Monitoring device, monitoring method, and program
The monitoring device expands the scope of users monitored in electronic payment systems by analyzing network communication and remittance history, effectively identifying a broader range of potential fraudulent users.
Patent Information
- Application Number
- JP2025045941
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-12-22
- Estimated Expiration
- 2045-03-19
AI Technical Summary
Existing fraud prevention systems in electronic payment services only monitor a limited range of users suspected of fraud and do not effectively expand the scope of users to be monitored.
A monitoring device that acquires network communication information and user-to-user remittance history of fraudulent users, extracts users to be monitored, and stores them in a memory unit, allowing for a broader range of users to be identified as potential fraudulent actors.
Enables the appropriate expansion of the number of users monitored, enhancing fraud detection capabilities in electronic payment systems.
Smart Images

Figure 0007789973000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a monitoring device, a monitoring method, and a program. [Background technology]
[0002] Conventionally, in electronic payment services, an invention has been disclosed in which flag information indicating whether a user is suspected of fraud is stored in association with identification information assigned to the user suspected of fraud, the identification information of the recipient user transmitted from the device used by the recipient user in response to the operation of the link information is acquired, the acquired identification information of the recipient user is compared with the identification information stored in the flag information storage unit, and if flag information indicating that the user is suspected of fraud is associated with the identification information of the recipient user, the recipient user is presumed to be a user suspected of fraud (Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent No. 7583203 Summary of the Invention [Problem to be solved by the invention]
[0004] The invention described in Patent Document 1 was made with the aim of preventing remittances to fraudulent users in advance, and no consideration was given to expanding the range of users who are suspected of being fraudulent and are subject to monitoring.
[0005] The present invention has been made in consideration of the above circumstances, and one of its objects is to provide a monitoring device, a monitoring method, and a program that can appropriately expand the number of users to be monitored. [Means for solving the problem]
[0006] One aspect of the present invention is a monitoring device that includes an acquisition unit that acquires network communication information of fraudulent users who commit fraudulent acts among users who use network services including electronic payments, and at least one of the user-to-user remittance history of the fraudulent users, and an extraction unit that extracts users to be monitored based on at least one of the network communication information and the user-to-user remittance history, and stores the extracted users in a memory unit. [Effects of the Invention]
[0007] According to one aspect of the present invention, it is possible to appropriately expand the users to be monitored. [Brief explanation of the drawings]
[0008] [Figure 1] FIG. 1 illustrates basic aspects of brick-and-mortar electronic payment. [Figure 2] FIG. 1 is a diagram illustrating an example of a configuration for performing electronic payment (terminal payment) using a payment application. [Figure 3] FIG. 10 is a diagram showing an example of the contents of user information 172. [Figure 4] FIG. 10 is a diagram showing an example of the contents of affiliated store / shop information 174. [Figure 5] FIG. 10 is a diagram showing an outline of a processing flow when a user scan is performed. [Figure 6] FIG. 10 is a diagram showing an outline of the processing flow when a store scan is performed. [Figure 7] FIG. 1 is a diagram showing an example of a configuration for performing electronic payment (card payment) using a payment card. [Figure 8] 1 is a diagram illustrating an example of the configuration and usage environment of a monitoring device 300. FIG. [Figure 9] 10 is a flowchart showing an example of the flow of processing executed by the monitoring device 300. [Figure 10] This diagram illustrates the users to be monitored who are identified in steps S102 to S104. [Figure 11] 10 illustrates the users to be monitored extracted in S106. [Figure 12] 10 illustrates the users to be monitored extracted in S108. [Figure 13] FIG. 10 is a diagram schematically illustrating the content of the process in S112. DETAILED DESCRIPTION OF THE INVENTION
[0009] [overview] Hereinafter, with reference to the drawings, embodiments of a monitoring device, a monitoring method, and a program according to the present invention will be described. The monitoring device is realized by one or more processors. The main function of the monitoring device is to extract users to be monitored who are thought to be likely to commit fraudulent use (hereinafter referred to as "monitored users") from among users of network services including electronic payments. The monitored users are identified as fraudulent users who commit fraudulent acts after a more detailed investigation. As a preliminary process, the monitoring device basically extracts monitored users through automated network processing. The monitoring device may have a function to conduct a detailed investigation to identify fraudulent users, but a description of this function will be omitted in this specification.
[0010] Network services including electronic payment are services that primarily focus on electronic payment and also provide peripheral services such as user-to-user remittance, chat, and splitting the bill. Hereinafter, network services including electronic payment will be referred to as electronic payment services. Electronic payment services are provided, for example, through collaboration between an application program, a payment server, and a credit card server. In the following description, the application program will be referred to as a payment app. Electronic payment services are services that support payments for the purchase of goods and services at stores. A store may be, for example, a physical store (real-world store) existing in real space, but may also include virtual stores for e-commerce. Virtual stores may also include those operated by entities other than the operator of the electronic payment service. In such cases, when making payments for purchases at the virtual store, the user is controlled to transition to the interface screen of the electronic payment service. In electronic payment services, stores are treated as belonging to, for example, affiliated stores (brands), and electronic payments made at stores are primarily made between the user and the affiliated store. Alternatively, electronic payments may be made between the user and the store. Below, we will first explain the details of the electronic payment service, followed by an explanation of the monitoring device.
[0011] [Electronic payment methods at brick-and-mortar stores] FIG. 1 illustrates the basic aspects of brick-and-mortar electronic payments. Electronic payments are generally carried out by three parties: a medium M held by a user U, store equipment E, and a payment system S. The medium M may be a portable computer device such as a smartphone or a credit card. The store equipment E resides in a physical brick-and-mortar store (hereinafter simply referred to as the store) in real space and may include a POS device, a wireless communication device, a credit card reader, a printed code image such as a QR Code (registered trademark), or a display device displaying the code image. In brick-and-mortar electronic payments, information that can identify the user and information about the payment amount are first shared unidirectionally or bidirectionally between the medium M and the store equipment E. At this time, either the medium M or the store equipment E optically reads various information from a code image displayed by the other, provides information via near-field communication (NFC), or reads the PAN (primary account number) using a credit card reader. Then, either the medium M or the store equipment E (the party that obtains information from the other) transmits the payment information required for the payment to the payment system S via a network NW. Both the medium M and the store equipment E may send some information to the payment system S. The payment system S manages various information about the user U and performs electronic payments between the store and the user U in various ways. Electronic payments are performed using either or both of a prepaid system and a postpaid system, or by other methods. In addition, electronic payments may also include so-called online shopping, which is performed between the user's terminal device and the payment system. The network NW includes, for example, the Internet, a LAN (Local Area Network), a wireless base station, a provider device, etc. The various devices that communicate via the network NW, which will be described below, are assumed to have communication devices such as network cards and wireless communication modules.
[0012] [Configuration (Terminal Payment)] 2 is a diagram showing an example of the configuration for performing electronic payment (terminal payment) using a payment app. This electronic payment is performed mainly by a payment app 20 running on a user terminal device 10, which is one of the media M, one or more store payment terminals 30 and one or more store code images 40, which are one of the store facilities E, and a payment server 100, which constitutes part of a payment system S. The payment server 100 communicates with the user terminal device 10, the store payment terminal 30, and one or more information terminals 50 via a network NW.
[0013] The user terminal device 10 is a portable terminal device such as a smartphone or tablet. The user terminal device 10 is a computer device having at least an optical reading function, a communication function, a display function, an input acceptance function, and a program execution function. In the following description, components for realizing these functions are referred to as a camera, a communication device, a touch panel, a central processing unit (CPU), etc. In the user terminal device 10, a processor such as a CPU executes a payment application 20, which operates in cooperation with a payment server 100 to provide electronic payment services to users. The payment application 20 is installed on the user terminal device 10 from, for example, an application distribution server (not shown) and controls the camera, communication device, touch panel, etc. of the user terminal device 10. In the following description, the terms "send information to the user terminal device 10 (or receive / acquire information from the user terminal device 10)" and "send information to the payment application 20 (or receive / acquire information from the payment application 20)" may be used interchangeably, but these terms are merely different expressions and are not intended to distinguish between them.
[0014] The store payment terminal 30 is installed, for example, in a store. The store payment terminal 30 is a computer device (or a collection of these) that has at least a product price acquisition function, an optical reading function, a program execution function, and a communication function. The store payment terminal 30 includes a so-called POS (Point of Sale) device, and the POS device may have a product price acquisition function and an optical reading function.
[0015] The store code image 40 is placed in a store and is a code image such as a QR code (registered trademark) printed on a paper or plastic medium. The store code image 40 may be displayed on a display placed in the store (or on a display of a terminal device such as a smartphone or tablet terminal).
[0016] The information terminal 50 is used by the operator of the affiliated store who oversees the stores. In electronic payment services, customers who provide goods or services are treated as affiliated stores (brands), and one or more stores exist under the affiliated store. An affiliated store may operate only one store. The information terminal 50 is a smartphone, tablet terminal, personal computer, etc. An affiliated store interface 55 runs on the information terminal 50. The affiliated store interface 55 may be an affiliated store app or a web page displayed by a general-purpose browser. The affiliated store interface 55 accepts coupon settings and the like from the affiliated store operator and transmits them to the payment server 100. By executing the affiliated store interface 55, the information terminal 50 may have the function of displaying a code image corresponding to the store code image 40 or reading a code image displayed by the user terminal device 10 (in the latter case, an optical reading function is required).
[0017] The payment server 100 communicates with the credit card server 200 via a network NW. The payment server 100 has, for example, a content provider 110, an information management unit 120, a payment processing unit 130, and a storage unit 170. The components other than the storage unit 170 are realized by, for example, a hardware processor such as a CPU executing a program (software). Some or all of these components may be implemented using a large scale integration (LSI), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or the like. The program may be realized by hardware (including circuitry) such as a Gate Array (GPU) or a Graphics Processing Unit (GPU), or may be realized by a combination of software and hardware. The program may be stored in advance in a storage device (a storage device with a non-transitory storage medium) such as a hard disk drive (HDD) or flash memory, or may be stored in a removable storage medium (a non-transitory storage medium) such as a DVD or CD-ROM, and installed in the storage device by inserting the storage medium into a drive device.
[0018] The storage unit 170 is a HDD, flash memory, RAM (Random Access Memory), etc. The storage unit 170 may be a NAS (Network Attached Storage) device that can be accessed by the payment server 100 via a network. The storage unit 170 stores information such as user information 172 and affiliated store / shop information 174.
[0019] The content providing unit 110 has, for example, a function of a web server, and provides information (content) for displaying various screens of the electronic payment service to the user terminal device 10. The content providing unit 110 provides the content to the user terminal device 10 in the form of a web page, and provides the user terminal device 10 with parameters required for the payment application 20 to render an image.
[0020] The information management unit 120 edits, adds, deletes, etc., user information 172 and affiliated store / shop information 174, and manages them.
[0021] FIG. 3 is a diagram showing an example of the contents of user information 172. User information 172 is information in which, for example, user URL, account ID, phone number, password, registration date, charge balance, electronic money type, terminal payment method, card payment method, various history information, identity verification flag, name, address, date of birth, email address, bank account, deferred payment settings, deferred payment condition information, user-to-user remittance history, friend list, chat history, and other information are associated with one another. Hereinafter, a user instance (electronic payment account) in which this information is associated may be referred to as an account. In the figure, items marked with "-" indicate that they are not set.
[0022] The user URL is used for remittance processing between users. When registering for the electronic payment service, registration of a phone number and password is required. The account ID is issued to the user by the payment server 100. The registration date is the date on which the user registered for the electronic payment service (the date on which the account was created). The charge balance is information indicating the balance of electronic money that the user has set by transferring money to the account in advance. Remittance methods include depositing money into an ATM (Automatic Teller Machine) of a designated service provider (bank) or transferring money from a registered bank account. The type of electronic money is information indicating, for example, whether the electronic money can be withdrawn or can only be used for electronic payments. The terminal payment method is setting information indicating whether the user will make electronic payment using the charge balance (balance payment) or by deferred payment in terminal payment. The card payment method is setting information indicating whether the user will make electronic payment using the charge balance (balance payment) or by deferred payment in card payment. The various historical information includes charge history, which is a record of the user transferring money to the electronic payment service in advance to increase the charge balance, and payment history, which shows the details of the payments made by the user for each payment (date and time, store ID of the store where the purchase was made, affiliated store ID, payment amount, payment method, etc.).
[0023] The identity verification flag indicates whether a user has completed identity verification using an ID document. Deferred payment is selectable only after identity verification has been completed. The user with account ID "002" in the figure has not completed identity verification, so can only select balance payment as the terminal payment method. The bank account is the account number of a bank account that can be used to deposit funds into the electronic payment service. Deferred payment settings indicate whether the settings required to select deferred payment have been completed. Deferred payment conditions information indicates various conditions, such as the deferred payment limit and the current month's usage amount. User-to-user remittance history includes a description of remittance history and remittance receipt history, along with the amount and date and time. The friend list contains information about other users who are displayed as potential partners for user-to-user remittances and chats. Chat history includes information such as the content, date, and time of a user's chats.
[0024] 4 is a diagram showing an example of the contents of affiliated store / store information 174. The affiliated store / store information 174 includes, for example, a first table 174A in which an affiliated store ID and a store ID are associated with a store URL, a second table 174B in which an affiliated store ID is associated with an affiliated store name and sales amount (described above), and a third table 174C in which a store ID is associated with a store ID. In addition to this information, the affiliated store / store information 174 may also include information such as the category of the affiliated store or store, the store's location, and payment patterns.
[0025] The payment processing unit 130 performs various processes for electronic payment. There are two methods for terminal payment: a first method (user scan) and a second method (store scan), which will be explained below.
[0026] FIG. 5 shows an overview of the process flow when a user scan is performed. First, the user terminal device 10, with the payment application 20 running, reads and decodes the store code image 40 using its optical reading function (S1). The store code image 40 contains store URL information. The payment application 20 sends first payment information, including the store URL and the user's account ID, to the payment server 100 (S2). The payment server 100 searches the affiliated store / store information 174 using the affiliated store ID and store ID corresponding to the store URL, acquires information about the affiliated store name and store name (S3), and sends this to the payment application 20 (S4). The user enters the payment amount into the payment application 20 on the screen displaying the affiliated store name and store name (S5). The payment application 20 then generates second payment information including at least the payment amount and sends it to the payment server 100 (S6).
[0027] If the "Terminal Payment Method" in the user information 172 of the user is set to "Balance Payment," the payment processing unit 130 of the payment server 100 performs electronic payment based on the received second payment information (S7-1). At this time, the payment processing unit 130 performs electronic payment by, for example, decreasing the charge balance managed in association with the user ID and increasing the item value of the affiliated store's sales proceeds. The item value of the affiliated store's sales proceeds is not used as electronic money itself, for example, but rather the amount corresponding to the item value of the sales proceeds is transferred to a bank account in a cycle determined by an agreement between the affiliated store and the electronic payment service. On the other hand, if the "Terminal Payment Method" is set to "Deferred Payment," the payment processing unit 130 transmits the first payment information and the second payment information to the credit card server 200 to request electronic payment (S7-2). The credit card server 200 performs electronic payment by adding the payment amount to the user's monthly usage amount based on the received information and deducting the monthly usage amount from the user's bank account after the closing date (S7-3).
[0028] Then, the payment processing unit 130 sends a payment completion notice (information for displaying a payment completion screen) to the payment app 20 via the content providing unit 110 (S8), and the payment app 20 displays the payment completion screen (S9). When the store code image 40 is displayed on a display installed in the store, the store code image 40 may include information on the payment amount in addition to the store URL. In this case, the procedure for the user to input the payment amount is omitted, and the information on the payment amount is included in the first payment information and sent to the payment server 100. Information on the affiliated store name and store name may be included and displayed on the payment completion screen.
[0029] FIG. 6 is a diagram showing an overview of the processing flow when a store scan is performed. First, when the payment app 20 is launched, when a payment operation is performed using the payment app 20, when an automatic update timing (e.g., every minute) occurs, and at other timings, the payment app 20 sends a request to issue a one-time code to the payment server 100 (S11). The payment processing unit 130 of the payment server 100 generates a one-time code (S12) and sends it to the payment app 20 (S13). The payment app 20 displays a code image, such as a QR code or barcode, generated based on the one-time code (S14). The user holds (presents) the display surface of the user terminal device 10 over the store payment terminal 30, and the store payment terminal 30 reads and decodes the code image using its optical reading function to obtain the one-time code, etc. (S15). The store payment terminal 30 then generates payment information including the one-time code, payment amount, affiliated store ID, store ID, etc., and sends it to the payment server 100 (S16). The payment amount information is acquired in advance by reading a barcode or manually entering it.
[0030] The payment processing unit 130 of the payment server 100 identifies the user corresponding to the one-time code based on the received information, and if the "terminal payment method" in the user information 172 of the user is set to "balance payment," it performs electronic payment based on the received second payment information (S17-1). The processing content at this time is the same as the processing of S7-1 in FIG. 5. On the other hand, if the "terminal payment method" is set to "post-payment," the payment server 100 transmits the first payment information and the second payment information to the credit card server 200 to request electronic payment (S17-2). The credit card server 200 adds the payment amount to the user's monthly usage amount based on the received information, and performs electronic payment by deducting the monthly usage amount from the user's bank account after the closing date (S17-3).
[0031] Then, the payment processing unit 130 transmits a payment completion notification to the payment application 20 via the content providing unit 110 (S18), and the payment application 20 displays a payment completion screen (S19).
[0032] Note that electronic payment may be performed using only one of the above patterns. Furthermore, the "account ID" described in FIG. 2 may be other information (e.g., a phone number) that can be used as user identification information. Furthermore, issuing a one-time code may be omitted in store scanning, and the payment application 20 may display a code image generated based on the user's account ID. In this case, the payment server 100 identifies the user corresponding to the account ID instead of identifying the user corresponding to the one-time code.
[0033] It should be noted that the "post-payment" settlement may be performed within the settlement server 100, rather than being managed by the credit card server 200. In this case, the components such as the settlement card 60 and the credit card server 200 may be omitted.
[0034] [Configuration (Card Payment)] 7 is a diagram showing an example of a configuration for performing electronic payment (card payment) using a payment card. This electronic payment is performed mainly using a payment card 60, which is one of the media M, a credit card processing terminal 70, which is one of the store facilities E, a payment server 100, which constitutes part of a payment system S, and a credit card server 200. The credit card server 200 communicates with the credit card processing terminal 70 via a network NW.
[0035] The credit processing terminal 70 is installed in the store, similar to the in-store payment terminal 30. The credit processing terminal 70 includes, for example, a credit card reader and a POS device. The credit card terminal reads a personal identification number (PIN) from an inserted or held-up credit card and compares it with the PIN entered by the user. It also transmits a primary account number (PAN) read from the credit card to the credit card server 200 via the POS device. The POS device cooperates with the credit card terminal to transmit information such as the payment amount to the credit card server 200. A payment agent (acquirer) server may be interposed between the credit processing terminal 70 and the credit card server 200; however, for simplicity, the following description omits the server. The payment card 60 is, for example, similar to a commonly used credit card, with a communication chip embedded in the card substrate. The communication chip incorporates a storage medium storing the PIN and communicates with an external device via a contactor (or a wireless antenna). Alternatively, the payment card 60 may be a magnetic card. The information (messages) sent and received when using a credit card include an authorization message for authentication and a sales message for conveying the payment amount, but detailed explanations distinguishing between these will be omitted below.
[0036] The credit card server 200 communicates with the payment server 100 via a network NW. The credit card server 200 includes, for example, an information management unit 210, a credit interface 220, a payment allocation unit 230, a credit payment processing unit 240, and a memory unit 270. The components other than the memory unit 270 are implemented by, for example, a hardware processor such as a CPU executing a program (software). Some or all of these components may be implemented by hardware (including circuitry) such as an LSI, ASIC, FPGA, or GPU, or may be implemented by a combination of software and hardware. The program may be stored in advance in a storage device such as an HDD or flash memory (a storage device with a non-transitory storage medium), or may be stored in a removable storage medium (a non-transitory storage medium) such as a DVD or CD-ROM, and installed in the storage device by inserting the storage medium into a drive device. The memory unit 270 stores information such as card user information 272.
[0037] The information management unit 210 edits, adds, deletes, etc., and manages the card user information 272. The card user information 272 is information in which, for example, information unique to a user (e.g., PAN), a card payment method, and the user's account ID (used by the payment server 100) are associated with one another. The card payment method is setting information that indicates whether the user will make electronic payment using the charged balance (balance payment) or deferred payment when making a card payment.
[0038] The credit interface 220 determines whether the BIN (Bank Identification Number) in the PAN included in the message received from the credit processing terminal 70 is a code for the company, and if it is a code for the company, passes the message received from the credit processing terminal 70 to the payment allocation unit 230, and if it is not a code for the company, discards the received message.
[0039] The payment allocating unit 230 refers to the card user information 272 of the user corresponding to the message obtained from the credit interface 220, and determines whether the "card payment method" is set to "post-payment." If the "card payment method" is set to "post-payment," the payment allocating unit 230 notifies the credit interface 220 of this and passes the message obtained from the credit interface 220 to the credit payment processing unit 240. On the other hand, if the "card payment method" is set to "balance payment," the payment allocating unit 230 adds the user's account ID to the message obtained from the credit interface 220 and sends it to the payment server 100, requesting electronic payment. When requested to make electronic payment, the payment server 100 performs the same processes as S7-1 in Figure 5 and S17-1 in Figure 6.
[0040] The credit interface 220 checks the PAN and expiration date, and verifies whether the cumulative payment amount exceeds the current month's upper limit, etc. The credit payment processing unit 240 adds the payment amount to the user's monthly usage amount based on the information contained in the message obtained from the payment allocation unit 230, and performs electronic payment by deducting the monthly usage amount from the user's bank account after the closing date.
[0041] [Monitoring device] The monitoring device will be described below. FIG. 8 is a diagram showing an example of the configuration and usage environment of the monitoring device 300. In the figure, the monitoring device 300 is shown as a separate device from the payment server 100, but the monitoring device 300 may also be a virtual machine included in the payment server 100. The monitoring device 300 may acquire information from the payment server 100 or from an SNS server 400 that provides a social networking service (SNS) linked to an electronic payment service. The monitoring device 300 includes, for example, an acquisition unit 310, an extraction unit 320, an alert unit 330, and a storage unit 350. The components other than the storage unit 350 are realized by, for example, a hardware processor such as a CPU executing a program (software). Some or all of these components may be realized by hardware (including circuitry) such as an LSI, ASIC, FPGA, or GPU, or by a combination of software and hardware. The program may be stored in advance in a storage device such as a HDD or flash memory, or may be stored in a removable storage medium such as a DVD or CD-ROM and installed in the storage device by inserting the storage medium into a drive device. The storage unit 350 stores information such as a fraudulent user list 352 and a monitored user list 354. The fraudulent user list 352 is the list of fraudulent users mentioned above. The monitored user list 354 is the list of monitored users mentioned above. This information is represented by, for example, account IDs.
[0042] The acquisition unit 310 acquires at least one of the network communication information of fraudulent users who use network services including electronic payments and the user-to-user remittance history of fraudulent users. In the following description, it is assumed that the acquisition unit 310 acquires both of these. The network communication information is based on, for example, chat history or friend list held by the payment server 100, or information obtained from an SNS provided by the SNS server 400. SNS includes various services for communicating information one-on-one, within a group, or among an unspecified number of people in the form of chat or posting. The acquisition unit 310 may further acquire withdrawal information from the user's electronic payment service to a bank from the payment server 100.
[0043] The extraction unit 320 extracts users to be monitored based on at least one of the network communication information and the user-to-user remittance history, and adds the extracted users to the list of users to be monitored 354 (stores them in the storage unit 350). In the following explanation, it is assumed that the extraction unit 320 extracts users to be monitored based on both of these.
[0044] When a user-to-user remittance is about to be performed for a monitored user, the alert unit 330 notifies the payment server 100 to output an alert to the remitter. When the monitoring device 300 is included in the payment server 100, the alert unit 330 sends the above notification directly to the payment application 20 of the remitter.
[0045] The processing of the monitoring device 300 will be described below with reference to a flowchart. FIG. 9 is a flowchart showing an example of the processing flow executed by the monitoring device 300. First, the acquisition unit 310 acquires the various pieces of information described above (S100). The extraction unit 320 references the user-to-user remittance history and extracts remittance recipient users who have received remittances from fraudulent users (S102). The extraction unit 320 determines whether the users extracted in S102 have a network communication relationship with the fraudulent user who is the remitter (S104). "Having a network communication relationship" includes, for example, some or all of the following: chat history, being registered on at least one friend list, and having an interaction history on SNS (e.g., one-to-one contact, liking a post, etc.). The extraction unit 320 adds users for whom the determination result in S104 is affirmative to the list of users to be monitored (S120). Note that the extraction unit 320 may omit the processing of S104 and add the users extracted in S102 directly to the list of users to be monitored. Figure 10 illustrates the users to be monitored who are identified in S102 to S104. Normally, fraudulent users "make others send money" fraudulently and then receive the money themselves, but if a user receives money from a fraudulent user, it is assumed that there is some kind of unusual relationship between the user and the fraudulent user. Furthermore, if there is a relationship in network communication, the possibility of being identified as a fraudulent user increases.
[0046] Next, the extraction unit 320 references the user-to-user remittance history and network communication information for users who were not added to the list of users to be monitored in S102 to S104, extracts users who have received remittances from other users and who are blocking or ignoring those other users in network communication (S106), and adds the extracted users to the list of users to be monitored (S120). Figure 11 illustrates the users to be monitored extracted in S106. "Ignoring" refers to a state in which another user has contacted the user through network communication (chat, posting, contact, etc.) but has not responded for a predetermined period of time or more. This is because such a state is likely to occur when a remittance from another user is fraudulently induced.
[0047] Next, the extraction unit 320 extracts users who have network communication relationships with a predetermined number (an integer of 2 or more) of users to be monitored or unauthorized users from among the users not added to the list of users to be monitored in the processing up to this point (S108), and adds the extracted users to the list of users to be monitored (S120). Figure 12 illustrates the users to be monitored extracted in S108. This is because such users are likely to be members of a group centered around unauthorized users or users to be monitored.
[0048] Next, the extraction unit 320 extracts users who have not been added to the list of users to be monitored in the above processes, but who have withdrawn money to a bank within a predetermined period of time since receiving money from another user at a frequency equal to or greater than a predetermined value (S110), and adds the extracted users to the list of users to be monitored (S120).This type of usage suggests an intention to quickly remit fraudulently received money to a bank and cash it.
[0049] Next, the extraction unit 320 selects each user who has not been added to the list of users to be monitored in the previous steps, inputs the content of the network communications of the selected user into the model (S112), and determines whether to add the selected user to the list of users to be monitored based on the model output (S114). The selected user is then added to the list of users to be monitored (S120). Figure 13 is a diagram illustrating the process of S112. The model may be, for example, a Large Language Model (LLM). The LLM, for example, learns based on collective intelligence obtained via a network and returns a response to input in natural language. This function allows the model to determine whether one or both users in a chat are engaging in abusive or defamatory behavior and output the determination result. The extraction unit 320 adds users who are determined to be engaging in abusive or defamatory behavior to the list of users to be monitored.
[0050] According to the embodiment described above, it is possible to appropriately expand the number of users to be monitored.
[0051] The above describes the form for carrying out the present invention using an embodiment, but the present invention is not limited to such an embodiment, and various modifications and substitutions can be made within the scope that does not deviate from the gist of the present invention. [Explanation of symbols]
[0052] E. Store Facilities M medium S payment system 10 User terminal device 20. Payment App 30 Store payment terminals 40 Store code image 60 Payment Cards 70 Credit card processing terminal 100 Payment Server 130 Payment processing unit 200 Credit Card Server 300 Monitoring equipment 310 Acquisition Department 320 Extraction part 330 Alert section 350 Storage section 352 Abuse List 354 List of monitored users
Claims
1. an acquisition unit that acquires network communication information of a fraudulent user who commits fraudulent acts among users who use a network service including electronic payment, and the user-to-user remittance history of the fraudulent user; an extraction unit that extracts users to be monitored based on the network communication information and the user-to-user remittance history, and stores the extracted users in a storage unit; Equipped with the extraction unit refers to the user-to-user remittance history and the network communication information, and determines, as the users to be monitored, users who are remittance destinations who have received remittances from the fraudulent user and who have a network communication relationship with the fraudulent user who is the remitter; monitoring equipment.
2. an acquisition unit that acquires network communication information of a fraudulent user who commits fraudulent acts among users who use a network service including electronic payment, and the user-to-user remittance history of the fraudulent user; an extraction unit that extracts users to be monitored based on the network communication information and the user-to-user remittance history, and stores the extracted users in a storage unit; Equipped with the extraction unit refers to the user-to-user remittance history and the network communication information, and identifies a user who receives remittances from other users and blocks or ignores the other users as the user to be monitored; monitoring equipment.
3. an acquisition unit that acquires network communication information of fraudulent users who commit fraudulent acts among users who use network services including electronic payments; an extraction unit that extracts users to be monitored based on the network communication information and stores the extracted users in a storage unit; Equipped with the extraction unit determines, as the users to be monitored, a predetermined number (an integer of 2 or more) of users to be monitored or users who have a network communication relationship with the unauthorized user; monitoring equipment.
4. The acquisition unit acquires the user-to-user remittance history of the fraudulent user, the extraction unit refers to the user-to-user remittance history and designates a remittance destination user who has received a remittance from the fraudulent user as the user to be monitored; 4. The monitoring device according to claim 2 or 3.
5. the acquisition unit acquires the network communication information based on information obtained from a chat history or a friend list included in the network service, or a linked SNS (Social Networking Service). A monitoring device according to any one of claims 1 to 3.
6. The acquisition unit further acquires withdrawal information to the user's bank, determining whether or not the user is to be monitored based on the frequency with which the user withdraws money to a bank within a predetermined period after receiving money from another user; 3. The monitoring device according to claim 1 or 2.
7. The extraction unit inputs the content of the user's network communication into an LLM (Large Language Model) and determines whether or not the user is to be monitored based on the output of the LLM. A monitoring device according to any one of claims 1 to 3.
8. further comprising an alert unit that outputs an alert to a remitter when a user-to-user remittance is about to be made to the monitored user; 3. The monitoring device according to claim 1 or 2.
9. The monitoring device Among users of a network service including electronic payments, network communication information of a fraudulent user who commits fraudulent acts and a user-to-user remittance history of the fraudulent user are acquired; extracting users to be monitored based on the network communication information and the user-to-user remittance history, and storing the extracted users in a storage unit; When extracting, the user-to-user remittance history and the network communication information are referenced, and a user who is a remittance destination user who has received a remittance from the fraudulent user and who has a network communication relationship with the fraudulent user who is the remitter is determined to be a user to be monitored. Monitoring method.
10. The processor A process of acquiring network communication information of a fraudulent user who commits fraudulent acts among users of a network service including electronic payment, and a user-to-user remittance history of the fraudulent user; A process of extracting users to be monitored based on the network communication information and the user-to-user remittance history, and storing the extracted users in a storage unit; A program for executing When extracting, the processor refers to the user-to-user remittance history and the network communication information, and designates a user who is a remittance destination user who has received a remittance from the fraudulent user and who has a network communication relationship with the fraudulent user who is the remitter as the user to be monitored. program.
Citation Information
Patent Citations
Fraudulent money transfer prevention method and fraudulent money transfer prevention system
JP2016170761A
Transfer processing system of digital asset and transaction system of digital asset such as issued st provided on the same system
JP2024052438A
Information processing device, information processing method, and information processing program
JP7583203B1