Fraudulent transaction monitoring device, fraudulent transaction monitoring system, and fraudulent transaction monitoring method

The fraudulent transaction monitoring device addresses the challenge of identifying suspicious users in electricity trading markets by using a common indicator calculation unit to analyze transaction information, enhancing the efficiency and accuracy of detecting fraudulent activity.

JP7774427B2Active Publication Date: 2025-11-21MITSUBISHI ELECTRIC CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2021192368
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-11-26
Publication Date
2025-11-21
Estimated Expiration
2041-11-26

AI Technical Summary

Technical Problem

Existing technologies for identifying fraudulent transactions in electricity trading markets require setting specific quantitative conditions, which can be challenging due to the dynamic nature of the energy trading environment and the potential for unforeseen fraudulent methods, leading to decreased accuracy in detecting suspicious users. These technologies have not adequately addressed the need for efficiently and efficiently identifying suspicious users in a trading market, specifically in the context of electricity trading markets, specifically in the field of fraudulent transaction monitoring.

Method used

A fraudulent transaction monitoring device that includes a transaction information acquisition unit, a storage unit, and a common index calculation unit to determine a common indicator for each user, independent of the type of fraudulent transaction, allowing for efficient identification of suspicious users through deviation and price influence analysis.

Benefits of technology

The device enables the extraction of suspicious users regardless of the type of fraudulent transaction, improving the accuracy and efficiency of identifying fraudulent activity in electricity trading markets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007774427000001
    Figure 0007774427000001
  • Figure 0007774427000002
    Figure 0007774427000002
  • Figure 0007774427000003
    Figure 0007774427000003
Patent Text Reader

Abstract

To provide an illegal transaction monitoring device, an illegal transaction monitoring system and an illegal transaction monitoring method, which extract a doubtful user regardless of a type of an illegal transaction to be performed.SOLUTION: In an illegal transaction monitoring device 100, a transaction information acquisition unit 101 acquires transaction information in a transaction market, a transaction information storage unit 102 stores the transaction information acquired by the transaction information acquisition unit 101, a common index calculation unit 103 calculates an index for extracting a doubtful user who has performed a possibly illegal transaction, the index being a common index comparable regardless of a type of the illegal transaction, for each user on the basis of the transaction information stored in the transaction information storage unit 102, and a calculation result storage unit 104 stores a calculation result of the common index calculated by the common index calculation unit 103.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to techniques for detecting fraudulent transactions in trading markets, such as electricity trading markets. [Background technology]

[0002] Following the liberalization of the electricity market, electric power companies buy and sell electricity through electricity trading. In electricity trading, transactions are conducted for 48 products, divided into 30-minute intervals each day. Monitors are posted at exchanges that operate wholesale electricity trading markets (hereinafter simply referred to as "trading markets"), and these monitors are required to monitor electricity transactions by trading implementers (hereinafter referred to as "users") such as electric power companies, and to identify transactions that may be fraudulent (hereinafter also referred to as "suspicious transactions"). If a suspicious transaction is identified, the monitor will verify the facts with the user who conducted the suspicious transaction.

[0003] Typically, the purpose of users who engage in fraudulent transactions is to fluctuate market prices and obtain personal profits. Therefore, in monitoring a trading market, it is more important to identify users who are engaging in fraudulent transactions than to identify a single fraudulent transaction. Therefore, monitors are required to identify users who have conducted suspicious transactions (hereinafter referred to as "suspicious users"). However, because there are a large number of users in a trading market, the workload of monitors to identify suspicious users is extremely heavy. Therefore, a technology that can easily and efficiently identify suspicious users is desired.

[0004] Conventionally, stock trading markets have been monitored by monitors, and techniques for identifying suspicious stock transactions have been developed. For example, Patent Document 1 below proposes a method in which a monitor sets extraction conditions in advance for identifying transactions as suspicious, and users who have conducted transactions that meet the set extraction conditions are identified as suspicious users. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2010-146093 Summary of the Invention [Problem to be solved by the invention]

[0006] The technology of Patent Document 1 requires monitors to set extraction conditions for each type of fraud in advance. Furthermore, the technology of Patent Document 1 requires that a quantitative value (e.g., "a drop in market prices of 3% or more in five minutes") be set as an extraction condition. However, determining the quantitative value properly requires expertise, and if the quantitative value is not set properly, the accuracy of detecting suspicious users will decrease. Furthermore, because the energy trading environment changes daily and the energy trading market is still in its infancy, there is a possibility that fraudulent transactions using previously unforeseen methods will be carried out in the future. Because it is not possible to define extraction conditions for fraudulent transactions using unexpected methods, the technology of Patent Document 1 cannot identify users who engage in fraudulent transactions using unexpected methods as suspicious users.

[0007] The present disclosure has been made to solve the above-mentioned problems, and aims to provide a technology that can extract suspicious users regardless of the type of fraudulent transaction being carried out. [Means for solving the problem]

[0008] The fraudulent transaction monitoring device according to the present disclosure includes a transaction information acquisition unit that acquires transaction information of each user in a trading market, a transaction information storage unit that stores the transaction information acquired by the transaction information acquisition unit, and, based on the transaction information stored in the transaction information storage unit, It is an indicator for extracting suspicious users who have engaged in potentially fraudulent transactions, and is a common indicator that can be compared regardless of the type of fraudulent transaction. The system includes a common index calculation unit that calculates, for each user, a common index including at least one of the degree of deviation from other users or the degree of impact on market price; a calculation result storage unit that stores the calculation results of the common index calculated by the common index calculation unit; and a display unit that displays, for each user, the calculation results of the common index stored in the calculation result storage unit. [Effects of the Invention]

[0009] According to the technology disclosed herein, a common indicator is calculated that is independent of the type of fraudulent transaction. By extracting suspicious users based on the common indicator, it is possible to extract suspicious users regardless of the type of fraudulent transaction being conducted. [Brief explanation of the drawings]

[0010] [Figure 1] 1 is a configuration diagram of a fraudulent transaction monitoring device according to a first embodiment. [Figure 2] FIG. 4 is a diagram showing an example of information stored in a transaction information storage unit according to the first embodiment. [Figure 3] FIG. 10 is a diagram illustrating a first example of a process executed by a common index calculation unit according to the first embodiment. [Figure 4] FIG. 4 is a flow diagram of a common indicator calculation step in the example of FIG. 3. [Figure 5] FIG. 10 is a diagram illustrating a second example of a process executed by the common index calculation unit according to the first embodiment. [Figure 6] FIG. 6 is a flow diagram of the Mahalanobis distance calculation step in the example of FIG. 5. [Figure 7] FIG. 10 is a diagram for explaining an example of calculation of a Mahalanobis distance. [Figure 8] FIG. 6 is a flow diagram of a common index calculation step in the example of FIG. 5. [Figure 9] FIG. 10 is a diagram illustrating a third example of a process executed by the common index calculation unit according to the first embodiment. [Figure 10] FIG. 10 is a flow diagram of the detection index calculation step in the example of FIG. 9. [Figure 11] FIG. 10 is a flow diagram of the Mahalanobis distance calculation step in the example of FIG. 9. [Figure 12] FIG. 4 is a diagram illustrating an example of information stored in a calculation result storage unit according to the first embodiment. [Figure 13] FIG. 10 is a configuration diagram of a fraudulent transaction monitoring device according to a second embodiment. [Figure 14]FIG. 10 is a diagram showing Example 1 of a screen display of a display unit according to the second embodiment. [Figure 15] FIG. 10 is a diagram showing Example 2 of a screen display of the display unit according to the second embodiment. [Figure 16] FIG. 10 is a configuration diagram of a fraudulent transaction monitoring device according to a third embodiment. [Figure 17] FIG. 11 is a diagram illustrating a first example of an operation flow of the priority order calculation unit according to the third embodiment. [Figure 18] FIG. 10 is a diagram illustrating an example of a method for calculating priority and priority order. [Figure 19] FIG. 11 is a diagram illustrating a second example of the operation flow of the priority order calculation unit according to the third embodiment. [Figure 20] FIG. 11 is a diagram illustrating an example of information stored in a calculation result storage unit according to the third embodiment. [Figure 21] FIG. 11 is a diagram showing an example of a screen display of a display unit according to the third embodiment. [Figure 22] FIG. 10 is a configuration diagram of a fraudulent transaction monitoring device according to a fourth embodiment. [Figure 23] FIG. 13 is a diagram illustrating an example of an operation flow of a recommendation order calculation unit according to the fourth embodiment. [Figure 24] FIG. 13 is a diagram illustrating an example of information stored in a calculation result storage unit according to the fourth embodiment. [Figure 25] FIG. 10 is a diagram showing Example 1 of a screen display of a display unit according to the fourth embodiment. [Figure 26] FIG. 13 is a diagram showing Example 2 of a screen display of the display unit according to the fourth embodiment. [Figure 27] FIG. 10 is a configuration diagram of a fraudulent transaction monitoring device according to a fifth embodiment. [Figure 28] FIG. 13 is a diagram showing an example of information stored in an index storage unit according to the fifth embodiment. [Figure 29] FIG. 13 is a diagram showing Example 1 of a screen display of an index setting unit according to the fifth embodiment. [Figure 30] FIG. 13 is a diagram showing a second example of a screen display of the index setting unit according to the fifth embodiment. [Figure 31] FIG. 13 is a diagram showing a third example of a screen display of the index setting unit according to the fifth embodiment. [Figure 32]FIG. 2 is a diagram illustrating an example of the hardware configuration of a fraudulent transaction monitoring device. [Figure 33] FIG. 2 is a diagram illustrating an example of the hardware configuration of a fraudulent transaction monitoring device. DETAILED DESCRIPTION OF THE INVENTION

[0011] An embodiment of the technology according to the present disclosure will be described below. In the following embodiment, an example will be shown in which a fraudulent transaction monitoring device monitors an energy trading market, but the trading market to be monitored is not limited to the energy trading market, and may be a trading market in which any commodity is traded.

[0012] <First Embodiment> The fraudulent transaction monitoring device 100 according to the first embodiment will be described.

[0013] [Overall configuration of the fraudulent transaction monitoring device 100] FIG. 1 is a configuration diagram of a fraudulent transaction monitoring device 100 according to the first embodiment. The fraudulent transaction monitoring device 100 comprises a transaction information acquisition unit 101, a transaction information storage unit 102, a common index calculation unit 103, and a calculation result storage unit 104. The transaction information acquisition unit 101 acquires transaction information from the trading market. The transaction information storage unit 102 stores the information acquired by the transaction information acquisition unit 101. The common index calculation unit 103 performs calculations to extract suspicious users from the transaction information stored in the transaction information storage unit 102. The calculation result storage unit 104 stores the calculation results calculated by the common index calculation unit 103.

[0014] [Description of transaction information acquisition unit 101] The trading information acquisition unit 101 acquires trading information in the trading market from the trading market via a network. The trading information is information indicating which user bid or agreed on how much electricity, when, and at what time. The trading information includes, for example, bidding information (bid number, bidding date and time, bidder, product name, bid amount, bid price, whether or not an agreement was made, etc.) which is information about the bidding, and agreement information (agreement number, agreement date and time, agreed bid number, agreed amount, agreement price, etc.) which is information about the agreement. The time interval of the trading information may be any interval, and the information may be obtained every 10 minutes, every minute, or every second, for example.

[0015] Furthermore, the transaction information acquisition unit 101 may acquire information about the user (hereinafter referred to as "user information") along with the transaction information. The user information includes, for example, the user name (e.g., company name), capital, amount of electricity sold, number of sales customers, maximum power generation, power source configuration, power supply and demand record, etc. A user must become a member of the exchange to conduct transactions in the trading market. Therefore, the transaction information acquisition unit 101 may acquire the user information during the membership procedure. Furthermore, the transaction information acquisition unit 101 may acquire the user information from information that the user has made public. In this embodiment, it is assumed that the transaction information acquisition unit 101 acquires not only transaction information but also user information.

[0016] [Description of transaction information storage unit 102] The transaction information storage unit 102 stores the information acquired by the transaction information acquisition unit 101. Fig. 2 shows examples of bid information, contract information, and user information as transaction information stored in the transaction information storage unit 102. The transaction information stored in the transaction information storage unit 102 is linked to the date and time when the transaction information was acquired and the market name.

[0017] [Explanation of common index calculation unit 103] The common indicator calculation unit 103 calculates an indicator value for each user based on the transaction information stored in the transaction information storage unit 102 to determine whether each user is suspicious. This indicator is a common indicator that can be compared regardless of the type of fraud, and will be referred to as the "common indicator" hereinafter. By comparing the common indicators of each transaction, it is possible to relatively determine whether each user is suspicious, and from this determination result, it is possible to extract suspicious users.

[0018] The process executed by the common index calculation unit 103 will be described with reference to Fig. 3 to Fig. 11. The common index calculation unit 103 executes the process at regular intervals (for example, at regular intervals of time, at regular intervals of days, at regular intervals of weeks, etc.).

[0019] (Example 1) Example of calculating common indicators from trading information In the example of FIG. 3, the common index calculation unit 103 executes a common index calculation step ST03-a for calculating the value of the common index from the transaction information stored in the transaction information storage unit 102.

[0020] An example of the processing of the common index calculation step ST03-a will be described with reference to the flowchart in Fig. 4. The common index calculation step ST03-a includes the following steps 1 to 5. The circled numbers 1 to 5 in Fig. 4 represent steps 1 to 5, respectively.

[0021] In step 1, the common indicator calculation unit 103 acquires transaction information of all users from the transaction information storage unit 102. The period of data to be acquired at this time (hereinafter referred to as the "data period") is set in advance according to the calculation method in step 2. For example, as shown below, in step 2, if the value of the common indicator is calculated by "calculating the ratio of user A's bid volume to the overall average of bid volume X1 on a certain day," the common indicator calculation unit 103 only needs to acquire one day's worth of transaction information. In addition, in this case, if the common indicator for the most recent week is to be calculated, the common indicator calculation unit 103 acquires seven days' worth of transaction information.

[0022] In step 2, the common indicator calculation unit 103 sets NUMterm, the number of periods for calculating the common indicator. NUMterm can be calculated as [data period acquired in step 1] / [one data period]. The "one data period" corresponds to the data period of the transaction information used to calculate one common indicator in step 3. For example, if the data period of the transaction information acquired in step 1 is seven days and one data period is one day, NUMterm will be 7.

[0023] In step 3, the common indicator calculation unit 103 calculates the value of the common indicator for each user from the transaction information acquired in step 1. Here, the item of transaction information acquired in step 1 is represented as Xi (i=1, 2, ..., n). For example, if X1 is the bid volume, the common indicator calculation unit 103 calculates the ratio of the bid volume X1 of user A to the overall average of the bid volume X1 on a certain day for item X1 of user A. A The ratio of X1 A The common indicator calculation unit 103 calculates the ratio of user A's Xi to the overall average of Xi for a certain day for other items. A The ratio (Xi A / [average of all users' bid volume Xi]). These ratio values ​​are indicators for determining whether user A has made a suspicious transaction for each item. If these ratios are close to 1, user A's transactions can be said to be average (ordinary), so the greater the deviation of the ratio from 1, the more suspicious the user can be.

[0024] The common index calculation unit 103 calculates the ratio of user A to the overall average calculated for each item (X1 A / [Average of all users' bid volume X1], X2 A / [Average of all users' bid volume X2], X3 A The common indicator calculation unit 103 calculates the common indicator for user A on a given day. The common indicator calculation unit 103 calculates the common indicator for all users.

[0025] In step 4, the common index calculation unit 103 repeats step 3 NUMterm times.

[0026] In step 5, the common index calculation unit 103 passes the calculation result obtained in step 4 to the calculation result storage unit 104.

[0027] In the above example, for each item, the ratio of the user's value to the overall average is calculated as an indicator of whether the user is suspicious. Therefore, there is no need to consider differences in units or value size for each item, and indicators can be compared between different items. Then, by using the maximum value of User A's ratio to the overall average calculated for each item as a common indicator, the common indicator becomes an indicator that can be used to extract suspicious users regardless of the type of fraud.

[0028] In the above example, the common indicator is calculated using only the transaction information stored in the transaction information storage unit 102, but the common indicator may be calculated using user information in addition to the transaction information.

[0029] Furthermore, in the above example, the data period of the transaction information acquired by the common index calculation unit 103 is set to seven days, but this data period may be of any length. As described above, the common index calculation unit 103 executes the above process at regular intervals, and therefore the length of the data period of the transaction information acquired by the common index calculation unit 103 may be set in accordance with this timing. For example, if the common index calculation unit 103 executes the process once a day, the data period acquired in step 1 may be set to one day. Furthermore, for example, the length of the data period of the transaction information acquired by the common index calculation unit 103 may be set to 30 minutes, one hour, six hours, three days, one week, one month, etc. in accordance with the calculation method in step 3.

[0030] In step 3 of the above example, the maximum value of the ratio of user A to the overall average calculated for each item was used as the value of the common index, but the method of calculating the common index is not limited to this. For example, the average or minimum value of the ratio of user A to the overall average calculated for each item may also be used as the value of the common index.

[0031] Furthermore, the common index calculation unit 103 may calculate the value of the common index by other calculation methods, such as the Mahalanobis distance using the items X1, X2, ..., Xn of the transaction information. However, the common index must be calculated for each user. In addition to being calculated for each user, it may also be calculated for each product, time interval (by time of day, day, week, day of the week, month, year, etc.), etc.

[0032] In addition, each user may have multiple common indicators. For example, each user's common indicator may include at least one of a "deviation degree," which is a common indicator that represents the degree of deviation from other users, and a "price influence degree," which is a common indicator that represents the degree of influence on the market price in the trading market. Below, the deviation degree and the price influence degree will be described as examples of common indicators that are different from the above examples.

[0033] (a) Examples of deviations Generally, trading trends vary depending on the type of fraudulent trading. However, what users who engage in fraudulent trading have in common is that they fluctuate market prices by behaving differently from the majority of users who do not engage in fraudulent trading. Therefore, the deviation, which represents the degree of deviation of each user from other users, is suitable as a common indicator.

[0034] In order to understand whether a user's behavior differs from that of many other users, it is preferable to use general transaction information such as bid volume, bid price, and number of bids when calculating the deviation. For example, the Mahalanobis distance or data density calculated from each user's transaction information can be used as a common indicator of "deviation." The larger the Mahalanobis distance and the lower the data density, the greater the deviation. A user with a larger deviation can be said to be a suspicious user. Mahalanobis distance will also be explained in "Example 2" below.

[0035] The Mahalanobis distance and data density, which represent the degree of deviation, are calculated by dividing the transaction information of user A for items X1, X2, ..., Xn into a single vector (X1 A ,X2 A ,…,Xn A) can also be calculated as (X1 A ,X2 A ), (X1 A ,X3 A ), and calculate the deviation from each vector, and then calculate the average, maximum, or minimum value of the deviations, and use this as the deviation.

[0036] The ratio of each user to the overall average can also be considered an index of deviation, since the closer the ratio is to 1, the smaller the deviation from other users.

[0037] (b) Example of price impact Since the purpose of fraudulent trading is to fluctuate market prices and obtain personal profits, whether a user's transactions have influenced the market price in order to fluctuate the market price is an important factor in determining whether the user is suspicious. Therefore, the price influence, which indicates the degree of influence each user has on the market price, is suitable as a common indicator.

[0038] Users who influence the market price include not only users who directly change the market price but also users who indirectly change the market price. For example, if a user makes a bid but the bid is not executed, the bid does not directly change the market price, but the bid price can indirectly change the market price by influencing the bid and execution prices of other users.

[0039] Therefore, it is advisable to calculate the "price influence" as a common indicator by calculating the fluctuation range of the market price from the trading information and finding the ratio to the fluctuation range of the trading of users who traded within a certain period of time. The fluctuation range of the market price may be the difference in the market price within a certain period of time, or the difference between the minimum and maximum values ​​of the market price. The certain period of time may be a preset period of time such as every 30 minutes or every hour, or may be determined based on trading information such as the time from the completion of one transaction to the completion of the next transaction. For example, the ratio of users (hereinafter assumed to be "User A") who traded within a certain period of time may be calculated as [User A's bid price within a certain period of time / market price fluctuation range (difference in market price within a certain period of time)]. This makes it possible to associate the fluctuation range of the market price with the trading information of users within a certain period of time.

[0040] Then, the ratio of user A is calculated for each item of the transaction information, and the maximum or minimum value among them is found and used as the price influence of user A. Alternatively, the Mahalanobis distance or data density of the ratio calculated for each item may be calculated and used as the price influence of user A.

[0041] (c) Example of calculating common indicators considering buyers / sellers In the above examples of common indicators, the calculation of the common indicator does not take into account whether the transaction information is that of a buyer or a seller. For example, in stock trading, a trader can be either a buyer or a seller. However, in electricity trading, a trader cannot be a seller unless they own power generation facilities, so the number of users may be biased towards either buyers or sellers.

[0042] The common index is calculated using transaction information of all users (average, maximum, minimum, Mahalanobis distance, etc.) and transaction information of a specific user. Therefore, for example, if the value of the common index of a seller user is calculated using transaction information of a large number of buyer users, seller users with a small number of buyer users are likely to be extracted as suspicious users. This is because there are many buyer users whose tendencies differ from those of seller users.

[0043] Therefore, when calculating a common indicator using transaction information, it is preferable to take into consideration whether the transaction information is transaction information of a buyer or a seller. For example, when calculating the value of the common indicator in step 3 of common indicator calculation step ST03-a, if the user is a buyer, only transaction information of the same buyer should be used. Whether a user is a buyer or a seller can be determined, for example, from the ratio of the volume of buy bids to the volume of sell bids within a certain period of time. Alternatively, it may be determined from the ratio of the number of buy bids to the number of sell bids. Furthermore, a method of determining a user as a buyer if the volume of bids made as a buyer exceeds the volume of bids made as a seller, or a method of determining a user as a seller if the execution price when executed as a buyer is lower than the execution price when executed as a seller, may also be used.

[0044] This makes it possible to calculate a common index that takes into account the imbalance in the number of buyers and sellers, thereby improving the accuracy of extracting suspicious users. Note that since there are users who both buy and sell, users can also be divided into three types: buyers, sellers, and both buyers and sellers.

[0045] (Example 2) Example of calculating common indicators using Mahalanobis distance The above example shows how to calculate a common indicator from transaction information. Here, we will explain an example of calculating a common indicator using Mahalanobis distance, which indicates whether a certain data trend deviates from other data.

[0046] Mahalanobis distance is a type of distance used in statistics. It takes correlation into account and shows whether a certain piece of data deviates in trend from other data. Mahalanobis distance is effective when comparing data that are strongly correlated and have different characteristics. The larger the Mahalanobis distance, the greater the deviation in trend from other data. Therefore, in this example, the greater the deviation in trend from other data, the more "suspicious" it is considered to be. In other words, a user whose trend is significantly different from other users is considered suspicious.

[0047] The Mahalanobis distance is the square of the k-dimensional Mahalanobis distance D 2 k The population follows a chi-squared distribution with k degrees of freedom. By setting the significance level based on the chi-squared distribution, the threshold can be automatically determined. This threshold is not only used when the common index calculation unit 103 calculates the common index, but can also be used to display the threshold on the display unit 105 (described later) and when the priority order calculation unit 106 determines the priority.

[0048] In the example of Figure 5, the common index calculation unit 103 executes a Mahalanobis distance calculation step ST02-a to calculate the Mahalanobis distance from the transaction information stored in the transaction information storage unit 102, and a common index calculation step ST03-b to calculate the value of the common index from the calculation result of the Mahalanobis distance calculation step ST02-a stored in the calculation result storage unit 104.

[0049] First, an example of the processing in Mahalanobis distance calculation step ST02-a will be described with reference to the flowchart in Fig. 6. Mahalanobis distance calculation step ST02-a includes the following steps 1 to 7. The circled numbers 1 to 7 in Fig. 6 represent steps 1 to 7, respectively.

[0050] In step 1, the common index calculation unit 103 acquires transaction information of all users from the transaction information storage unit 102. The period of data to be acquired at this time (hereinafter referred to as the "data period") is set in advance, for example, the day before the calculation date, n days going back from a certain day, one day of the target date, three hours going back from the calculation time, a certain month, etc. In this case, the data period is set to seven days including the dth day of the Mth month. At this time, the common index calculation unit 103 may acquire user information of all users in addition to the transaction information.

[0051] In step 2, the common indicator calculation unit 103 sets NUMterm, the number of periods for which the Mahalanobis distance is to be calculated. NUMterm is calculated as [data period acquired in step 1] / [one data period]. For example, if the data period acquired in step 1 is seven days and one data period is one day's worth of trading information, NUMterm is 7. Note that one data period is set according to the calculation method in step 4. In this example, one data period is set to one day's worth of trading information in step 4 to calculate the Mahalanobis distance.

[0052] In step 3, the common index calculation unit 103 sets the number of users NUMuser for which the Mahalanobis distance is to be calculated. NUMuser may be set based on the transaction information acquired in step 1, or may be set in advance.

[0053] In step 4, the common index calculation unit 103 calculates the Mahalanobis distance between a certain user (hereinafter assumed to be "User A") and all users excluding User A (hereinafter referred to as "other users") from the transaction information obtained in step 1.

[0054] Figure 7 shows an example of calculating the Mahalanobis distance. For example, let Xi represent the item of transaction information acquired in step 1 (i = 1, 2, ... n), X1 represent the bid amount, and X2 represent the bid price. First, let us consider the bid amount X1 of other users on a certain day (assumed to be "month M, day d" here) within the data period in step 1. B ,X1 C ,…,X1 N and bid price X2 B ,X2 C ,…,X2 N is the data group (white circle in the figure), and the center value of the data group (diagonal triangle in the figure) is calculated. Then, the bid volume of user A, X1 A and bid price X2 A Calculate the Mahalanobis distance from the black circle in the figure to the center of the data group. This is performed for all combinations of items.

[0055] The combination of items used to calculate the Mahalanobis distance may be set in advance. FIG. 7 shows an example in which the Mahalanobis distance is calculated from two items (bid quantity X1 and bid price X2), but the Mahalanobis distance may be calculated from only one item, or from three or more items. Also, a calculation method other than that described above may be used as long as it can determine the Mahalanobis distance between user A and other users. For example, in the example of FIG. 7, the center value of the data group is calculated from only the data of other users, but it may also be calculated from the data of all users, including user A.

[0056] In the above example, the Mahalanobis distance was calculated using transaction information items X1, X2, ..., Xn, but the Mahalanobis distance may also be calculated using user information items Y1, Y2, ..., Yn in addition to transaction information items X1, X2, ..., Xn. For example, if X1 is the bid amount and Y1 is the amount of electricity sold, then the bid amount X1 of other users on a certain day (month M, day d) is B ,X1 C ,…,X1 N and electricity sales Y1 B ,Y1 C ,…,Y1 N is used as a data set, calculate the center value of the data set, and determine the bid volume of user A, X1 A and electricity sales Y1 A It is also possible to calculate the Mahalanobis distance to the center of the data group from the user information. Although user information is basically a fixed value and does not fluctuate from day to day, by combining it with transaction information, which fluctuates daily, it is thought that trends that would be difficult to notice from transaction information alone can be discovered.

[0057] In step 5, the common index calculation unit 103 repeats step 4 for NUMuser times.

[0058] In step 6, the common index calculation unit 103 repeats step 5 NUMterm times.

[0059] In step 7, the common index calculation unit 103 passes the calculation result obtained in step 6 to the calculation result storage unit 104.

[0060] Next, an example of the processing of common index calculation step ST03-b will be described with reference to the flowchart in Fig. 8. Common index calculation step ST03-b includes the following steps 1 to 7. Circled numbers 1 to 7 in Fig. 8 represent steps 1 to 7, respectively.

[0061] In step 1, the common index calculation unit 103 acquires the Mahalanobis distances of all users calculated in the Mahalanobis distance calculation step ST02-a from the calculation result storage unit 104. The period of data to be acquired at this time (hereinafter referred to as the "data period") is set in advance, for example, the day before the calculation date, n days prior to a certain day, one day prior to the target day, three hours prior to the calculation time, a certain month, etc.

[0062] In step 2, the common index calculation unit 103 sets NUMterm, the number of periods for calculating the common index. NUMterm is calculated as [data period acquired in step 1] / [one data period]. One data period is set according to the calculation method in step 3. For example, if the data period acquired in step 1 is seven days and one data period is one day, NUMterm is 7.

[0063] In step 3, the common index calculation unit 103 sets the number of users NUMuser for calculating the value of the common index. NUMuser may be set based on the Mahalanobis distance information acquired in step 1, or may be set based on the number of users set in step 3 of the Mahalanobis distance calculation step ST02-a, or may be set in advance.

[0064] In step 4, the common index calculation unit 103 calculates the value of the common index of a certain user (hereinafter assumed to be "user A") from the Mahalanobis distances acquired in step 1. For example, the average value of user A's Mahalanobis distances is calculated as the common index with common index number "1" (hereinafter referred to as "common index 1"), and the maximum value of user A's Mahalanobis distances is calculated as the common index with common index number "2" (hereinafter referred to as "common index 2"). The method of calculating the common index is not limited to this, and the sum or minimum value of user A's Mahalanobis distances may also be used as the common index. Furthermore, the common index may be calculated from all of user A's Mahalanobis distances, or may be calculated from a specific Mahalanobis distance.

[0065] In step 5, the common index calculation unit 103 repeats step 4 for NUMuser times.

[0066] In step 6, the common index calculation unit 103 repeats step 5 NUMterm times.

[0067] In step 7, the common index calculation unit 103 passes the calculation result obtained in step 6 to the calculation result storage unit 104.

[0068] This allows for a common indicator to be obtained in which the greater the deviation in tendency from other users, that is, the greater the Mahalanobis distance, the greater the degree of "suspiciousness."

[0069] In the above example, the common index is calculated using the Mahalanobis distance, but it may also be calculated using other indices that can represent the degree of deviation or density of the data distribution other than the Mahalanobis distance. In this case, the common index is calculated so that the more the data deviates from the data distribution of other users or the lower the density of the data, the greater the degree of "suspiciousness" of the data.

[0070] Here, a modified example of the method for calculating the common index when using the Mahalanobis distance will be described.

[0071] (a) Example of using a threshold when calculating a common indicator When using the Mahalanobis distance, the threshold can be automatically determined by setting the significance level based on the chi-square distribution. Here, we will show an example of calculating the common index using a threshold.

[0072] When calculating the value of the common index in step 4 of the common index calculation step ST03-b, for example, common index 1 is set to the ratio of the number of Mahalanobis distances of user A calculated in the Mahalanobis distance calculation step ST02-a that exceed a threshold.

[0073] However, since the threshold value differs depending on the number of transaction information items used when calculating the Mahalanobis distance, it is not possible to directly compare Mahalanobis distances with different numbers of items. Therefore, the calculation method for the Mahalanobis distance of user A calculated in Mahalanobis distance calculation step ST02-a is changed.

[0074] Since the average of the squared value of the Mahalanobis distance corresponds to the number of items, the squared value of the Mahalanobis distance is divided by the number of items. As a result, the Mahalanobis distance is normalized so that the average of its squared value becomes 1, making it possible to compare thresholds regardless of the number of items.

[0075] Then, based on the threshold determined in step 3 of common index calculation step ST03-b according to the chi-squared distribution with degrees of freedom k, the number of Mahalanobis distances that exceed the threshold is calculated. Finally, the ratio of the number of Mahalanobis distances that exceed the threshold (number of Mahalanobis distances that exceed the threshold / total number of Mahalanobis distances) is calculated. The ratio of the number of Mahalanobis distances that exceed the threshold becomes the value of the common index.

[0076] In this way, by using the Mahalanobis distance, it is possible to set the significance level based on the chi-square distribution and automatically determine the threshold. Furthermore, even if the number of transaction information items used to calculate the Mahalanobis distance is different, a common indicator that can be compared with each other can be obtained.

[0077] (b) Example of calculating Mahalanobis distance considering buyer / seller In the example of Mahalanobis distance above, when calculating the Mahalanobis distance, it is not taken into account whether the transaction information is that of a buyer or a seller. For example, in stock trading, a trader can be either a buyer or a seller. However, in electricity trading, a trader cannot be a seller unless they own power generation facilities, so the number of users may be biased towards either buyers or sellers.

[0078] Since the Mahalanobis distance represents the degree of deviation between the trends of one piece of data and another, if the seller has a very small number of users, the seller's Mahalanobis distance may be large, which increases the likelihood that the seller's users will be identified as suspicious.

[0079] Therefore, the calculation method of the Mahalanobis distance calculation step ST02-a is changed. For example, the transaction information acquired in step 1 of the Mahalanobis distance calculation step ST02-a is divided into transaction information of users who are buyers and transaction information of users who are sellers. Whether a user is a buyer or a seller can be determined, for example, from the ratio of the volume of buy bids to the volume of sell bids within a certain period of time. Alternatively, it may be determined from the ratio of the number of buy bids to the number of sell bids. Furthermore, a method such as a "buyer" method may be used, in which a user is determined to be a buyer if the volume of bids made as a buyer exceeds the volume of bids made as a seller, or a method may be used in which a user is determined to be a seller if the contract price when executed as a buyer is lower than the contract price when executed as a seller.

[0080] Then, in step 3 of the Mahalanobis distance calculation step ST02-a, when calculating the Mahalanobis distance of user A, for example, if user A is a buyer, the users excluding user A from the buyer users are considered as other users, and the Mahalanobis distance between user A and the other users is calculated.

[0081] This allows us to calculate the Mahalanobis distance while taking into account the imbalance in the number of buyers and sellers. As a result, we can calculate a common index that takes into account the imbalance in the number of buyers and sellers, thereby improving the accuracy of extracting suspicious users. Note that since there are users who both buy and sell, we can also divide users into three types: buyers, sellers, and buyers and sellers.

[0082] (Example 3) Example of calculating Mahalanobis distance using detection index In the procedure 3 of the Mahalanobis distance calculation step ST02-a in Example 2, for example, when calculating the Mahalanobis distance of user A from a combination of items including bid volume X1, the bid volume X1 of user A on a certain day (month M, day d) is calculated as follows: A This calculation must be performed each time the Mahalanobis distance is calculated from a combination of items including the bid amount X1, and therefore the same calculation is performed multiple times, resulting in an enormous amount of calculation required to calculate the Mahalanobis distance for each user.

[0083] Here, an example is shown in which the common index calculation unit 103 calculates the values ​​of each item for each user in advance and stores them in the calculation result storage unit 104, thereby reducing the amount of calculation required to calculate the Mahalanobis distance.

[0084] In the example of FIG. 9, the common index calculation unit 103 performs a detection index calculation step ST01, a Mahalanobis distance calculation step ST02-b, and a common index calculation step ST03-b. In the detection index calculation step ST01, a value of an index related to energy trading (hereinafter referred to as a "detection index") is calculated for each user, and the value is stored in the calculation result storage unit 104. In the Mahalanobis distance calculation step ST02-b, a Mahalanobis distance is calculated for each combination of user and detection index from the calculation results (detection index values ​​for each user) of the detection index calculation step ST01 stored in the calculation result storage unit 104. In the common index calculation step ST03-b, a value of the common index is calculated from the calculation results of the Mahalanobis distance calculation step ST02-b stored in the calculation result storage unit 104. Note that the common index calculation step ST03-b is the same as that shown in Example 2.

[0085] Here, detection indicators are indicators that represent the trading behavior of each user extracted from trading information. Trading behavior refers to what actions (bidding, execution, cancellation, etc.) are performed within a certain period of time and on what scale (volume, price, number of times, etc.). Examples of detection indicators include the average bid volume by user and day, the execution price by user and product, and the bid price relative to the bid volume by user, product, and day.

[0086] The detection index is calculated using information acquired from the transaction information storage unit 102. Not only the transaction information but also user information may be used to calculate the detection index. By using the user information, a detection index is obtained that represents transaction behavior that takes into account the size of the user's company, such as the user's bid amount for the amount of electricity sold.

[0087] There are multiple detection indices. The detection indices to be used may be determined in advance, or may be added or changed by an observer. When an observer adds or changes a detection indices, the indices may be added or changed using the index setting unit 109 described later.

[0088] Detection indicators are always aggregated by user. In addition to by user, transaction information may also be aggregated by product, time interval (by time of day, day, week, day of the week, month, year, etc.), bid volume, etc. In the following example, all detection indicators are aggregated by user, day, and product.

[0089] First, an example of the processing of the detection index calculation step ST01 will be described with reference to the flow diagram in Fig. 10. In the detection index calculation step ST01, the value of the detection index is calculated for each user, each day, and each product. The detection index calculation step ST01 includes the following steps 1 to 7. The circled numbers 1 to 7 in Fig. 10 represent steps 1 to 7, respectively.

[0090] In step 1, the common index calculation unit 103 acquires transaction information of all users from the transaction information storage unit 102. In this example, the common index calculation unit 103 acquires transaction information for the past seven days including the dth day of the Mth month. In addition to the transaction information, the common index calculation unit 103 may also acquire user information for all users.

[0091] In step 2, the common indicator calculation unit 103 sets NUMterm, the number of periods for calculating the detection indicators. NUMterm is calculated as [data period acquired in step 1] / [one data period]. One data period is set according to the calculation method in step 4. In this example, the data period acquired in step 1 is seven days, and one data period is one day, so NUMterm is 7.

[0092] In step 3, the common indicator calculation unit 103 sets the number of target users NUMuser. NUMuser may be set in advance by an observer, or may be set based on the transaction information or user information acquired in step 1 from the transaction information storage unit 102.

[0093] In step 4, the common indicator calculation unit 103 calculates the value of each detection indicator for a certain day (month M, day d) for a certain user (hereinafter assumed to be "user A") from the transaction information acquired in step 1. For example, the detection indicator for detection indicator number "1" (hereinafter referred to as "detection indicator 1") is calculated by averaging the bid volume for user A's product with product name "1" on month M, day d. The detection indicator may also be calculated in other ways. For example, the total transaction volume for user A's product with product name "1" on month M, day d may be used as the detection indicator, or the amount of fluctuation in user A's bid price on month M, day d may be used as the detection indicator. User information may also be included when calculating the detection indicator. Furthermore, for example, the ratio of the bid volume on month M, day d to the amount of electricity sold by user A for user A's product with product name "1" may be used as the detection indicator.

[0094] In step 5, the common index calculation unit 103 repeats step 4 for NUMuser times.

[0095] In step 6, the common index calculation unit 103 repeats steps 3 to 5 for NUMterm.

[0096] In step 7, the common index calculation unit 103 passes the calculation result obtained in step 6 to the calculation result storage unit 104.

[0097] Next, an example of the processing of Mahalanobis distance calculation step ST02-b will be described with reference to the flowchart in Fig. 11. In Mahalanobis distance calculation step ST02-b, the Mahalanobis distance value is calculated for each user, each day, and each product. Mahalanobis distance calculation step ST02-b includes the following steps 1 to 7. The circled numbers 1 to 7 in Fig. 11 represent steps 1 to 7, respectively.

[0098] In step 1, the common index calculation unit 103 sets NUMterm, the number of periods for which the Mahalanobis distance is to be calculated. In this example, the Mahalanobis distance is calculated for the past seven days including month M and day d, and the detection index value for one day is used when calculating the Mahalanobis distance per time in step 5. Therefore, NUMterm is 7.

[0099] In step 2, the common index calculation unit 103 sets the number of target users NUMuser. NUMuser may be set in advance by an observer, or may be set based on all detection information of all users acquired in step 4.

[0100] In step 3, the common index calculation unit 103 sets the number of combinations of detection indices, NUMdetect. NUMdetect may be set in advance by an observer, or may be set based on the detection information acquired in step 4.

[0101] In step 4, the common index calculation unit 103 acquires all detection information of all users from the calculation result storage unit 104. The common index calculation unit 103 may acquire user information for all users in addition to the detection information. In this example, the common index calculation unit 103 acquires detection information for the past day (month M, day d).

[0102] In step 5, the common indicator calculation unit 103 calculates the Mahalanobis distance between a certain user (hereinafter assumed to be “user A”) and other users for the combination of detection indicators extracted from the detection information acquired in step 4.

[0103] In step 6, the common indicator calculation unit 103 repeats steps 4 and 5 NUMdetect times, thereby calculating the Mahalanobis distance between user A and other users for all combinations of detection indicators.

[0104] In step 7, the common index calculation unit 103 repeats step 6 for NUMuser times.

[0105] In step 8, the common index calculation unit 103 repeats step 7 for NUMterm.

[0106] In step 9, the common index calculation unit 103 passes the calculation result obtained in step 8 to the calculation result storage unit 104.

[0107] In this way, in Mahalanobis distance calculation step ST02-b, the Mahalanobis distance for each user is calculated using the detection index calculated in advance in detection index calculation step ST01, so the amount of calculation required to calculate the Mahalanobis distance in Mahalanobis distance calculation step ST02-b is less than that in Mahalanobis distance calculation step ST02-a shown in Example 2.

[0108] In the above example, detection indicators are aggregated by user, day, and product, but detection indicators only need to be aggregated by user, and do not necessarily have to be aggregated by product, day, etc. For example, there may be detection indicators that look at consecutive products. For example, in electricity trading, product i is the electricity at h, product i+1 is the electricity at h:30, product i+2 is the electricity at h+1, etc. Therefore, it is thought that there are also user trading trends that can be understood by checking the detection indicators for consecutive products.

[0109] The common index calculation step ST03-b is the same as that shown in Example 2, and therefore a description thereof will be omitted here.

[0110] The fraudulent transaction monitoring device 100, equipped with the common indicator calculation unit 103, can calculate a common indicator, a "common indicator," that can be compared regardless of the type of fraud. This makes it possible to extract suspicious users regardless of the type of fraudulent transaction being carried out. It is also expected that users who carry out fraudulent transactions of unknown definitions can be extracted. Furthermore, since there is no need to set extraction conditions for each type of fraudulent transaction, the workload of monitors is reduced.

[0111] [Explanation of calculation result storage unit 104] The calculation result storage unit 104 stores the calculation results obtained by the common index calculation unit 103. An example of information stored in the calculation result storage unit 104 is shown in FIG.

[0112] 12(a) is an example of the calculation result of the detection index calculation step ST01 of the common index calculation unit 103 stored in the calculation result storage unit 104. For example, when the common index calculation unit 103 calculates the value of the detection index by user, by day, and by product, the calculation result storage unit 104 stores the user name, target date and time, product name, detection index number, and detection index value of the detection index. The detection index name may be used instead of the detection index number.

[0113] 12(b) is an example of the calculation result of the Mahalanobis distance calculation step ST02-a of the common index calculation unit 103 stored in the calculation result storage unit 104. For example, if the common index calculation unit 103 calculates the Mahalanobis distance by user, by day, and by product, the calculation result storage unit 104 stores the user name, target date and time, product name, the combination of items used when calculating the Mahalanobis distance, and the Mahalanobis distance. The calculation result of the Mahalanobis distance calculation step ST02-b is similar to this, but because a combination of detection indexes is used when calculating the Mahalanobis distance, the calculation result includes the combination of detection indexes rather than the combination of items.

[0114] 12(c) is an example of the calculation result of the common index calculation step ST03-a or ST03-b of the common index calculation unit 103 stored in the calculation result storage unit 104. For example, when the common index calculation unit 103 calculates the value of the common index by user, by day, and by product, the calculation result storage unit 104 stores the user name, target date and time, product name, common index number, and value of the common index. The common index name may be used instead of the common index number.

[0115] As described above, by storing the calculation results of detection index calculation step ST01, Mahalanobis distance calculation step ST02-a or ST02-b, and common index calculation step ST03-a or ST03-b of common index calculation unit 103 in calculation result storage unit 104, it becomes easy to change the aggregation period of, for example, the detection index calculated in detection index calculation step ST01, the Mahalanobis distance calculated in Mahalanobis distance calculation step ST02-a or ST02-b, and the common index calculated in common index calculation step ST03-a or ST03-b.

[0116] This makes it possible to calculate, for example, the aggregation period for detection indicators by time of day, the aggregation period for Mahalanobis distances by day, and the aggregation period for common indicators by week. Furthermore, for example, it is also possible to prepare, as common indicators, a daily common indicator calculated from daily Mahalanobis distances and a weekly common indicator calculated from weekly Mahalanobis distances. Preparing common indicators with different aggregation periods in this way allows for more flexible use of common indicators, which can contribute to improving the accuracy of detecting suspicious users.

[0117] <Embodiment 2> The following describes a fraudulent transaction monitoring device 100 according to embodiment 2. In embodiment 2, elements that are the same as or equivalent to those described in embodiment 1 are given the same reference numerals. Therefore, their description will be omitted or simplified, and the description will focus on the differences from embodiment 1.

[0118] [Overall configuration of the fraudulent transaction monitoring device 100] Figure 13 is a configuration diagram of a fraudulent transaction monitoring device 100 according to embodiment 2. The configuration of the fraudulent transaction monitoring device 100 in Figure 13 is obtained by adding a display unit 105 that displays the calculation results stored in the calculation result storage unit 104 on a screen to the configuration of Figure 1.

[0119] [Explanation of display unit 105] Display unit 105 displays on its screen the calculation results stored in calculation result storage unit 104. Examples of screen displays on display unit 105 are shown in Fig. 14 and Fig. 15.

[0120] (Example 1) Display example showing the value of the common index Figure 14 shows an example of displaying the values ​​of common indicators. Figures 14(a), 14(b), and 14(c) show examples of graphs with common indicators as axes. These graphs represent each user with each common indicator as an axis, and monitors monitor these graphs.

[0121] For example, Figure 14(a) is an example of a graph showing two types of common indicators, with common indicator 1 on the horizontal axis and common indicator 2 on the vertical axis. The display unit 105 obtains the values ​​of common indicator 1 and common indicator 2 by day, product, and user from the calculation result storage unit 104, and plots these values ​​on a graph. It is possible to display only the calculation results for a pre-specified date and product, or to display the calculation results for a date and product selected by the observer, as shown in Figure 14(a).

[0122] Figures 14(b) and 14(c) are examples of graphs showing three types of common indicators. When there are three or more types of common indicators, the graph may be displayed three-dimensionally with all the common indicators as the axes, as in Figure 14(b), or a graph may be displayed with the common indicator selected by the observer as the axis, as in Figure 14(c).

[0123] Figure 14(d) is an example of a table displaying common index values. The display unit 105 acquires the values ​​of common index 1 and common index 2 by day, product, and user from the calculation result storage unit 104, and displays these values ​​in a table. At this time, only the calculation results for a pre-specified date and product may be displayed, or the calculation results for a date and product selected by the inspector may be displayed, as in Figure 14(d). Alternatively, a table sorted by the magnitude of the value of each common index may be displayed.

[0124] In the above example, the display unit 105 displays either a graph or a table, but it may also display both. In this case, it is preferable that when the inspector selects a date and a product, the display contents of both the table and the graph are changed.

[0125] In the example of displaying a graph with common indicators as axes, it is preferable to align the scale intervals of the axes of each common indicator and display the graph in a square or cube. If the maximum value or scale interval of the axis differs for each common indicator, it will be difficult for the monitor to grasp the tendency of each user at a glance of the graph.

[0126] (Example 2) Display example showing Mahalanobis distance Next, an example will be shown in which the display unit 105 displays not only the common index but also the value used to calculate the common index. Here, an example of displaying the Mahalanobis distance when the common index is calculated using the Mahalanobis distance will be described.

[0127] An example of a Mahalanobis distance display is shown in Figure 15. After checking the values ​​of the common indicators for each user on a screen like the one shown in Figure 14 and extracting suspicious users, the monitor can then display a screen like the one shown in Figure 15 and check the values ​​used to calculate the common indicators for each user, thereby checking the details of the common indicator values ​​(calculation results).

[0128] For example, Figure 15(a) is an example of Mahalanobis distance represented by a graph with two types of detection indicators as axes. Here, the combination of detection indicators used to calculate the Mahalanobis distance is detection indicator 1 and detection indicator 2, and an example is shown in which detection indicator 1 is on the horizontal axis and detection indicator 2 is on the vertical axis. The display unit 105 obtains the values ​​of detection indicator 1, detection indicator 2 and Mahalanobis distance by day, product and user from the calculation result storage unit 104 and displays them on a graph.

[0129] When there are multiple detection indices, a three-dimensional graph with each detection indices as an axis may be displayed, as shown in Figures 14(b) and 14(c), or a graph with only the common indices selected by the observer as an axis may be displayed. However, the detection indices that can be selected are limited to those included in the combinations of detection indices stored in the calculation result storage unit 104.

[0130] Furthermore, when the detection indicator calculation step ST01 is not used, that is, when the common indicator is calculated directly from the transaction information, the Mahalanobis distance may be expressed by a graph with each item of the transaction information as an axis.

[0131] 15(b) is an example of a table displaying the Mahalanobis distance and detection index values. The display unit 105 acquires the values ​​of the Mahalanobis distance, detection index 1, and detection index 2 by day, product, and user from the calculation result storage unit 104, and displays these values ​​in a table.

[0132] By providing the fraudulent transaction monitoring device 100 with the display unit 105, the common indicators of each user can be visualized as a graph, allowing monitors to understand the transaction trends of each user. Furthermore, if the values ​​of each common indicator are displayed in a table, monitors can easily understand differences in transaction trends between users.

[0133] Furthermore, by providing the display unit 105 with a function for displaying the values ​​used in calculating the common index, the basis for the value of the common index and its connection to the transaction information can be made clear.

[0134] <Third Embodiment> The following describes a fraudulent transaction monitoring device 100 according to embodiment 3. In embodiment 3, elements that are the same as or equivalent to those described in embodiment 1 are given the same reference numerals. Therefore, their description will be omitted or simplified, and the description will focus on the differences from embodiment 1.

[0135] [Overall configuration of the fraudulent transaction monitoring device 100] Figure 16 is a configuration diagram of a fraudulent transaction monitoring device 100 according to embodiment 2. The configuration of the fraudulent transaction monitoring device 100 in Figure 16 is obtained by adding a priority order calculation unit 106 to the configuration in Figure 1. The priority order calculation unit 106 calculates, from the values ​​of the common indicators stored in the calculation result storage unit 104, at least one of the priority ranking (hereinafter referred to as "priority") or the order of precedence (hereinafter referred to as "priority order") of suspicious users that should be checked by an observer as a priority.

[0136] [Explanation of the priority order calculation unit 106] The priority order calculation unit 106 obtains the values ​​of the common indicators calculated by the common indicator calculation unit 103 from the calculation result storage unit 104, and calculates at least one of the priority and the priority order of suspicious users that should be checked by an observer based on these values. Below, an example of the operation flow of the priority order calculation unit 106 is shown, assuming that the priority order calculation unit 106 calculates the priority and the priority order by day and by product. Note that the priority and the priority order do not have to be by day, but may be by week, month, year, etc. However, the priority and the priority order cannot be calculated at a time interval shorter than the value of all the common indicators obtained in step 1.

[0137] (Example 1) How to calculate the priority order after calculating the priority Fig. 17 shows an example of an operational flow when the priority order calculation unit 106 calculates the priority order after calculating the priority. The flow in Fig. 17 includes the following steps 1 to 6. The circled numbers 1 to 6 in Fig. 17 represent steps 1 to 6, respectively.

[0138] In step 1, the priority order calculation unit 106 acquires from the calculation result storage unit 104 the values ​​of all common indices for all users calculated by the common index calculation unit 103 in the common index calculation step ST03-a or ST03-b.

[0139] In step 2, the priority order calculation unit 106 sets NUMterm, the number of periods for calculating the common indicators. NUMterm is calculated as [data period acquired in step 1] / [one data period]. For example, if the data period acquired in step 1 is seven days, one data period for calculating the priority and priority order by day and by product is one day, so NUMterm is 7.

[0140] In step 3, the priority order calculation unit 106 calculates the priorities of all users from the common index acquired in step 1. Fig. 18 shows an example of a method for calculating the priorities and priority order.

[0141] FIG. 18(a) shows an example of calculating priorities from two types of common indicators (common indicator 1, common indicator 2). Here, a threshold value Ri for the common indicator i (i = 1, 2,..., n) is set in advance, and the priority is determined based on whether the common indicator i exceeds the threshold value Ri. For example, assuming that the value of the common indicator 1 of a certain user (hereinafter referred to as "User A") is C1 A and the value of the common indicator 2 is C2 A , then based on whether C1 A exceeds R1 and whether C2 A exceeds R2, User A is classified into one of four groups.

[0142] That is, if C1 A ≥ R1 and C2 A ≥ R2, then User A is classified into Group 1 with high priority; if C1 A < R1 and C2 A ≥ R2, then User A is classified into Group 2 with medium priority; if C1 A ≥ R1 and C2 A < R2, then User A is classified into Group 3 with medium priority; if C1 A < R1 and C2 A < R2, then User A is classified into Group 4 with low priority. This is performed for all users. Here, the priority is divided into three levels: high, medium, and low, but the priority may also be two levels or four levels or more. User grouping may be performed using three or more types of common indicators. Also, the method of calculating the priority may be other methods.

[0143] The threshold value Ri may be set in advance, or the average value, median, etc. of the values of the common indicator i of all users may be used as the threshold value Ri. When the Mahalanobis distance is used in the common indicator calculation unit 103, the threshold value may be determined using the chi-square distribution.

[0144] In step 4, the priority order calculation unit 106 determines the priority order of all users based on the priorities of all users calculated in step 3. FIGS. 18(b) to (d) show examples of calculating the priority order from two types of common indicators. In this example, first, for each user, the Euclidean distance from the origin (√(C12 +C2 2 ) is calculated. Next, as shown in Figure 18(c), within the groups determined in step 2, the users are sorted in descending order of Euclidean distance from the origin. Then, as shown in Figure 18(d), each user is assigned a serial number ranging from group 1 with high priority to group 4 with low priority, and the serial numbers are used to determine the priority order of each user.

[0145] The priority order may be calculated by other methods. Here, the Euclidean distance from the origin is used, but the Euclidean distance from another point may also be used. Also, although the users are arranged in descending order of Euclidean distance within a group, the users may also be arranged in descending order of Euclidean distance within a group with the same priority (group 2 and group 3 in the example of Figure 18).

[0146] In step 5, the priority order calculation unit 106 repeats steps 3 and 4 NUMterm times.

[0147] In step 6, the priority order calculation unit 106 passes the calculation result obtained in step 5 to the calculation result storage unit 104.

[0148] This allows the order of priority to be determined while taking priority into consideration. Note that step 4 may be omitted and only priority calculated. In this case, only step 3 is repeated in step 5.

[0149] (Example 2) How to calculate priority after calculating priority order In Example 1, it was necessary to calculate the priority in order to calculate the priority order, but here we will show an example in which the priority order is calculated without using the priority order. Figure 19 is an example of an operation flow in which the priority order calculation unit 106 calculates the priority order after calculating the priority order. The flow in Figure 19 includes the following steps 1 to 6. The circled numbers 1 to 6 in Figure 19 represent steps 1 to 6, respectively.

[0150] In step 1, the priority order calculation unit 106 acquires from the calculation result storage unit 104 the values ​​of all common indices for all users calculated by the common index calculation unit 103 in the common index calculation step ST03-a or ST03-b.

[0151] In step 2, the priority order calculation unit 106 sets NUMterm, the number of periods for calculating the common indicators. NUMterm is calculated as [data period acquired in step 1] / [one data period]. For example, if the data period acquired in step 1 is seven days, one data period for calculating the priority and priority order by day and by product is one day, so NUMterm is 7.

[0152] In step 3, the priority order calculation unit 106 determines the priority order of all users based on the common index acquired in step 1. For example, the Euclidean distance (√(C1 2 +C2 2 )) is calculated, and the users are sorted in descending order of Euclidean distance. Then, users are assigned serial numbers in descending order of Euclidean distance, and this is used as the priority order. The priority order may be determined by other calculation methods. For example, when determining the priority order from two types of common indicators (common indicator 1, common indicator 2), the priority order may be determined by sorting the users in descending order of the average value of common indicator 1 value C1 and common indicator 2 value C2. Alternatively, the priority order may be determined by sorting the users in descending order of the common indicator value for each common indicator, and sorting the users in descending order of the total ranking of all common indicators.

[0153] In step 4, the priority order calculation unit 106 determines the priorities of all users based on the priority orders of all users calculated in step 3. For example, the top p numbers in the priority order are determined as high priority, and numbers p+1 to q are determined as medium priority. Other methods for determining user priorities may also be used.

[0154] In step 5, the priority order calculation unit 106 repeats steps 3 and 4 NUMterm times.

[0155] In step 6, the priority order calculation unit 106 passes the calculation result obtained in step 5 to the calculation result storage unit 104.

[0156] This allows the priority to be determined while taking the order of priority into consideration. Note that step 4 may be omitted and only the order of priority calculated. In this case, only step 3 is repeated in step 5.

[0157] By including the priority order calculation unit 106, the fraudulent transaction monitoring device 100 can calculate, from two or more common indicators, at least one of the priority or priority order of suspicious users that should be prioritized for surveillance by surveillance personnel. By checking the priority or priority order, surveillance personnel can prioritize the identification of suspicious users without having to set extraction conditions for each type of fraudulent transaction. Furthermore, when there are multiple suspicious users, surveillance personnel can prioritize the suspicious users that should be prioritized for investigation, which contributes to the efficient identification of users who have committed fraudulent transactions.

[0158] [Explanation of calculation result storage unit 104] FIG. 20 shows an example of the calculation results of the priority order calculation unit 106 stored in the calculation result storage unit 104.

[0159] When the priority order calculation unit 106 calculates both the user priority and the priority order, the calculation result storage unit 104 stores the user name, target date and time, product name, priority order, and priority as the calculation results of the priority order calculation unit 106, as shown in Figure 20(a).

[0160] When the priority order calculation unit 106 calculates only either the user priority or the priority order, the calculation result storage unit 104 stores the user name, target date and time, product name, priority order or priority order as the calculation result of the priority order calculation unit 106, as shown in Figure 20(b) or Figure 20(b).

[0161] [Explanation of display unit 105] The fraudulent transaction monitoring device 100 may include the display unit 105 shown in embodiment 2 in addition to the priority order calculation unit 106. In this case, the display unit 105 displays the calculation results of the priority order calculation unit 106 stored in the calculation result storage unit 104 on a screen.

[0162] FIG. 21 shows an example of a display on the screen of the display unit 105. Here, it is assumed that the priority order calculation unit 106 calculates the priority or priority order of users using a common index, and in the example of FIG. 21, it is assumed that the priority or priority order of each user is calculated from common index 1 and common index 2. The display unit 105 can display at least one of the priority or priority order in a table. Furthermore, when the priority and priority order of each user are calculated from multiple common indexes, the display unit 105 may display a graph that shows the value of each common index together with the priority or priority order of each user.

[0163] For example, Fig. 21(a) is a display example in the case where the priority order calculation unit 106 calculates only the priority order of users. The table in Fig. 21(a) shows the priority order of each user, with users arranged in descending order of priority. The graph in Fig. 21(a) plots the values ​​of common index 1 and common index 2 for each user, with common index 1 on the horizontal axis and common index 2 on the vertical axis, and users are shown with darker markers in descending order of priority. By representing the priority order with the shade of the markers (circular dots) on the graph, it is clearly shown where on the graph high-priority users are shown.

[0164] Fig. 21(b) is a display example in the case where the priority order calculation unit 106 calculates only the user priorities. The table in Fig. 21(b) shows the priority of each user, and the users are arranged in order from highest priority to lowest priority. The graph in Fig. 21(b) plots the values ​​of common index 1 and common index 2 for each user, with common index 1 on the horizontal axis and common index 2 on the vertical axis, and users are shown with darker markers in order of highest priority. By representing the priority by the shade of the marker on the graph, it is clearly shown where on the graph high priority users are shown.

[0165] Also, when the priority order calculation unit 106 determines the priority using a threshold value, as in the graph of FIG. 21(b), a straight line corresponding to the threshold values (R1 and R2) of each common index may be displayed on the graph. Thereby, for example, the position of the user within the priority, such as whether the user with the current priority is a user closer to a high priority or a user closer to a low priority, becomes clear. Note that the threshold value used by the priority order calculation unit 106 may be set in advance, or may be automatically determined according to the chi-square distribution when the common index calculation unit 103 uses the Mahalanobis distance.

[0166] FIG. 21(c) is a display example when the priority order calculation unit 106 calculates both the priority and the priority order of the users. In the table in FIG. 21(c), the priority and the priority order of each user are shown, and they are arranged in order from the user with the highest priority or the highest priority order. In the graph in FIG. 21(c), with the common index 1 on the horizontal axis and the common index 2 on the vertical axis, the values of the common index 1 and the common index 2 of each user are plotted.

[0167] Also, the graph in FIG. 21(c) is divided into four regions by straight lines corresponding to the threshold value R1 of the common index 1 and the threshold value R2 of the common index 2, and different backgrounds are displayed in each region according to the priority. Specifically, assuming the value of the common index 1 is C1 and the value of the common index 2 is C2, the region where C1≧R1 and C2≧R2 is the high-priority region, and the background of the high-priority region is hatched with oblique lines. The regions where C1<R1 and C2≧R2 as well as C1 A ≧R1 and C2 A <R2 are the medium-priority regions, and the backgrounds of the medium-priority regions are hatched with horizontal lines. C1 A <R1 and C2 A <R2 are the low-priority regions, and the low-priority regions are hatched with a dot pattern.

[0168] 21(a) and 21(b) show examples in which each user is displayed with a marker of a different color, all users may be displayed with the same marker color, or only the marker color of a user who meets a specific condition may be a different color from the markers of other users. Also, while the graph in FIG. 21(c) shows an example in which the background hatching is different for each region, the background of each region may be any color, for example, the background color may be different for each region.

[0169] Even when the priority order calculation unit 106 calculates only the user priority (i.e., the case of FIG. 21(b) above), the display unit 105 may display a graph such as that shown in FIG. 21(c). Also, even when the priority order calculation unit 106 calculates both the user priority and the priority order (i.e., the case of FIG. 21(c) above), the display unit 105 may display a graph such as that shown in FIG. 21(a) or 21(b). Also, the graphs in FIG. 21(b) and FIG. 21(c) do not need to display a straight line representing the threshold.

[0170] Although FIGS. 21(a), 21(b) and 21(c) show examples in which both a table and a graph are displayed, it is also possible to display only either a table or a graph.

[0171] When both a table and a graph are displayed, the table and the graph may be linked. For example, when an observer selects a user to be checked on the graph, the display range of the table may be automatically changed so that the priority or prioritization of the selected user can be confirmed. Conversely, when an observer selects a row of a user to be checked in the table, the marker of the selected user may be made to flash or the color, size, or shape of the marker of the selected user may be changed so that the marker of the selected user stands out in the graph.

[0172] Furthermore, after the monitor checks the screen of Fig. 21(a), Fig. 21(b) or Fig. 21(c), the monitor may be able to transition to a Mahalanobis distance display screen as shown in Fig. 15, for example, so that the monitor can check details of users with high priority or ranking. Also, the monitor may be able to transition to a screen such as Fig. 25 or Fig. 26, which are display examples described later.

[0173] In this way, by display unit 105 visualizing a graph with the common indicator as an axis, monitors can grasp the trends of users with high priorities or priority rankings. Furthermore, monitors can determine the order of users to check based on the user trends, which contributes to reducing the workload of monitors. Furthermore, by displaying the user priorities or priority rankings in a table, monitors can easily grasp which users they should start with, which also contributes to reducing the workload of monitors.

[0174] <Fourth Embodiment> The following describes a fraudulent transaction monitoring device 100 according to embodiment 4. In embodiment 4, elements that are the same as or equivalent to those described in embodiment 1 are given the same reference numerals. Therefore, their description will be omitted or simplified, and the description will focus on the differences from embodiment 1.

[0175] When a monitor identifies a suspicious user based on the value of each user's common index calculated by the common index calculation unit 103 of the fraudulent transaction monitoring device 100, the monitor then checks the facts of the suspicious user. In this case, prior to checking the facts, the monitor needs to check in detail why the suspicious user is classified as a suspicious user.

[0176] An example of a means for performing detailed confirmation is the "example of display showing Mahalanobis distance" described in the second embodiment using FIG. 15. In other words, an observer can confirm the details of the value of the common index by checking not only the common index but also the value used to calculate the common index (in this example, the Mahalanobis distance). In reality, however, a large number of values ​​are used to calculate the common index, and checking all of them increases the workload of the observer. In particular, when there are multiple common indexes, the observer must check the values ​​used to calculate each common index, further increasing the workload. In the fourth embodiment, we propose a fraudulent transaction monitoring device 100 that can solve this problem.

[0177] [Overall configuration of the fraudulent transaction monitoring device 100] Figure 22 is a configuration diagram of a fraudulent transaction monitoring device 100 according to embodiment 4. The configuration of the fraudulent transaction monitoring device 100 in Figure 22 is obtained by adding a recommendation order calculation unit 107 to the configuration in Figure 1. When an observer checks the details of a suspicious user, the recommendation order calculation unit 107 determines and recommends the common indicator value or value to be used when calculating the common indicator that should be checked first, from among the values ​​of multiple common indicators or values ​​to be used when calculating multiple common indicators.

[0178] [Explanation of recommendation order calculation unit 107] The recommendation order calculation unit 107 acquires the values ​​of the common indices calculated by the common index calculation unit 103 from the calculation result storage unit 104, and calculates the recommendation order of the common indices that should be checked preferentially in order to check the details of the common indices.

[0179] In the following, an example of the operation of the recommendation order calculation unit 107 will be described, assuming that the common index calculation unit 103 calculates the value of the common index for each user, each day, and each product. Note that the recommendation order may not be by day, but may be by week, month, year, etc. However, the recommendation order cannot be calculated at a finer time interval than the values ​​acquired in step 1 (values ​​of all common indexes, values ​​of Mahalanobis distances, and values ​​of common indexes).

[0180] (Example 1) Example of calculating the recommendation order of common indicators When there are multiple common indicators, checking the values ​​of all of the common indicators imposes a workload on the observer, so the recommendation order calculation unit 107 recommends values ​​of common indicators that should be checked with priority. Fig. 23 shows an example of the operation flow when the recommendation order calculation unit 107 calculates the recommendation order of common indicators. The flow in Fig. 23 includes the following steps 1 to 7. The circled numbers 1 to 7 in Fig. 23 represent steps 1 to 7, respectively.

[0181] In step 1, the recommendation order calculation unit 107 acquires from the calculation result storage unit 104 the values ​​of all common indices for all users calculated by the common index calculation unit 103 in the common index calculation step ST03-a or ST03-b.

[0182] In step 2, the recommendation order calculation unit 107 sets NUMterm, the number of periods for calculating the recommendation order. NUMterm is calculated as [data period acquired in step 1] / [one data period]. One data period is set according to the calculation method in step 4. For example, if the data period acquired in step 1 is seven days and one data period is one day, NUMterm is 7.

[0183] In step 3, the recommendation order calculation unit 107 sets the number of users NUMuser for which the recommendation order is to be calculated. NUMuser may be set based on the information acquired in step 1, or may be set in advance.

[0184] In step 4, the recommendation order calculation unit 107 calculates the recommendation order of common indicators that should be checked preferentially among the values ​​of each common indicator of a certain user (hereinafter assumed to be "user A") based on the value of the common indicator acquired in step 1. For example, the recommendation order of the common indicators may be determined in descending order of the common indicator value.

[0185] The [Data Period for One Time] in Step 2 above indicates how often the recommendation order is calculated. Here, since common indicators are calculated by user, day, and product, the recommendation order is calculated by day. Therefore, the [Data Period for One Time] in Step 2 is one day.

[0186] In step 5, the recommendation order calculation unit 107 repeats step 4 for NUMusers.

[0187] In step 6, the recommendation order calculation unit 107 repeats step 5 NUMterm times.

[0188] In step 7, the recommendation order calculation unit 107 passes the calculation result of step 6 to the calculation result storage unit 104.

[0189] (Example 2) Example of calculating the recommended order of values ​​used when calculating common indicators When the common index calculation unit 103 calculates the value of the common index using the Mahalanobis distance, it can be said that a combination of detection indices with a large Mahalanobis distance includes detection indices for a certain user (hereinafter assumed to be "user A") whose trends deviate from those of other users. Therefore, the recommendation order calculation unit 107 determines the recommendation order of the combination of detection indices using the Mahalanobis distance for each combination of detection indices for user A, which is the calculation result of the Mahalanobis distance calculation step ST02-b.

[0190] In this case as well, the operation flow of the recommendation order calculation unit 107 is basically the same as that of Fig. 23. Below, the operation of the recommendation order calculation unit 107 when determining the recommendation order of combinations of detection indicators will be described while appropriately replacing Fig. 23.

[0191] In step 1, the recommendation order calculation unit 107 acquires from the calculation result storage unit 104 the Mahalanobis distance values ​​for each combination of detection indices of all users calculated in the Mahalanobis distance calculation step ST02-b of the common index calculation unit 103.

[0192] In step 2, the recommendation order calculation unit 107 sets NUMterm, the number of periods for calculating the recommendation order. NUMterm is calculated as [data period acquired in step 1] / [one data period]. One data period is set according to the calculation method in step 4. For example, if the data period acquired in step 1 is seven days and one data period is one day, NUMterm is 7.

[0193] In step 3, the recommendation order calculation unit 107 sets the number of users NUMuser for which the recommendation order is to be calculated. NUMuser may be set based on the information acquired in step 1, or may be set in advance.

[0194] In step 4, the recommendation order calculation unit 107 calculates the recommendation order of combinations of detection indicators that should be checked preferentially based on the Mahalanobis distance values ​​for each combination of detection indicators of a certain user (hereinafter assumed to be "User A") on a certain day in step 1. For example, the recommendation order of common indicators may be determined in descending order of Mahalanobis distance.

[0195] The [Data Period for One Time] in Step 2 above indicates the period over which the recommendation order is calculated. Here, the common indicators are calculated by user, day, and product, and the Mahalanobis distance is also calculated by user, day, and product. Therefore, the recommendation order is calculated by day. In other words, the [Data Period for One Time] in Step 2 is one day.

[0196] In step 5, the recommendation order calculation unit 107 repeats step 4 for NUMusers.

[0197] In step 6, the recommendation order calculation unit 107 repeats step 5 NUMterm times.

[0198] In step 7, the recommendation order calculation unit 107 passes the calculation result of step 6 to the calculation result storage unit 104.

[0199] (Example 3) Example of calculating recommendation order using deviation When the common indicator calculation unit 103 calculates the "deviation degree", which is one of the common indicators, the recommendation order can be calculated using the deviation degree. Here, as in the "example of deviation degree" described in the first embodiment, the common indicator calculation unit 103 calculates (X1 A ,X2 A ), (X1 A ,X3 A ) and calculate the deviation from each vector.

[0200] In this case as well, the operation flow of the recommendation order calculation unit 107 is basically the same as that in Fig. 23. Hereinafter, the operation when the recommendation order calculation unit 107 determines the recommendation order using the deviation degree will be described, with appropriate changes made to Fig. 23.

[0201] In step 1, the recommendation order calculation unit 107 acquires the deviation degrees of all users calculated by the common index calculation unit 103 from the calculation result storage unit 104.

[0202] In step 2, the recommendation order calculation unit 107 sets NUMterm, the number of periods for calculating the recommendation order. NUMterm is calculated as [data period acquired in step 1] / [one data period]. One data period is set according to the calculation method in step 4. For example, if the data period acquired in step 1 is seven days and one data period is one day, NUMterm is 7.

[0203] In step 3, the recommendation order calculation unit 107 sets the number of users NUMuser for which the recommendation order is to be calculated. NUMuser may be set based on the information acquired in step 1, or may be set in advance.

[0204] In step 4, the recommendation order calculation unit 107 calculates a recommendation order of combinations of detection indicators that should be checked with priority based on an arbitrary number of deviation degrees of a certain user (hereinafter assumed to be "user A") on a certain day in step 1. For example, the recommendation order of combinations of detection indicators may be determined in descending order of deviation degrees.

[0205] The [Data Period for One Time] in Step 2 above indicates the period over which the recommendation order is calculated. Here, the common indicators are calculated by user, day and product, and the deviation is also calculated by user, day and product. Therefore, the recommendation order is calculated by day. In other words, the [Data Period for One Time] in Step 2 is one day.

[0206] In step 5, the recommendation order calculation unit 107 repeats step 4 for NUMusers.

[0207] In step 6, the recommendation order calculation unit 107 repeats step 5 NUMterm times.

[0208] In step 7, the recommendation order calculation unit 107 passes the calculation result of step 6 to the calculation result storage unit 104.

[0209] By providing the fraudulent transaction monitoring device 100 with the recommendation order calculation unit 107, monitors can easily grasp the recommended order of common indicators that should be checked first or the values ​​used to calculate the common indicators, allowing them to quickly conduct detailed checks on suspicious users. Furthermore, among the values ​​used to calculate the common indicators (e.g., Mahalanobis distance), it is possible to know which values ​​should be checked first. By checking the combinations of detection indicators that are ranked high in the recommendation order, monitors can efficiently conduct detailed checks on suspicious users.

[0210] In addition, if the fraudulent transaction monitoring device 100 is equipped with the priority order calculation unit 106 shown in embodiment 3 in addition to the recommendation order calculation unit 107, the priority order calculation unit 106 may calculate the priority or priority order of suspicious users based on the recommendation order calculated by the recommendation order calculation unit 107.

[0211] [Explanation of calculation result storage unit 104] FIG. 24 shows an example of the calculation results of the recommendation order calculation unit 107 stored in the calculation result storage unit 104.

[0212] When the common index calculation unit 103 calculates the value of the common index by user, by day, and by product, the calculation result storage unit 104 stores the user name, target date and time, product name, common index number, and recommendation order of the common index as the calculation results of the recommendation order calculation unit 107, as shown in Figure 24.

[0213] When the recommendation order calculation unit 107 calculates the recommendation order of values ​​used when calculating common indicators (such as the recommendation order of combinations of detection indicators) instead of the recommendation order of common indicators, the calculation result storage unit 104 stores the combination numbers of detection indicators instead of the common indicator numbers in Figure 24.

[0214] [Explanation of display unit 105] The fraudulent transaction monitoring device 100 may include the display unit 105 described in embodiment 2 in addition to the recommendation order calculation unit 107. In this case, the display unit 105 displays the calculation results of the recommendation order calculation unit 107 stored in the calculation result storage unit 104 on a screen.

[0215] (Example 1) Example of recommended order of common indicators Figure 25 shows an example of the display of the recommendation order of common indicators for a certain user (assumed to be "User A"). The table in Figure 25 displays the recommendation order, the name of the common indicator, and the value of the common indicator. Although the value of the common indicator is displayed in Figure 25, it does not have to be displayed. The monitor checks this table and, based on the common indicators with high recommendation orders, clarifies the detailed reasons why a suspicious user is classified as a suspicious user.

[0216] (Example 2) Example of the recommended order of values ​​used when calculating common indicators FIG. 26 shows an example of a display of the recommendation order of values ​​used when calculating the common index for a certain user (assumed to be "User A").

[0217] In this example, the Mahalanobis distance is used as the value used to calculate the common indicator. A combination of detection indicators with a large Mahalanobis distance can be said to include detection indicators whose trends for a user deviate from those of other users. Therefore, the Mahalanobis distance for each combination of detection indicators for user A is used to determine the recommendation order for the combination of detection indicators.

[0218] The recommended order and combinations of detection indices are shown in the table of Fig. 26. The observer can decide the combination of detection indices that he or she wants to check by taking into consideration the recommended order in this table.

[0219] Furthermore, in the table of FIG. 26, when the monitor clicks the "Select" button to select the combination of detection indicators that he or she wishes to check, a graph is displayed with the selected combination of detection indicators as the axis. For example, if the combination of detection indicators is detection indicator 1 and detection indicator 2, a graph is displayed with detection indicator 1 on the horizontal axis and detection indicator 2 on the vertical axis. Detection indicator 1 may also be on the vertical axis and detection indicator 2 on the horizontal axis. This graph displays a marker (circular dot) for each user. In FIG. 26, the black marker indicates user A, and the white markers indicate other users. By displaying such a graph, the degree of deviation in the trends between user A and other users is visualized.

[0220] The graph in FIG. 26 is equivalent to the graph of the Mahalanobis distance calculation example shown in FIG. 7, in which X1 is considered to be the cancellation amount and X2 is considered to be the bid amount. The graph in FIG. 26 only displays the markers of each user, but the center of other users (data group) may also be displayed as in the graph in FIG. 7. The graph in FIG. 26 may also be color-coded to indicate priority or order of precedence, similar to the graph shown in FIG. 21. Furthermore, like the table in FIG. 25, the table in FIG. 26 may also display Mahalanobis distance values. When the table in FIG. 26 displays Mahalanobis distance values, contour lines of the Mahalanobis distance may be displayed on the graph so that the Mahalanobis distance can be understood.

[0221] In addition, if the common indicator calculation unit 103 does not calculate detection indicators (if the detection indicator calculation step ST01 is not used), a table showing the recommended order of combinations of transaction information items and a graph with the selected combination of transaction information items as the axis may be displayed.

[0222] Furthermore, when a user is selected on the common index value display screen as shown in FIG. 14, the screen may transition to the screen shown in FIG. 25 or 26, which shows the recommendation order of the selected user.

[0223] If the fraudulent transaction monitoring device 100 is equipped with a priority order calculation unit 106 in addition to the recommendation order calculation unit 107, when a user is selected on a screen displaying user priorities or priority orders such as that shown in Figure 21, the screen may transition to the screen shown in Figure 25 or Figure 26, which shows the recommendation order of the selected user. For example, when the marker for user A displayed on the graph in Figure 21 is clicked, the screen may transition to the screen shown in Figure 25 or Figure 26. This allows the monitor to quickly check the details of users with high priorities or priority orders.

[0224] In this way, by displaying the recommendation order calculated by the recommendation order calculation unit 107 on the display unit 105, the monitor can quickly grasp the common indicators that should be checked first or the recommendation order of values ​​used when calculating the common indicators. Also, by displaying a graph with the combination of detection indicators as the axis, the monitor can grasp the Mahalanobis distance, which is one of the values ​​used when calculating the common indicators, that is, the degree of deviation in the trends between a certain user and other users. These lead to a quick detailed check of suspicious users.

[0225] <Fifth Embodiment> The following describes a fraudulent transaction monitoring device 100 according to embodiment 5. In embodiment 5, elements that are the same as or equivalent to those described in embodiment 1 are given the same reference numerals. Therefore, their description will be omitted or simplified, and the description will focus on the differences from embodiment 1.

[0226] [Overall configuration of the fraudulent transaction monitoring device 100] Figure 27 is a configuration diagram of a fraudulent transaction monitoring device 100 according to embodiment 5. The configuration of the fraudulent transaction monitoring device 100 in Figure 27 is obtained by adding, to the configuration in Figure 1, an index storage unit 108 that stores information about the indexes used by the common index calculation unit 103, and an index setting unit 109 that can set information about the indexes stored in the index storage unit 108.

[0227] [Explanation of the index storage unit 108] The index storage unit 108 stores information on indices used in the common index calculation unit 103. Specifically, the common index calculation unit 103 stores information on the detection indices used in the detection index calculation step ST01 (hereinafter referred to as "detection index information"), information on the combination of detection indices used in the Mahalanobis distance calculation step ST02-b (hereinafter referred to as "detection index combination information"), and information on the common index used in the common index calculation step ST03-a or ST03-b (hereinafter referred to as "common index information").

[0228] FIG. 28 shows an example of information stored in the index storage unit 108. FIG. 28(a) is an example of detection index information stored in the index storage unit 108. The index storage unit 108 stores, as detection index information, the detection index number of the detection index, the detection index name, the transaction information to be used, the aggregation unit, the aggregation period, the calculation formula, and the like. In the example of FIG. 28(a), a detection index called "daily bid volume" is stored as the detection index with detection index number "1." In this example, the detection index "daily bid volume" is specified as being calculated by averaging the bid volume for one day on a target date by user, by product, and by day, using the items of date and time, user name, product name, and bid volume in the transaction information stored in the transaction information storage unit 102.

[0229] The number of transaction information items used to calculate the detection indicators may be one or more. In the example of Figure 28(a), the calculation formula is written in SQL (Structured Query Language) or a program-like expression, but it may also be written in human language, such as "average the bid volume."

[0230] The detection index may be calculated using not only transaction information but also user information. For example, the detection index may be calculated using the bid volume, which is one piece of transaction information, and the amount of electricity sold, which is one piece of user information, by the formula bid volume / amount of electricity sold, and stored in the index storage unit 108.

[0231] FIG. 28(b) is an example of combination information of detection indicators stored in the indicator storage unit 108. In the Mahalanobis distance calculation step ST02-b of the common indicator calculation unit 103, a Mahalanobis distance is calculated from a combination of one or more types of detection indicators. Therefore, the indicator storage unit 108 stores, as combination information of detection indicators, the combination number of detection indicators, the number of types of detection indicators to be used, the detection indicator numbers of the detection indicators to be used, etc. In the example of FIG. 28(b), the combination of detection indicators with combination number "1" is specified as using two types of detection indicators, namely, "daily bid volume," which is the detection indicator with detection indicator number "1," and "daily number of bids," which is the detection indicator with detection indicator number "2."

[0232] 28(b) shows an example in which the number of types of detection indices used is "2", but the number of types of detection indices used may be one or three or more. However, the number of types of detection indices used cannot exceed the number of detection indices stored as detection indices information.

[0233] The combination information of detection indices may be set in advance, or may be added or modified by an observer. The observer can add or modify the combination information of detection indices using the index setting unit 109, which will be described later.

[0234] FIG. 28(c) is an example of common indicator information stored in the indicator storage unit 108. The indicator storage unit 108 stores, as common indicator information, the common indicator number of the common indicator, the common indicator name, the detection indicator number to be used, the combination number of the detection indicators to be used, and a calculation formula. Only one of the detection indicator number to be used and the combination number of the detection indicators to be used may be stored. In the example of FIG. 28(c), the common indicator with common indicator number "1" has the common indicator name "deviation" and is specified as being found by calculating the maximum value of the detection indicator combination numbers "1" to "10."

[0235] In the example of FIG. 28(c), the calculation formula is written in a manner similar to SQL or a program, but it may also be written in human language such as "average the bid volume."

[0236] By equipping the fraudulent transaction monitoring device 100 with the indicator storage unit 108, it is possible to set multiple indicators to be used by the common indicator calculation unit 103. This allows for more flexible preparation of detection indicators, combinations of detection indicators, and common indicators, which can contribute to the extraction of suspicious users.

[0237] Furthermore, by having the index storage unit 108 store information on detection indices that utilize not only transaction information but also user information, it becomes possible to utilize transaction information that is tailored to the scale of each user.

[0238] Furthermore, by storing information on combinations of detection indices in the index storage unit 108, it is possible to calculate only combinations of detection indices that can be used for common index information from all combinations.

[0239] [Explanation of the indicator setting unit 109] The index setting unit 109 displays on the screen the detection index information, the combination information of detection indices, and the common index information stored in the index storage unit 108, and can set the information stored in the index storage unit 108 in response to operations by the observer. Based on the information displayed on the screen by the index setting unit 109, the observer can confirm, modify, or add the detection index information, the combination information of detection indices, and the common index information.

[0240] (Example 1) Example of displaying and setting detection indicator information An example of a confirmation screen and a setting screen for detection index information is shown in Fig. 29. Hereinafter, display and setting of detection index information by the index setting unit 109 will be described with reference to Fig. 29.

[0241] FIG. 29(a) is an example of a confirmation screen for detection indicator information. This confirmation screen displays the detection indicator number, detection indicator name, and detection indicator formula as detection indicator information. For example, to delete a detection indicator, select the check box in the deletion column for the detection indicator you want to delete and press the "Delete" button, and the information for the selected detection indicator will be deleted from the indicator storage unit 108. To modify a detection indicator, select the detection indicator you want to modify and press the "Modify" button. This will take you to a settings screen like the one in FIG. 29(b), where you can modify the detection indicator information, such as changing the name or formula of the selected detection indicator. To add a detection indicator, press the "+" button at the bottom left of the confirmation screen. In this case, you will also be taken to a settings screen like the one in FIG. 29(b), where you can set a new detection indicator.

[0242] The setting screen in Figure 29(b) is an example of what happens when the "Edit" button for detection indicator number "3" (not shown in Figure 29(a)) is pressed on the confirmation screen. On the setting screen, you can edit the name and formula of the detection indicator. The formula is created by combining the transaction information to be used (time interval, transaction information items, aggregation method) and calculation symbols (+ - × ÷, etc.).

[0243] The time interval for the transaction information to be used may be, for example, by transaction, by time, by n hours, by day, by week, or by month. The item of transaction information to be used may be selected from the items of transaction information stored in the transaction information acquisition unit 101. The aggregation method for the transaction information to be used may be, for example, sum, average, median, maximum, or minimum. On the setting screen in Figure 29(b), formulas are written in human language to make it easier for the monitor to set up, but it is also possible to input formulas in expressions similar to SQL or programs. Once the modifications are complete and the "Confirm" button at the bottom right of the setting screen is pressed, the detection indicator information stored in the indicator storage unit 108 is updated.

[0244] (Example 2) Example of displaying and setting combination information of detection indicators An example of a confirmation screen and a setting screen for combination information of detection indices is shown in Fig. 30. Hereinafter, the display and setting of combination information of detection indices by the index setting unit 109 will be described with reference to Fig. 29.

[0245] FIG. 30(a) is an example of a confirmation screen for combination information of detection indices. This confirmation screen displays the combination information of detection indices, including the combination number of the detection indices, the combination name of the detection indices, and the detection indices to be used. In FIG. 30(a), a maximum of two types of detection indices are displayed. However, if three or more types of detection indices are used, three or more types of detection indices are displayed. For example, to delete a combination of detection indices, select the check box in the deletion column for the combination of detection indices you want to delete and press the "Delete" button. The selected combination of detection indices is then deleted from the index storage unit 108. To modify the combination of detection indices, select the combination of detection indices you want to modify and press the "Modify" button. This will take you to a settings screen like that shown in FIG. 30(b), where you can modify the combination of detection indices, such as by changing the name or formula of the selected combination of detection indices. To add a combination of detection indices, press the "+" button at the bottom left of the confirmation screen. In this case, you will also be taken to a settings screen like that shown in FIG. 30(b), where you can set the new combination of detection indices.

[0246] The setting screen in Figure 30(b) is an example of what happens when the "Edit" button for indicator combination number "1" is pressed on the confirmation screen. On the setting screen, you can edit the name of the indicator combination and the indicators to be used.

[0247] The detection indices to be used consist of a combination and an additional detection indices. For example, by using the selection box on the setting screen to select one of the detection indices that can be confirmed on the confirmation screen of FIG. 29(a) as the detection indices to be added, and pressing the "OK" button, the selected detection indices are added to the combination of detection indices. After completing the corrections, pressing the "OK" button at the bottom right of the setting screen updates the combination information of detection indices stored in the index storage unit 108.

[0248] (Example 3) Example of displaying and setting combination information of detection indicators An example of a confirmation screen and a setting screen for common index information is shown in Fig. 31. Hereinafter, the display and setting of common index information by the index setting unit 109 will be described with reference to Fig. 31.

[0249] FIG. 31(a) is an example of a confirmation screen for common indicator information. This confirmation screen displays the common indicator number, common indicator name, and formula of the common indicator as the common indicator information. For example, to delete a common indicator, select the check box in the deletion column for the common indicator you want to delete and press the "Delete" button, and the information for the selected common indicator will be deleted from the indicator storage unit 108. To modify a common indicator, select the common indicator you want to modify and press the "Modify" button. This will take you to a settings screen like that shown in FIG. 31(b), where you can modify the common indicator information, such as changing the name or formula of the selected common indicator. To add a common indicator, press the "+" button at the bottom left of the confirmation screen. In this case, you will also be taken to a settings screen like that shown in FIG. 31(b), where you can set a new common indicator.

[0250] The setting screen in Figure 31(b) is an example of what happens when the "Edit" button for the common indicator with common indicator number "1" is pressed on the confirmation screen. The setting screen allows the name and formula of the common indicator to be modified. The formula is created by combining the combination information of the detection indicators to be used with calculation symbols. The combination information of the detection indicators to be used is selected from those that can be confirmed on the confirmation screen in Figure 30(a) using the selection box on the setting screen. On the setting screen in Figure 31(b), formulas are written in human language to make it easier for the monitor to set them, but it is also possible to input calculation formulas in expressions similar to SQL or programs. Once the modifications are complete and the "Confirm" button at the bottom right of the setting screen is pressed, the common indicator information stored in the index storage unit 108 is updated.

[0251] The indicator setting unit 109 displays the detection indicator information, the combination of detection indicators, and the common indicator information stored in the indicator storage unit 108, allowing the monitor to set the detection indicator information, the combination of detection indicators, and the common indicator information based on the displayed information. This allows the monitor's knowledge to be reflected in the information, which can contribute to the extraction of suspicious users.

[0252] <Hardware configuration example> 32 and 33 are diagrams illustrating examples of the hardware configuration of the fraudulent transaction monitoring device 100. The functions of the components of the fraudulent transaction monitoring device 100 illustrated in FIG. 1 and elsewhere are realized, for example, by a processing circuit 200 illustrated in FIG. 32. Specifically, the fraudulent transaction monitoring device 100 acquires transaction information from a trading market, stores the acquired transaction information, calculates a common index for each user based on the transaction information, which is an index used to identify suspicious users who have engaged in potentially fraudulent transactions and is comparable regardless of the type of fraudulent transaction, and stores the calculation results of the common index. The processing circuit 200 may be dedicated hardware, or may be configured using a processor (also referred to as a central processing unit (CPU), processing device, arithmetic unit, microprocessor, microcomputer, or DSP (Digital Signal Processor)) that executes a program stored in memory.

[0253] When the processing circuit 200 is dedicated hardware, the processing circuit 200 may be, for example, a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a combination thereof. The functions of the components of the fraudulent transaction monitoring device 100 may be realized by individual processing circuits, or these functions may be realized together by a single processing circuit.

[0254] FIG. 33 shows an example of the hardware configuration of the fraudulent transaction monitoring device 100 when the processing circuit 200 is configured using a processor 201 that executes a program. In this case, the functions of the components of the fraudulent transaction monitoring device 100 are realized by software, etc. (software, firmware, or a combination of software and firmware). The software, etc. is written as a program and stored in memory 202. The processor 201 realizes the functions of each unit by reading and executing the program stored in memory 202. That is, the fraudulent transaction monitoring device 100 includes memory 202 for storing a program that, when executed by the processor 201, results in the following: acquiring transaction information from the trading market; storing the acquired transaction information; calculating, for each user, a common index that is used to identify suspicious users who have engaged in potentially fraudulent transactions based on the transaction information and is comparable regardless of the type of fraudulent transaction; and storing the calculation results of the common index. In other words, this program can be said to cause a computer to execute the procedures and methods of the operation of the components of the fraudulent transaction monitoring device 100.

[0255] Here, the memory 202 may be, for example, a non-volatile or volatile semiconductor memory such as RAM (Random Access Memory), ROM (Read Only Memory), flash memory, EPROM (Erasable Programmable Read Only Memory), EEPROM (Electrically Erasable Programmable Read Only Memory), HDD (Hard Disk Drive), magnetic disk, flexible disk, optical disk, compact disk, mini disk, DVD (Digital Versatile Disc) and its drive device, or any other storage medium that will be used in the future.

[0256] The above describes a configuration in which the functions of the components of the fraudulent transaction monitoring device 100 are realized either by hardware or software, etc. However, this is not limited to this, and the configuration may be such that some of the components of the fraudulent transaction monitoring device 100 are realized by dedicated hardware and other components are realized by software, etc. For example, the functions of some components may be realized by the processing circuit 200 as dedicated hardware, and the functions of other components may be realized by the processing circuit 200 as the processor 201 reading and executing a program stored in the memory 202.

[0257] As described above, the fraudulent transaction monitoring device 100 can realize each of the above-mentioned functions by hardware, software, or a combination of these.

[0258] It is possible to freely combine the embodiments, and to modify or omit the embodiments as appropriate. [Explanation of symbols]

[0259] 100 Fraudulent transaction monitoring device, 101 Transaction information acquisition unit, 102 Transaction information storage unit, 103 Common index calculation unit, 104 Calculation result storage unit, 105 Display unit, 106 Priority order calculation unit, 107 Recommendation order calculation unit, 108 Index storage unit, 109 Index setting unit, 200 Processing circuit, 201 Processor, 202 Memory.

Claims

1. a trading information acquisition unit that acquires trading information of each user in the trading market; a transaction information storage unit that stores the transaction information acquired by the transaction information acquisition unit; a common index calculation unit that calculates, for each user, a common index that is an index for extracting suspicious users who have engaged in potentially fraudulent transactions based on the transaction information stored in the transaction information storage unit, the common index being a comparable common index regardless of the type of fraudulent transaction, and including at least one of the degree of deviation from other users or the degree of impact on market price; a calculation result storage unit that stores the calculation result of the common index calculated by the common index calculation unit; a display unit that displays the calculation results of the common index stored in the calculation result storage unit for each user; A fraudulent transaction monitoring device comprising:

2. the common indicator calculation unit calculates the common indicators of users who are buyers and the common indicators of users who are sellers separately; The fraudulent transaction monitoring device of claim 1.

3. the common index calculation unit uses a Mahalanobis distance from other users when calculating the common index of each user; 3. The fraudulent transaction monitoring device according to claim 1 or 2.

4. a priority order calculation unit that acquires the value of the common indicator for each user from the calculation result storage unit and calculates at least one of the priority or the priority order of suspicious users that should be checked by an observer on a priority basis based on the value of the common indicator for each user; The fraudulent transaction monitoring device according to any one of claims 1 to 3.

5. a recommendation order calculation unit that acquires the value of the common index of each user from the calculation result storage unit and calculates a recommendation order of the common indexes that should be checked preferentially by an observer based on the value of the common index of each user; The fraudulent transaction monitoring device according to any one of claims 1 to 4.

6. The common indicator of each user includes a deviation from other users, the recommendation order calculation unit calculates the recommendation order based on a degree of deviation between each user included in the common index and other users; 6. The fraudulent transaction monitoring device according to claim 5.

7. an index storage unit that stores information on the indexes used in the common index calculation unit; An index setting unit capable of setting information on the indexes stored in the index storage unit, The fraudulent transaction monitoring device according to any one of claims 1 to 6.

8. a trading information acquisition unit that acquires trading information of each user from a trading market via a network; a transaction information storage unit that stores the transaction information acquired by the transaction information acquisition unit; a common index calculation unit that calculates, for each user, a common index that is an index for extracting suspicious users who have engaged in potentially fraudulent transactions based on the transaction information stored in the transaction information storage unit, the common index being a comparable common index regardless of the type of fraudulent transaction, and including at least one of the degree of deviation from other users or the degree of impact on market price; a calculation result storage unit that stores the calculation result of the common index calculated by the common index calculation unit; a display unit that displays the calculation results of the common index stored in the calculation result storage unit for each user; A fraudulent transaction monitoring system.

9. a transaction information acquisition step in which a transaction information acquisition unit of the fraudulent transaction monitoring device acquires transaction information of each user in the trading market; a common index calculation step in which the common index calculation unit of the fraudulent transaction monitoring device calculates, for each user, a common index that is an index for extracting suspicious users who have engaged in potentially fraudulent transactions based on the transaction information, the common index being a common index that can be compared regardless of the type of fraudulent transaction, and that includes at least one of the degree of deviation from other users or the degree of impact on market price; a display step in which a display unit of the fraudulent transaction monitoring device displays the calculation results of the common indicator for each user; A fraudulent transaction monitoring method comprising:

Citation Information

Patent Citations

  • Purchase order receiving system and purchase order receiving method

    JP2008021141A

  • Securities transaction extraction device, securities transaction extraction method, and program thereof

    JP2010146093A

  • Illegal transaction detection system

    JP2016015000A

  • Intelligent alert system

    WO2020167691A1