operate the server.
[0015] The acquired decoy account information is then used to log into the decoy account from the user terminal of the phishing scam perpetrator (S4). At this time, the balance of the decoy account is displayed, encouraging the perpetrator to make an illegal transfer and making a request to transfer money to the account held by the perpetrator. A transfer request to transfer the balance of the decoy account (e.g., 9.99 million yen) to the account held by the perpetrator is then accepted from the user terminal of the phishing scam perpetrator (S5). The server then acquires the information on the account held by the perpetrator, discards the transfer request, and automatically blocks the transfer process to the account held by the perpetrator (S6). Thereafter, transfers to any identified accounts held by the perpetrator are automatically blocked (S7). In this way, the decoy account information is provided to the phishing scam perpetrator, information on the account held by the perpetrator is acquired, and transfers to the account held by the perpetrator are prohibited, thereby limiting the damage caused by phishing scams. In other words, even if a customer of the bank enters their account information on a phishing site and their financial account is taken over by a criminal, fraudulent transfers to accounts held by the criminals can be prevented.
[0016] [System Configuration] 2, a financial processing system 100 according to an embodiment of the present invention includes a server 10 and multiple user terminals 20A and 20B. In this embodiment, an example will be described in which user terminal 20A is a terminal belonging to a perpetrator of a phishing scam, and user terminal 20B is a terminal belonging to a customer who holds a financial account at a bank.
[0017] The server 10 and the user terminals 20A and 20B are connected via a network 26 such as the Internet. The network 26 is an example of a communication network.
[0018] The user terminals 20A and 20B are composed of mobile terminals or computer terminals, etc., and have a function of transmitting and receiving SMS (Short Message Service) messages. Here, the mobile terminals include smartphone terminals, mobile phones, PDA (Personal Digital Assistants) terminals, etc. The computer terminals include notebook / book type computer terminals, desktop type computer terminals, etc.
[0019] FIG. 3 is a block diagram showing the hardware configuration of the user terminals 20A and 20B of this embodiment.
[0020] 3, the user terminals 20A and 20B each include a CPU (Central Processing Unit) 11, a ROM (Read Only Memory) 12, a RAM (Random Access Memory) 13, a storage 14, an input unit 15, a display unit 16, and a communication interface (I / F) 17. Each component is connected to each other via a bus 19 so as to be able to communicate with each other.
[0021] The CPU 11 is a central processing unit, and executes various programs and controls each part. That is, the CPU 11 reads a program from the ROM 12 or the storage 14, and executes the program using the RAM 13 as a working area. The CPU 11 controls each of the above components and performs various arithmetic processing according to the program stored in the ROM 12 or the storage 14. In this embodiment, the ROM 12 or the storage 14 stores a program for performing various processing.
[0022] The ROM 12 stores various programs and various data. The RAM 13 temporarily stores programs or data as a working area. The storage 14 is configured with a recording medium such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive), and stores various programs including an operating system and various data.
[0023] The input unit 15 includes a pointing device such as a mouse, and a keyboard, and is used to perform various input operations.
[0024] The display unit 16 is, for example, a liquid crystal display, and displays various information. The display unit 16 may function as the input unit 15 by adopting a touch panel system.
[0025] The communication interface 17 is an interface for communicating with other devices, and uses standards such as Ethernet (registered trademark), FDDI, and Wi-Fi (registered trademark).
[0026] Next, a description will be given of the functional configuration of the server 10. Fig. 4 is a block diagram showing an example of the functional configuration of the server 10.
[0027] Functionally, as shown in Figure 4, the server 10 comprises an information acquisition unit 30, an access unit 32, a specific account authentication detection unit 34, an account information acquisition unit 36, a prohibited remittance account registration unit 38, a prohibited remittance account matching unit 40, and a remittance request discarding unit 42.
[0028] The information acquisition unit 30 acquires phishing site information from an external source. For example, when a phishing site that imitates the online banking site of the bank is established, the information acquisition unit 30 acquires the URL of the phishing site from a vendor that monitors phishing sites.
[0029] The access unit 32 accesses the acquired URL of the phishing site and inputs to the phishing site information required for authentication processing to a specific financial account, which is a decoy account prepared in advance. For example, the login ID and password required for authentication processing to the specific financial account are input to the phishing site. In this way, the perpetrator of the phishing fraud obtains the login ID and password of the specific financial account.
[0030] Here, access to the acquired phishing site URL and input of information required for authentication processing may be performed by an operator operating the server 10, or may be performed automatically by a program or the like.
[0031] Then, when the login ID and password for a specific financial account are entered into the bank's online banking site from the user terminal 20A of the phishing fraud perpetrator and a request for authentication to the specific financial account is made, the server 10 performs authentication processing for the specific financial account.
[0032] The specific account authentication detection unit 34 detects whether authentication processing for a specific financial account by the user terminal 20A of the perpetrator of the phishing fraud has been successful.
[0033] When the account information acquisition unit 36 detects that the authentication process for a specific financial account by the user terminal 20A has been successful, and receives a request to transfer money from the specific financial account to another financial account held by the perpetrator of a phishing scam, it acquires information regarding the other financial account.
[0034] For example, if the authentication process for a specific financial account is successful, there is a high possibility that a remittance request will be accepted from the user terminal 20A of the phishing scam perpetrator to transfer the balance of the specific financial account to another financial account held by the phishing scam perpetrator, and information regarding the other financial account held by the phishing scam perpetrator is obtained from this remittance request.
[0035] Furthermore, the account information acquisition unit 36 discards the remittance request to the other financial account without carrying out the remittance process to the other financial account.
[0036] The prohibited remittance account registration unit 38 registers the obtained information about the other financial account in the prohibited remittance account list stored in the storage 14.
[0037] Then, user terminal 20B, which is a terminal on the customer side of the bank, accesses the URL of the phishing site and inputs the information required for authentication processing for the customer's financial account to the phishing site, thereby allowing the perpetrator of the phishing scam to obtain the login ID and password for the customer's financial account.
[0038] Then, when the login ID and password for the customer's financial account are entered into the bank's online banking site from the user terminal 20A of the phishing fraud perpetrator and a request for authentication of the customer's financial account is made, the server 10 carries out the authentication process for the customer's financial account.
[0039] If the authentication process for the customer's financial account is successful, it is expected that a transfer request will be accepted from the user terminal 20A of the phishing scam perpetrator to transfer the balance of the customer's financial account to another financial account held by the phishing scam perpetrator.
[0040] When the prohibited remittance account verification unit 40 receives a remittance request from the user terminal 20A from a remittance source financial account to a remittance destination financial account, it verifies the remittance destination financial account against the prohibited remittance account list. Note that this remittance request may be received from any user terminal other than the user terminal 20A.
[0041] When the remittance destination financial account matches a financial account registered in the remittance prohibited account list, a remittance request discarding section 42 discards the remittance request to the remittance destination financial account without carrying out remittance processing to the remittance destination financial account.
[0042] [Functions of financial processing systems] Next, the operation of financial processing system 100 according to the embodiment of the present invention will be described.
[0043] First, when a vendor monitors a phishing site and provides phishing site information to the bank having the server 10, the sequence shown in Figures 5 and 6 is started. This sequence is an example of a financial processing method.
[0044] In step S100, the information acquisition unit 30 of the server 10 acquires phishing site information provided by a vendor.
[0045] In step S102, the access unit 32 of the server 10 accesses the URL of the obtained phishing site. In step S104, the access unit 32 of the server 10 inputs information required for authentication processing for a specific financial account, which is a decoy account prepared in advance, to the phishing site. In this way, the perpetrator of the phishing fraud obtains the login ID and password of the specific financial account.
[0046] In step S106, the login ID and password for a specific financial account are entered into the bank's online banking site on the user terminal 20A of the phishing fraud perpetrator, and when a request to execute authentication for the specific financial account is accepted, the request to execute authentication is sent to the server 10.
[0047] In step S108, the server 10 performs authentication processing for the specific financial account, and transmits the authentication result to the user terminal 20A.
[0048] In step S110, the specific account authentication detection unit 34 of the server 10 detects that the authentication process for the specific financial account by the user terminal 20A of the perpetrator of the phishing fraud has been successful.
[0049] Then, in step S112, when a remittance request to transfer the balance of a specific financial account to another financial account held by the perpetrator of the phishing fraud is received at user terminal 20A of the perpetrator of the phishing fraud, the remittance request is transmitted to server 10.
[0050] In step S114, the account information acquisition unit 36 of the server 10 acquires information about a specific financial account from a remittance request to another financial account held by the perpetrator of a phishing scam. The account information acquisition unit 36 also discards the remittance request to the other financial account without carrying out the remittance process to the other financial account.
[0051] In step S116, the prohibited remittance account registration unit 38 of the server 10 registers the obtained information about the other financial account in the prohibited remittance account list stored in the storage 14.
[0052] In step S118, user terminal 20B, which is a terminal on the bank's customer side, accesses the URL of the phishing site and inputs the information required for authentication processing for the customer's financial account to the phishing site, thereby enabling the perpetrator of the phishing scam to obtain the login ID and password for the customer's financial account.
[0053] In step S120, on the user terminal 20A of the phishing fraud perpetrator, the login ID and password for the customer's financial account are entered into the bank's online banking site, and when a request to execute authentication for the customer's financial account is received, the request to execute authentication is sent to the server 10.
[0054] In step S122, the server 10 performs authentication processing for the financial account of the customer, and transmits the authentication result to the user terminal 20A.
[0055] Then, if the authentication process for the customer's financial account is successful, in step S124, the user terminal 20A of the phishing fraud perpetrator accepts a remittance request to transfer the balance of the customer's financial account to another financial account held by the phishing fraud perpetrator, and sends the remittance request to the server 10.
[0056] In step S126, when the prohibited remittance account verification unit 40 of the server 10 receives a request from the user terminal 20A to remit from the source financial account to the destination financial account, it verifies the destination financial account against the prohibited remittance account list.
[0057] In step S128, if the remittance destination financial account matches a financial account registered in the prohibited remittance account list, the remittance request discarding unit 42 of the server 10 discards the remittance request to the remittance destination financial account without processing the remittance to the remittance destination financial account.
[0058] As described above, according to the financial processing system of the embodiment of the present invention, when information required for authentication processing of a specific financial account is input to a phishing site and authentication processing of the specific financial account by the user terminal is successful, the server, upon receiving a request to transfer money from the specific financial account to another financial account, obtains information about the other financial account and registers it in the prohibited transfer account list, compares the destination financial account with the prohibited transfer account list, and if the destination financial account matches a financial account registered in the prohibited transfer account list, discards the transfer request to the destination financial account without performing the transfer processing to the destination financial account, thereby reducing the damage caused by phishing scams.
[0059] In the above embodiment, the phishing site is an online banking phishing site, but the present invention is not limited to this. The phishing site may be a service site other than an online banking site.
[0060] Furthermore, the information required for accessing a phishing site and for authentication processing may be input from a terminal other than the server.
[0061] Furthermore, the above-mentioned server processing may be distributed and executed by a plurality of computers connected via a network. [Explanation of symbols]
[0062] 10 Server 11 CPU 14. Storage 15 Input section 16 Display 17 Communication Interface 19 Bus 20A, 20B User terminal 26 Network 30 Information acquisition department 32 Access Section 34 Specific Account Authentication Detection Unit 36 Account Information Acquisition Department 38. Prohibited Transfer Accounts Registration Department 40 Prohibited Account Verification Unit 42 Remittance request cancellation unit 100 Financial Processing Systems
Claims
1. A financial processing system in which a user terminal and a server are connected to each other via a communication network so as to be able to communicate with each other, When the authentication process for the specific financial account by the user terminal is successful, the server, upon receiving a request for remittance from the specific financial account to another financial account, acquires information about the other financial account and discards the request for remittance to the other financial account without carrying out the remittance process to the other financial account; The server registers information about the other financial account in a prohibited remittance account list; When a remittance request from a remittance source financial account to a remittance destination financial account is received from the user terminal, the server compares the remittance destination financial account with the remittance prohibited account list, and if the remittance destination financial account matches a financial account registered in the remittance prohibited account list, the server discards the remittance request to the remittance destination financial account without carrying out a remittance process to the remittance destination financial account. Financial processing systems.
2. 2. The financial processing system according to claim 1, wherein, upon acquiring the phishing site information, the server accesses the phishing site and inputs information required for authentication processing for the specific financial account.
3. A financial processing method in a financial processing system in which a user terminal and a server are connected to each other via a communication network so as to be able to communicate with each other, comprising the steps of: When the authentication process for the specific financial account by the user terminal is successful, the server, upon receiving a request for remittance from the specific financial account to another financial account, acquires information about the other financial account and discards the request for remittance to the other financial account without carrying out the remittance process to the other financial account; The server registers information about the other financial account in a prohibited remittance account list; When a remittance request from a remittance source financial account to a remittance destination financial account is received from the user terminal, the server compares the remittance destination financial account with the remittance prohibited account list, and if the remittance destination financial account matches a financial account registered in the remittance prohibited account list, the server discards the remittance request to the remittance destination financial account without carrying out a remittance process to the remittance destination financial account. Financial transaction methods.
4. 4. The financial processing method according to claim 3, wherein, upon acquiring the phishing site information, the server accesses the phishing site and inputs information required for authentication processing for the specific financial account.
Citation Information
Patent Citations
online fraud solution
JP2008507005A