System for detecting abnormal electronic financial transaction and method therefor
The electronic financial fraud detection system uses sentiment analysis and a security dictionary to identify and halt suspicious transactions, addressing the inefficiencies in detecting telecommunication-based fraud and reducing financial losses.
Patent Information
- Application Number
- PCT/KR2024/095706
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-25
- Filing Date
- 2024-04-15
- Publication Date
- 2025-10-02
AI Technical Summary
Existing financial fraud detection systems struggle to effectively detect and immediately respond to telecommunication-based financial fraud, such as voice phishing and messenger phishing, leading to significant financial losses due to delayed or inadequate response measures.
An electronic financial fraud detection system that performs sentiment analysis on accessed websites using a text summarization and frequency calculation algorithm, generates a security dictionary and malicious judgment criterion, and integrates these into a fraud detection system to identify and halt suspicious transactions.
Effectively detects and prevents telecommunication-based financial fraud by identifying malicious URLs and taking immediate action to prevent financial damage, enhancing the detection rate and response time.
Smart Images

Figure KR2024095706_02102025_PF_FP_ABST
Abstract
Description
Electronic financial fraud detection system and method thereof
[0001] The present invention relates to an electronic financial abnormal transaction detection system and a method therefor, which performs sentiment analysis on a plurality of websites accessed from a plurality of user terminals using a text summarization algorithm and a frequency calculation algorithm, extracts a security dictionary and a malicious judgment criterion for determining a malicious URL based on the results of the sentiment analysis obtained, and generates an analysis module, and collects the detection results detected by a malicious URL detection engine including the generated analysis module in a log collection server to generate and store user log information, and then, when a suspicious transaction is detected during a financial transaction through a fraud detection system (FDS) installed in a financial institution server, requests target log information corresponding to the suspicious transaction, extracts target log information from the user log information, and then determines whether the transaction is malicious based on the malicious judgment criterion of the fraud detection system (FDS), thereby effectively detecting abnormal transactions due to telecommunication financial fraud in electronic finance and enabling immediate action to be taken, as well as preventing and preventing financial damage due to financial fraud.
[0002]
[0003] As is well known, as of 2023, all domestic financial institutions are operating a Fraud Detection System (FDS). FDS is a system for detecting and preventing phishing crimes. It can be provided to detect abnormal transactions through scanning of emails and messages, domain inspection, user behavior analysis, user education and warnings, and multi-factor authentication.
[0004] It is known that the average prevention rate reached 95.4% in 2017 through the detection of abnormal transactions through FDS. However, as financial convenience advances, various phishing crimes that exploit technological vulnerabilities are occurring, and they are continuously evolving, causing greater financial damage than before.
[0005] In addition, as the deposit and withdrawal scenarios of financial accounts become more diverse, it is difficult to detect abnormal financial transactions related to voice phishing through monitoring or simple rule-based detection methods. Even when abnormal transactions are detected, there is a problem in that it is difficult to take immediate and active measures such as suspending transactions or payments.
[0006] Meanwhile, telecommunications financial fraud related to electronic finance (e.g., voice phishing, messenger phishing, etc.) can proceed according to the scenarios below.
[0007] First, when requesting a remittance by impersonating an acquaintance through an internet messenger, the internet messenger ID and password of the person from whom the remittance is requested are hacked, and after logging into the internet messenger, emergency funds such as money or traffic accident settlement money are requested through 1:1 conversations or messages to family members, friends, etc. registered on the internet messenger. If the victim is deceived and sends the money for emergency funds, the money is embezzled.
[0008] Second, in the case of fraudulent use of internet banking for card loan payments, deposits, etc., the victim is deceived into accessing a phishing site under the pretext of identity theft, information leak, or involvement in a criminal case, and then credit card information (e.g., card number, password, CVC number, etc.) and internet banking information (e.g., internet banking ID, password, account number, public certificate password, security card number, etc.) are obtained through the phishing site. Then, the fraudster receives a card loan in the victim's name through ARS or the internet, and the fraudster reissues a public certificate and transfers the card loan payment, etc. to the fraudster's account through internet banking, thereby fraudulently conducting the transaction.
[0009] Third, in cases where the victim is deceived and defrauded under the pretext of an erroneous remittance of the product price, the fraudster contacts the victim via text message or phone call, saying that he or she has remitted the product price, accommodation fee, etc., and then shortly thereafter requests a return of the money, claiming that it was remitted by mistake, or demands the difference in amount.
[0010] Fourth, in cases of fraud by sending false text messages and leading to phishing sites, emergency notification text messages are sent in the name of financial companies, the Financial Supervisory Service, etc. to deceive and lead people to access phishing sites, thereby stealing deposits, etc.
[0011] Fifth, in cases where the victim is deceived and lured into an automated teller machine (ATM) to steal funds, a fraudster impersonating an investigative agency employee calls the victim and deceives them into thinking that the victim's account is involved in a case (crime) and that the victim's account needs to be secured. The fraudster lures the victim into an ATM and has them operate the ATM to steal funds.
[0012] In the process described above, in order to deceive and mislead the victim, a phishing message may be sent to the victim, or a phishing site similar to a website operated by a public institution or financial institution may be used. A phishing message such as that shown in FIG. 1 may be sent to a user terminal to stimulate the user's curiosity, and the user may be induced to click on a link planted in the message, thereby accessing a phishing site. In this case, the phishing site accessed configures a web UI similar to the actual site so that it is impossible to know whether it is a phishing site or not. Here, FIG. 2 shows a phishing site created to be similar to the actual KB Kookmin Bank as a "website".
[0013] As described above, there is a need for the development of an abnormal transaction detection technique that can effectively detect abnormal transactions resulting from telecommunication financial fraud in electronic finance and take immediate action to prevent and mitigate financial damage caused by financial fraud.
[0014] [Prior Art Literature]
[0015] 1. Korean Patent Publication No. 10-2016-0078281 (published on July 4, 2016)
[0016]
[0017] The present invention collects user log information obtained by performing sentiment analysis using a text summarization algorithm and a frequency calculation algorithm on a plurality of websites accessed from a plurality of user terminals, and uses the user log information to create and store a security dictionary and a malicious judgment criterion for determining a malicious URL, and then, when a suspicious transaction is detected during a financial transaction through a fraud detection system (FDS) installed on a financial institution server, requests target log information corresponding to the suspicious transaction, extracts target log information from the user log information, and then determines whether the transaction is malicious based on the malicious judgment criterion of the fraud detection system (FDS), thereby effectively detecting and taking immediate action on fraudulent transactions due to telecommunication financial fraud in electronic finance, and provides an electronic financial fraud detection system and method therefor.
[0018]
[0019] The purpose of the embodiments of the present invention is not limited to the purpose mentioned above, and other purposes not mentioned will be clearly understood by those skilled in the art to which the present invention pertains from the description below.
[0020]
[0021] According to one aspect of the present invention, a plurality of user terminals for generating a domain list corresponding to a plurality of websites accessed through a communication network, labeling the domain list as one of normal, malicious, and caution, collecting search results for the plurality of websites, preprocessing the collected search results to extract target sentences for determining malicious URLs, performing sentiment analysis on the extracted target sentences using a text summarization algorithm and a frequency calculation algorithm, generating and storing a security dictionary for determining the malicious URL according to the performance result of the sentiment analysis, extracting a malicious judgment criterion for determining the malicious URL using the security dictionary to create an analysis module, and transmitting detection results detected through a malicious URL detection engine including the generated analysis module through the communication network; a log collection server for collecting the detection results transmitted from the plurality of user terminals to create and store user log information; An electronic financial abnormal transaction detection system may be provided, including a financial institution server that, while monitoring all financial transactions through an installed abnormal transaction detection system (FDS), if a suspicious transaction using a financial transaction means is detected, requests target log information corresponding to the suspicious transaction to the log collection server through the communication network, determines whether the transaction is abnormal by considering a preset time range when the target log information is provided from the log collection server, and stops the suspicious transaction if it is determined to be an abnormal transaction.
[0022] In addition, according to one aspect of the present invention, the plurality of user terminals include: a communication module unit that provides a wired and wireless communication environment by connecting through at least one communication module corresponding to the communication network; a list generation unit that generates the domain list corresponding to the plurality of websites connected through the communication module unit; a labeling unit that labels the domain list as one of normal, malicious, and caution; a data collection unit that crawls the plurality of websites included in the domain list and collects the search results; a preprocessing unit that extracts the target sentence for determining the malicious URL by preprocessing the search results in a manner of performing plaintext parsing, labeling as to whether or not malicious, removing stop words, and tokenizing; a sentiment analysis unit that performs keyword summary on the target sentence using the text summarization algorithm for the sentiment analysis, and calculates keyword importance on the keyword summary using the frequency calculation algorithm for the sentiment analysis; a security dictionary generation unit that generates and stores the security dictionary for determining the malicious URL based on the keyword summary and keyword importance; An electronic financial abnormal transaction detection system may be provided, including: an analysis module generating unit that extracts the malicious judgment criterion value for determining the malicious URL by using a keyword vector value assigned in response to each keyword included in the security dictionary according to the keyword importance; and a control unit that controls data processing of each component unit and controls the communication module unit to transmit the detection result detected by the malicious URL detection engine including the analysis module through the communication network.
[0023] In addition, according to one aspect of the present invention, the preprocessing unit may include a parsing block that performs plaintext parsing for the search results transmitted from the data collection unit, separately in English and Korean; a labeling block that labels each sentence transmitted from the parsing block, on which the plaintext parsing has been performed, as one of normal, malicious, and caution; a removal block that analyzes morphemes for each labeled sentence transmitted from the labeling block and then removes stop words; and a tokenizing block that performs tokenization on the output sentence transmitted from the removal block to extract the target sentence.
[0024] In addition, according to one aspect of the present invention, the sentiment analysis unit may provide an electronic financial abnormal transaction detection system that uses the textRank algorithm as the text summary algorithm.
[0025] In addition, according to one aspect of the present invention, an electronic financial fraud detection system may be provided that performs keyword summarization by using at least one sequence for the target sentence as a vertex of a graph, adding an edge of the graph by considering co-occurrence, repeatedly performing the textRank algorithm so as to converge on the importance of the initial vertex, and then sorting the vertices according to each importance and designating a preset number of vertices as keywords.
[0026] In addition, according to one aspect of the present invention, the sentiment analysis unit may provide an electronic financial abnormal transaction detection system using a BM25 algorithm based on a TF-IDF (Term Frequency-Inverse Document Frequency) algorithm as the frequency calculation algorithm.
[0027] In addition, according to one aspect of the present invention, the sentiment analysis unit may provide an electronic financial abnormal transaction detection system that calculates the keyword importance through the BM25 algorithm, which is based on the TF-IDF algorithm calculated according to the word frequency and inverse document frequency for the keyword summary, but is corrected so that the IDF converges to 0 while the TF converges to a reference value.
[0028] In addition, according to one aspect of the present invention, an electronic financial abnormal transaction detection system may be provided in which the analysis module generation unit generates a malicious score using each keyword vector value for a collected document or sentence, and analyzes the generated malicious score to determine a threshold value between labels, thereby generating the malicious judgment criterion value.
[0029] In addition, according to one aspect of the present invention, when the analysis module receives a URL from the plurality of user terminals or accesses the URL, the URL is transmitted to the analysis module, and an electronic financial abnormal transaction detection system can be provided that detects the URL in real time or continuously by detecting whether the URL is normal, malicious, or cautionary through the analysis module.
[0030]
[0031] According to another aspect of the present invention, there is provided a method for detecting malicious URLs, comprising: generating a domain list corresponding to a plurality of websites accessed through a communication network from a plurality of user terminals, labeling the domain list as one of normal, malicious, and caution, and then collecting search results for the plurality of websites; preprocessing the collected search results from the plurality of terminals to extract target sentences for determining malicious URLs; performing sentiment analysis on the extracted target sentences using a text summarization algorithm and a frequency calculation algorithm from the plurality of terminals; generating a security dictionary for determining the malicious URL according to the results of the sentiment analysis from the plurality of terminals; extracting a malicious judgment criterion for determining the malicious URL using the security dictionary from the plurality of terminals to create an analysis module; transmitting detection results detected through a malicious URL detection engine including the generated analysis module from the plurality of terminals; collecting the detection results from a log collection server to create and store user log information; A step of requesting target log information corresponding to the suspicious transaction to the log collection server through the communication network when a suspicious transaction using a financial transaction means is detected while monitoring the entire financial transaction through the fraud detection system (FDS) installed on the financial institution server;
[0032] In addition, according to another aspect of the present invention, an electronic financial abnormal transaction detection method may be provided, including: a step of extracting target log information from the user log information in the log collection server and transmitting the target log information through the communication network; a step of determining whether a transaction is abnormal by considering a preset time range when the target log information is provided from the log collection server in the financial institution server; and a step of stopping the suspicious transaction when the financial institution server determines that the transaction is abnormal.
[0033] In addition, according to another aspect of the present invention, a method for detecting electronic financial abnormal transactions may be provided in which the step of extracting the target sentence extracts the target sentence for determining the malicious URL by preprocessing the search result in a manner of performing plaintext parsing, labeling whether it is malicious, removing stop words, and tokenizing in a preprocessing unit of the user terminal.
[0034] In addition, according to another aspect of the present invention, the step of extracting the target sentence may include the step of performing plaintext parsing separately in English and Korean for the search result transmitted from the parsing block of the preprocessing unit; the step of labeling each sentence transmitted from the parsing block as one of normal, malicious, and caution in the labeling block of the preprocessing unit; the step of analyzing morphemes for each labeled sentence transmitted from the labeling block in the removal block of the preprocessing unit and then removing stop words; and the step of performing tokenization on the output sentence transmitted from the removal block in the tokenizing block of the preprocessing unit to extract the target sentence.
[0035] In addition, according to another aspect of the present invention, the step of performing the sentiment analysis may provide an electronic financial abnormal transaction detection method in which the sentiment analysis unit of the user terminal performs keyword summary using the textRank algorithm as the text summary algorithm for the target sentence, and the sentiment analysis unit calculates keyword importance using the BM25 algorithm based on the TF-IDF (Term Frequency-Inverse Document Frequency) algorithm as the frequency calculation algorithm for the keyword summary.
[0036] In addition, according to another aspect of the present invention, the step of performing the sentiment analysis may provide an electronic financial abnormal transaction detection method in which the keyword summary is performed by using at least one sequence as a vertex of a graph for the target sentence in the sentiment analysis unit, adding an edge of the graph in consideration of co-occurrence, repeatedly performing the textRank algorithm so as to converge on the importance of the initial vertex, and then sorting the vertices according to each importance and designating a preset number of vertices as keywords.
[0037] In addition, according to another aspect of the present invention, the step of performing the sentiment analysis may provide an electronic financial abnormal transaction detection method in which the keyword importance is calculated through the BM25 algorithm based on the TF-IDF algorithm calculated according to the word frequency and inverse document frequency for the keyword summary in the sentiment analysis unit, but corrected so that the IDF converges to 0 while the TF converges to a reference value.
[0038] In addition, according to another aspect of the present invention, the step of generating the analysis module may provide an electronic financial abnormal transaction detection method in which a keyword vector value is assigned to each keyword included in the security dictionary according to the keyword importance in an analysis module generating unit provided in the plurality of terminals, a malicious score is calculated using each keyword vector value for the collected document or sentence, and a threshold value between labels is determined by analyzing the calculated malicious score, thereby generating the malicious judgment criterion value.
[0039] In addition, according to another aspect of the present invention, the step of transmitting the detection result may provide an electronic financial abnormal transaction detection method that detects the URL in real time or continuously in such a way that, when a URL is received from the plurality of user terminals or the URL is accessed, the URL is transmitted to the analysis module, and the analysis module detects whether the URL is normal, malicious, or cautionary.
[0040]
[0041] The present invention performs sentiment analysis on a plurality of websites accessed from a plurality of user terminals using a text summarization algorithm and a frequency calculation algorithm, extracts a security dictionary and a malicious judgment criterion for determining a malicious URL based on the obtained sentiment analysis results, and generates an analysis module, and collects the detection results detected by a malicious URL detection engine including the generated analysis module in a log collection server to generate and store user log information, and then, when a suspicious transaction is detected during a financial transaction through a fraud detection system (FDS) installed in a financial institution server, requests target log information corresponding to the suspicious transaction, extracts target log information from the user log information, and then determines whether or not the transaction is malicious based on the fraud judgment criterion of the fraud detection system (FDS), thereby effectively detecting and taking immediate action on fraudulent transactions due to telecommunication financial fraud in electronic finance, and can also prevent and prevent financial damage due to financial fraud.
[0042]
[0043] Figure 1 is a drawing illustrating text messages and phishing sites used in telecommunication financial fraud.
[0044] Figure 3 is a block diagram of an electronic financial abnormal transaction detection system according to one embodiment of the present invention.
[0045] Figures 4 to 6 are drawings for explaining the detailed configuration of an electronic financial abnormal transaction detection system according to one embodiment of the present invention.
[0046] Figure 7 is a flowchart showing a process for detecting abnormal electronic financial transactions according to another embodiment of the present invention.
[0047] Figure 8 is a flowchart showing a specific process for detecting a malicious URL in the process of detecting an electronic financial abnormal transaction according to another embodiment of the present invention.
[0048]
[0049] Advantages and features of embodiments of the present invention, and methods for achieving them, will become clearer with reference to the embodiments described in detail below together with the accompanying drawings. However, the present invention is not limited to the embodiments disclosed below, but can be implemented in various different forms. These embodiments are provided only to ensure that the disclosure of the present invention is complete and to fully inform those skilled in the art of the scope of the invention, and the present invention is defined only by the scope of the claims. Like reference numerals refer to like elements throughout the specification.
[0050] When describing embodiments of the present invention, detailed descriptions of known functions or configurations will be omitted if they are deemed to unnecessarily obscure the gist of the invention. Furthermore, the terms described below are defined in light of their functions in the embodiments of the present invention and may vary depending on the intent or custom of the user or operator. Therefore, their definitions should be based on the overall content of this specification.
[0051] Hereinafter, embodiments of the present invention will be described in detail with reference to the attached drawings.
[0052]
[0053] FIG. 3 is a block diagram of an electronic financial abnormal transaction detection system according to one embodiment of the present invention, and FIGS. 4 to 6 are drawings for explaining the detailed configuration of an electronic financial abnormal transaction detection system according to one embodiment of the present invention.
[0054]
[0055] Referring to FIGS. 3 to 6, an electronic financial abnormal transaction detection system according to an embodiment of the present invention may include a plurality of user terminals (100), a log collection server (200), a financial institution server (300), a communication network (400), etc.
[0056]
[0057] The plurality of user terminals (100) are terminals registered in response to an unspecified plurality of users who perform financial transactions through financial transaction means (e.g., home banking, firm banking, open banking, ATM, etc.) while registered as members in a financial institution server (300), and may include, for example, a smart phone, a mobile phone, a navigation device, a computer, a laptop, a digital broadcasting terminal, a PDA (Personal Digital Assistants), a PMP (Portable Multimedia Player), a tablet PC, a game console, a wearable device, an IoT (Internet of Things) device, a VR (virtual reality) device, an AR (augmented reality) device, etc.
[0058] These multiple user terminals (100) create a domain list corresponding to multiple websites accessed through a communication network (500), label them as one of normal, malicious, and caution, collect search results for multiple websites, preprocess the collected search results to extract target sentences for determining malicious URLs, perform sentiment analysis on the extracted target sentences using a text summarization algorithm and a frequency calculation algorithm, and then create and store a security dictionary for determining malicious URLs according to the results of the sentiment analysis, extract a malicious judgment criterion for determining malicious URLs using the security dictionary, create an analysis module, and transmit the detection results detected by a malicious URL detection engine including the created analysis module through the communication network (500).
[0059] The plurality of user terminals (100) as described above may each include a communication module unit (110), a list generation unit (120), a labeling unit (130), a data collection unit (140), a preprocessing unit (150), a sentiment analysis unit (160), a security dictionary generation unit (170), an analysis module generation unit (180), a control unit (190), etc.
[0060] Here, the communication module unit (110) is a component that provides a wired / wireless communication environment by connecting through at least one communication module corresponding to a communication network (500). When performing a financial transaction through a user terminal (100), the user can connect to a financial institution server (300) through the communication network (500), and can connect to a specific website through the communication network (500) according to the operation of the user terminal (100).
[0061] Additionally, the communication module unit (110) can transmit user log information to the log collection server (200) under the control of the control unit (180).
[0062] The list generation unit (120) is a component that generates a domain list corresponding to multiple websites accessed through the communication module unit (110), and can generate the domain list by extracting domains corresponding to multiple websites accessed through the communication module unit (110) according to the operation of the user terminal (100).
[0063] Of course, the list generation unit (120) can extract the domain when accessing a specific website and generate a corresponding domain list.
[0064] The labeling unit (130) is a component that labels the domain list as one of normal, malicious, and caution, and can label each domain in the domain list transmitted from the list generation unit (120) as one of normal, malicious, and caution.
[0065] For example, the labeling unit (130) can label a domain that provides a security service for each domain in the domain list as secure, label a domain that does not have a security characteristic in either normal or malicious aspects as neutral, label a domain that indicates phishing, malicious, adult, etc. as malicious or caution, and label other domains as normal.
[0066] The data collection unit (140) is a component that crawls multiple websites included in the domain list to collect search results. It can crawl multiple websites included in the domain list, extract each HTML to create target data necessary for sentiment analysis within each website, and collect the search results.
[0067] The preprocessing unit (150) is a component that extracts target sentences for determining malicious URLs by preprocessing search results by performing plaintext parsing, labeling for maliciousness, removing stop words, and tokenizing, and may include a parsing block (151), a labeling block (152), a removal block (153), a tokenizing block (154), etc.
[0068] Here, the parsing block (151) is a block that performs plain text parsing for each English and Korean character for the search results transmitted from the data collection unit (140), and can extract each sentence by parsing the tag corresponding to the sentence in the HTML search results, and perform plain text parsing for each extracted sentence for each English and Korean character.
[0069] The labeling block (152) is a block that labels each sentence for which plaintext parsing is performed from the parsing block (151) as either normal, malicious, or caution. Sentences that indicate phishing, malicious, adult, etc. among the parsed sentences can be labeled as malicious or caution, and other sentences can be labeled as normal.
[0070] The removal block (153) is a block that analyzes morphemes for each labeled sentence transmitted from the labeling block (152) and then removes stop words. It can analyze morphemes for each sentence labeled as normal or malicious through a morphological analysis algorithm and then output the results by removing stop words such as unnecessary words and unnecessary adverbs that are unnecessary for sentiment analysis.
[0071] Here, morphological analysis algorithms can be used, for example, the longest match method, shortest path analysis, hidden markov model (HMM), conditional random fields (CRF), and deep learning models (e.g., recurrent neural network (RNN) model).
[0072] The tokenizing block (154) is a block that performs tokenizing on the output sentence transmitted from the removal block (153) to extract a target sentence. Tokenizing means cutting information to be predicted (e.g., sentence or utterance) into a specific basic unit. By performing tokenizing after removing all but adverbs, adjectives, verbs, and nouns corresponding to positive and negative words, the target sentence can be extracted and transmitted.
[0073] The sentiment analysis unit (160) is a component that performs keyword summary using a text summarization algorithm for sentiment analysis on a target sentence, and calculates keyword importance using a frequency calculation algorithm for sentiment analysis on the keyword summary. For example, the textRank algorithm can be used as the text summarization algorithm. At least one sequence for the target sentence is used as a vertex of a graph, an edge of the graph is added considering co-occurrence, and after repeatedly performing the textRank algorithm so as to converge on the importance of the initial vertex, keyword summary can be performed by sorting according to each importance and designating a preset number of vertices as keywords.
[0074] For example, sentiment analysis is a process of analyzing digital text to determine whether the emotional tone of the message is positive, negative, or neutral. By using a sentiment analysis tool, target sentences can be scanned and the writer's intention on the topic can be confirmed. If target sentences for different domains are obtained as shown in Figure 4, the sentiment analysis for sentence 1 can be used to determine that it is a trustworthy site, the sentiment analysis for sentence 2 can be used to determine that it is a site that requires caution, and the sentiment analysis for sentence 3 can be used to determine that it is a dangerous site with very low reliability.
[0075] That is, although sentence 1 contains the word 'scam', the word is negated by 'not a' + 'scam', and since the words 'legit and reliable' show reliability, the site can be judged to be a trustworthy site.
[0076] And, since sentence 2 contains words like 'trust score' and 'low', the site can be judged as a site that requires caution, and since sentence 3 contains 'very low' and 'trust score', the site can be judged as a dangerous site.
[0077] Meanwhile, since sentence 4 uses a negative word like 'anti' before 'malware', we can conclude that the site is not a malicious site.
[0078] Accordingly, the sentiment analysis unit (160) can use the textRank algorithm, which is a graph-based ranking algorithm, as a text summarization algorithm to extract keywords for sentiment analysis. A sequence (character combination) composed of at least one word for a target sentence can be used as a vertex of the graph, and a meaningful edge can be defined between the vertices to determine the importance for keyword extraction.
[0079] For example, the sentiment analysis unit (160) may tokenize a target sentence, perform POS (Part Of Speech) tagging to filter sequences consisting of at least one word, and add the filtered vertices to the graph. At this time, edges may also be added to account for co-occurrence.
[0080] In addition, the sentiment analysis unit (160) can set the importance of the initial vertex to 1 and repeatedly perform the textRank algorithm as shown in mathematical expression 1 below.
[0081]
[0082] Next, the sentiment analysis unit (160) can perform keyword summary by sequentially sorting the importance finally obtained through the repeatedly performed textRank algorithm from the highest score, extracting a preset number (Top-N) from the top, and then designating the corresponding vertices as keywords of the target sentence as shown in FIG. 5.
[0083] Meanwhile, the sentiment analysis unit (160) can use, for example, the BM25 algorithm based on the TF-IDF (Term Frequency-Inverse Document Frequency) algorithm as a frequency calculation algorithm. The keyword importance can be calculated through the BM25 algorithm, which is based on the TF-IDF algorithm calculated according to the word frequency and inverse document frequency for the keyword summary, but is corrected so that the IDF converges to 0 as the TF converges to the reference value.
[0084] For example, the sentiment analysis unit (160) can calculate keyword importance using the BM25 algorithm based on the TF-IDF algorithm. In a specific document group, an important word is not simply a word that appears frequently in the documents, but can be determined as a word that appears frequently only in a specific document. In order to extract an important word, it is necessary to consider not only the frequency of the word but also how many documents the word appears in, and for this purpose, the inverse document frequency (IDF) can be used.
[0085] TF-IDF using this IDF is a value that considers both word frequency and inverse document frequency, and can be expressed as the product of TF and IDF as shown in mathematical expression 2 below.
[0086]
[0087] In the above mathematical expression 2, IDF is a numerical value that indicates the degree to which a word appears in a group of documents. As shown in mathematical expression 3 below, it is a value obtained by dividing the entire document by the number of words in which the word appears and then taking the logarithm.
[0088]
[0089] Here, means the total number of documents, refers to the number of documents in which a specific word t appears, and since a larger IDF value indicates that the word appears in fewer documents, a word with a large TF-IDF value can be judged to be a word that appears only in specific documents among the entire document group, but frequently appears in those documents. In other words, the sentiment analysis unit (160) can judge that the word is suitable for the meaning of the extracted keyword.
[0090] In addition, the sentiment analysis unit (160) can use the BM25 algorithm based on the TF-IDF algorithm. However, since the TF-IDF has a very large variation in the keyword importance score according to the word appearance frequency (TF) and document length, it can cause a problem when calculating the keyword importance. Accordingly, the BM25 algorithm applies the basic principle of multiplying TF and IDF, but adds correction parameters to calculate the keyword importance as shown in the following mathematical expression 4.
[0091]
[0092] Here, the BM25 algorithm can reduce the influence of word frequency by converging TF to a specific value even if word frequency continues to increase, and can also reduce the influence of stop words by rapidly converging the keyword importance score to 0 as DF increases.
[0093] The biggest difference between the BM25 algorithm and TF-IDF is that it uses the average document length (avgdl) to calculate keyword importance, thereby reducing the influence of document length.
[0094] For example, the highest-weighted words in security labels are malicious negative words such as anti and protected.
[0095] The reason why the textRank algorithm and the BM25 algorithm are used together in the sentiment analysis unit (160) described above is that the reliability of the extracted keywords can be improved compared to when only one algorithm is used.
[0096] The security dictionary generation unit (170) is a component that generates a security dictionary for determining a malicious URL based on keyword summary and keyword importance, and can generate a security dictionary for determining a malicious URL using keyword summary and keyword importance. Each keyword in the security dictionary can be matched 1:1 with a vector value, and the size of the vector value can be determined and assigned based on the ranking of keyword importance calculated using the BM25 algorithm.
[0097] Here, the vector values assigned in the security dictionary are as follows: first, keywords with high keyword importance in the security label can be assigned a negative vector value, which is the opposite of the malicious label; second, keywords that appear frequently in most documents in the field of Web Security regardless of whether they are security labels or malicious labels and thus receive high keyword importance in both labels can be assigned a very low vector value; third, except for the second case, keywords that appear in the security label that overlap with keywords in the malicious label can be excluded from the security label dictionary; and fourth, considering the effect of the keyword, the vector value of the security keyword can be assigned a vector value that is twice the absolute value compared to the vector value of the malicious keyword.
[0098] The analysis module generation unit (180) is a component that extracts a malicious judgment criterion for determining a malicious URL by using a keyword vector value assigned corresponding to each keyword included in a security dictionary according to keyword importance and creates an analysis module. The malicious judgment criterion can be created by assigning a keyword vector value corresponding to each keyword included in a security dictionary according to keyword importance, calculating a malicious score using each keyword vector value for a collected document or sentence, and analyzing the calculated malicious score to determine a threshold value between labels.
[0099] This analysis module generation unit (180) can calculate the malicious score of a document or sentence by using the vector value assigned to the keyword (e.g., summation, etc.), analyze each calculated malicious score, extract a threshold value between labels (i.e., normal, malicious, caution), and generate and store the extracted threshold value as a malicious judgment criterion value.
[0100] Here, the extraction of the threshold value can be performed by finding and removing outliers among the malicious scores for each label using a statistical outlier calculation method including a modified Z-score, and extracting the threshold value between each label based on the outliers.
[0101] The control unit (190) controls the data processing of each component, and is a component that controls the communication module unit (110) to transmit the detection results detected by the malicious URL detection engine including the analysis module through the communication network (500), controls the list generation unit (120) to generate a domain list corresponding to a plurality of websites accessed through the communication module unit (110), controls the labeling unit (130) to label the domain list as one of normal, malicious, and caution, controls the data collection unit (140) to collect search results by crawling a plurality of websites included in the domain list, and controls the preprocessing unit (150) to extract target sentences for determining malicious URLs by preprocessing the search results by performing plaintext parsing, labeling as malicious, removing stop words, and tokenizing.
[0102] In addition, the control unit (190) can control the sentiment analysis unit (160) to perform keyword summary using a text summary algorithm for sentiment analysis on a target sentence, and then calculate keyword importance using a frequency calculation algorithm for sentiment analysis on the keyword summary, and can control the security dictionary generation unit (170) to generate a security dictionary for determining a malicious URL based on the keyword summary and keyword importance, and can control the analysis module generation unit (180) to generate an analysis module by extracting a malicious judgment criterion value for determining a malicious URL using a keyword vector value assigned corresponding to each keyword included in the security dictionary based on the keyword importance.
[0103] This control unit (180) can control the communication module unit (110) to transmit the detection results obtained through the malicious URL detection engine through the communication network (500). The detection results can include, for example, a malicious URL, user information of the terminal where the malicious URL occurred, the date and time of the malicious URL occurrence, etc.
[0104] For example, when a malicious URL detection engine receives a URL from multiple user terminals (100) or accesses a URL, the URL is transmitted to an analysis module generated through an analysis module generation unit (180), and the analysis module can detect whether the URL is normal, malicious, or a warning. In all user terminals (100) where the malicious URL detection engine is installed, detection of the URL can be performed in real time or continuously, and the detection results obtained therefrom can be transmitted to a log collection server (200).
[0105] Here, the detection process of this malicious URL detection engine is explained. The malicious URL detection engine including the analysis module can be installed in each of a plurality of user terminals (100), and when a URL is received in real time (or continuously) from any one of the plurality of user terminals (100) or accessed, the URL is transmitted to the analysis module of the malicious URL detection engine, and the search results for the URL transmitted from the analysis module can be collected similarly to the operation of the data collection unit (140), and the collected search results can be preprocessed similarly to the operation of the preprocessing unit (150) to extract a target sentence for determining a malicious URL.
[0106] In addition, it is possible to match keywords within the target sentence with the security dictionary already created within the analysis module, and compare the malicious score corresponding to the target sentence matched with the security dictionary with the malicious judgment standard value to determine whether the URL is normal, malicious, or cautionary.
[0107] Here, in the case of a URL judged to be malicious or suspicious, the detection result can be transmitted to the log collection server (200) to be collected and stored. The detection result can include, for example, a malicious URL, user information of the terminal where the malicious URL occurred, the date and time of the malicious URL occurrence, etc.
[0108]
[0109] The log collection server (200) is a server that collects detection results transmitted from multiple user terminals (100) through a communication network (500) and creates and stores user log information. The server can collect detection results transmitted from multiple user terminals (100) through a communication network (500) and create and store user log information.
[0110] When target log information corresponding to a suspicious transaction is requested from a financial institution server (300), the log collection server (200) can extract target log information corresponding to the user from the user log information of the log collection server (200) and transmit it to the financial institution server (300) via a communication network (500).
[0111]
[0112] The financial institution server (300) is a server operated by a financial institution that provides financial transaction services, and while monitoring all financial transactions through the installed abnormal transaction detection system (FDS), if a suspicious transaction using a financial transaction means is detected, the server requests target log information corresponding to the suspicious transaction to the log collection server (200) through a communication network (400), and if target log information is provided from the log collection server (200), it determines whether or not it is an abnormal transaction by considering a preset time range, and if it is determined to be an abnormal transaction, the suspicious transaction can be stopped.
[0113] For example, a financial institution server (300) can detect suspicious transactions using financial transaction means while monitoring all financial transactions through a fraud detection system (FDS), and can detect whether or not a transaction is fraudulent by checking whether financial transaction information is input through any one of multiple user terminals (100).
[0114] Here, financial transaction information may include, for example, credit card information (e.g., card number, password, CVC number, etc.) or internet banking information (e.g., internet banking ID, password, account number, public certificate password, security card number, etc.).
[0115] Specifically, the abnormal transaction detection system (FDS) of the financial institution server (300) can determine that the transaction pattern is a suspicious transaction if credit card information or internet banking information is input by accessing the financial institution server (300) from any one of multiple user terminals (100) and the information is repeatedly input periodically (for example, when access and financial transactions are attempted more than a preset number of times within a preset time).
[0116] In addition, the abnormal transaction detection system (FDS) of the financial institution server (300) can detect whether a transaction is suspicious based on the amount transferred in the financial transaction. In the case of account transfer, it can be confirmed that a large amount of money is suddenly transferred to the first target account that appears rather than the account that has been used for transactions or transfers in the past, and this case can be determined to be a suspicious transaction.
[0117] In addition, the abnormal transaction detection system (FDS) of the financial institution server (300) can check for suspicious transactions by considering the transfer amount, transfer account, and number of transfers. In the case of the transfer amount, if a transfer request is made for an amount higher than a preset amount (e.g., 5 million won, 10 million won, etc.), or if a transfer request is made for an amount higher than a preset percentage (e.g., 100%, etc.) of the highest amount among existing transfer transactions, the transaction can be determined to be suspicious.
[0118] In addition, the abnormal transaction detection system (FDS) of the financial institution server (300) can determine that a transaction is suspicious if a transfer request is made to an account that has not previously been transferred in the case of a transfer account, and in the case of the number of transfers, if multiple transfer requests are made in succession but the total amount is higher than a preset amount (e.g., 5 million won, 10 million won, etc.), or if the amount is higher than a preset percentage (e.g., 100%, etc.) of the highest amount among the existing transfer transactions, the transaction can be determined to be suspicious.
[0119] Meanwhile, the financial institution server (300)'s abnormal transaction detection system (FDS) can check for suspicious transactions by considering the transfer amount, transfer account, and number of transfers, as described above, even when a financial transaction is made through an ATM.
[0120] Detailed financial transaction information such as the transfer amount, transfer account, and number of transfers can be monitored by the abnormal transaction detection system (FDS) installed in the financial institution server (300) by obtaining permission in advance from multiple user terminals (100) and the financial institution server (300). Since this has been presented in various ways in the operation method of the abnormal transaction detection system (FDS) in the past, a detailed description thereof will be omitted.
[0121] Through the process described above, when the abnormal transaction detection system (FDS) of the financial institution server (300) detects a suspicious transaction, it can request target log information for a specific user (here, one of the multiple user terminals (100)) corresponding to the suspicious transaction from the log collection server (200) through the communication network (400).
[0122] Next, the abnormal transaction detection system (FDS) of the financial institution server (300) receives target log information from the log collection server (200), and, considering a preset time range (e.g., within 6 hours before and after the time of the suspicious transaction), determines whether the suspicious transaction is an abnormal transaction based on the result of determining whether the connected URL is a malicious URL, and if it is determined to be an abnormal transaction, the suspicious transaction can be stopped.
[0123] Here, the abnormal transaction detection system (FDS) of the financial institution server (300) can determine whether a transaction is abnormal based on the result of the malicious URL judgment included in the target log information, i.e., whether the terminal has accessed the malicious URL in the past 6 hours or what the malicious URL was accessed.
[0124]
[0125] The communication network (400) may include, for example, a mobile communication network, a wired Internet communication network, a wireless Internet communication network, a broadcasting network, an administrative network (closed network), etc., and specifically, may include one or more networks among a personal area network (PAN), a local area network (LAN), a campus area network (CAN), a metropolitan area network (MAN), a wide area network (WAN), a broadband network (BBN), the Internet, LoRaWAN, etc., and may include one or more network topologies including a bus network, a star network, a ring network, a mesh network, a star-bus network, a tree network, a hierarchical network, etc.
[0126] Through this communication network (400), a communication environment for wired and wireless data transmission and reception between user terminals (100), log collection servers (200), and financial institution servers (300) can be provided.
[0127]
[0128] Accordingly, according to one embodiment of the present invention, a sentiment analysis is performed on a plurality of websites accessed from a plurality of user terminals using a text summarization algorithm and a frequency calculation algorithm, and a security dictionary and a malicious judgment criterion for determining a malicious URL are extracted based on the results of the sentiment analysis obtained, thereby generating an analysis module, and the detection results detected through a malicious URL detection engine including the generated analysis module are collected by a log collection server to generate and store user log information, and then, when a suspicious transaction is detected during a financial transaction through a fraud detection system (FDS) installed on a financial institution server, target log information corresponding to the suspicious transaction is requested, and the target log information is extracted from the user log information, and then whether or not the transaction is malicious is determined based on the malicious judgment criterion of the fraud detection system (FDS), thereby effectively detecting and taking immediate action on fraudulent transactions due to telecommunication financial fraud in electronic finance, and preventing and preventing financial damage due to financial fraud.
[0129]
[0130] Figure 7 is a flowchart illustrating a process for detecting anomalous electronic financial transactions according to another embodiment of the present invention, and Figure 8 is a flowchart illustrating a specific process for detecting malicious URLs during the process for detecting anomalous electronic financial transactions according to another embodiment of the present invention. Since the specific details of detecting anomalous electronic financial transactions have been described in detail in one embodiment of the present invention, only a brief overview of the process will be provided.
[0131]
[0132] Referring to FIGS. 7 and 8, a domain list corresponding to multiple websites accessed through a communication network (500) from multiple user terminals (100) is created, and after labeling them as either normal, malicious, or caution, search results for multiple websites can be collected (step 601).
[0133]
[0134] In addition, the search results collected from multiple terminals (100) can be preprocessed to extract target sentences for determining malicious URLs (step 603).
[0135] In the step (603) of extracting the target sentence, the preprocessing unit (150) of the user terminal (100) can extract the target sentence for determining a malicious URL by performing plain text parsing, labeling for maliciousness, removing stop words, and tokenizing on the search result.
[0136] The step (603) of extracting the target sentence may include a step (603a) of performing plaintext parsing separately in English and Korean for the search results transmitted from the parsing block (151) of the preprocessing unit (150), a step (603b) of labeling each sentence transmitted from the parsing block (151) as normal, malicious, or caution in the labeling block (152) of the preprocessing unit (150), a step (603c) of analyzing morphemes in each labeled sentence transmitted from the labeling block (152) in the removal block (153) of the preprocessing unit (150) and then removing stop words, and a step (603d) of performing tokenization on the output sentence transmitted from the removal block (153) in the tokenizing block (154) of the preprocessing unit (150) to extract the target sentence.
[0137]
[0138] Next, sentiment analysis can be performed on target sentences extracted from multiple terminals (100) using a text summary algorithm and a frequency calculation algorithm (step 605).
[0139] In the step (605) of performing the above sentiment analysis, the sentiment analysis unit (160) of the user terminal (100) performs keyword summary using the textRank algorithm as a text summary algorithm for the target sentence, and calculates keyword importance using the BM25 algorithm based on the TF-IDF algorithm as a frequency calculation algorithm for the keyword summary.
[0140] Here, in the step (605) of performing the sentiment analysis, the sentiment analysis unit (160) uses at least one sequence for the target sentence as a vertex of the graph, adds an edge of the graph in consideration of co-occurrence, repeatedly performs the textRank algorithm to converge on the importance of the initial vertex, and then sorts the vertices according to each importance and designates a preset number of vertices as keywords, thereby performing keyword summary.
[0141] In addition, in the step (605) of performing the sentiment analysis, the sentiment analysis unit (160) calculates keyword importance based on the TF-IDF algorithm calculated based on the word frequency and inverse document frequency for the keyword summary, but corrects the BM25 algorithm so that the IDF converges to 0 while the TF converges to the reference value.
[0142]
[0143] Next, a security dictionary for determining malicious URLs can be created based on the results of sentiment analysis performed on multiple terminals (100) (step 607).
[0144] Here, a security dictionary generation unit (170) equipped in multiple terminals (100) can generate a security dictionary for determining a malicious URL using keyword summary and keyword importance. Each keyword in the security dictionary can be matched 1:1 with a vector value, and the size of the vector value can be determined and assigned according to the ranking of keyword importance calculated using the BM25 algorithm.
[0145]
[0146] In addition, an analysis module can be created by extracting a malicious judgment criterion value for determining a malicious URL using a security dictionary in multiple terminals (100) (step 609).
[0147] In the step (609) of generating the above analysis module, the analysis module generating unit (180) provided in the plurality of terminals (100) assigns a keyword vector value corresponding to each keyword included in the security dictionary according to keyword importance, calculates a malicious score using each keyword vector value for the collected document or sentence, and analyzes the calculated malicious score to determine a threshold value between labels, thereby generating a malicious judgment criterion value.
[0148]
[0149] Additionally, the detection results detected through a malicious URL detection engine including an analysis module generated from multiple terminals (100) can be transmitted (step 611).
[0150] In the step (611) of transmitting the above detection results, when a URL is received or accessed from multiple user terminals (100), the URL is transmitted to the analysis module, and detection of the URL can be performed in real time or continuously by detecting whether the URL is normal, malicious, or cautionary through the analysis module.
[0151] Here, the detection results may include, for example, a malicious URL, user information of the terminal where the malicious URL occurred, and the date and time when the malicious URL occurred.
[0152]
[0153] Next, the log collection server (200) can collect detection results and create and store user log information (step 613).
[0154]
[0155] Meanwhile, while monitoring all financial transactions through the abnormal transaction detection system (FDS) installed in the financial institution server, if a suspicious transaction using a financial transaction means is detected, target log information corresponding to the suspicious transaction can be requested to the log collection server (200) through the communication network (500) (step 615).
[0156]
[0157] And, the target log information can be extracted from the user log information in the log collection server (200) and transmitted through the communication network (500) (step 617).
[0158]
[0159] In addition, when target log information is provided from the log collection server (200) to the financial institution server (300), it is possible to determine whether or not an abnormal transaction is occurring by considering a preset time range (step 619).
[0160] Here, the abnormal transaction detection system (FDS) of the financial institution server (300) can determine whether a transaction is abnormal based on the result of the malicious URL judgment included in the target log information, i.e., whether the terminal has accessed the malicious URL in the past 6 hours or what the malicious URL was accessed.
[0161]
[0162] Next, if the financial institution server (300) determines that the transaction is abnormal, the suspicious transaction can be stopped (step 621).
[0163]
[0164] Accordingly, according to another embodiment of the present invention, a sentiment analysis is performed on a plurality of websites accessed from a plurality of user terminals using a text summarization algorithm and a frequency calculation algorithm, and a security dictionary and a malicious judgment criterion for determining a malicious URL are extracted based on the results of the sentiment analysis obtained, thereby generating an analysis module, and the detection results detected through a malicious URL detection engine including the generated analysis module are collected by a log collection server to generate and store user log information, and then, when a suspicious transaction is detected during a financial transaction through a fraud detection system (FDS) installed on a financial institution server, target log information corresponding to the suspicious transaction is requested, and the target log information is extracted from the user log information, and then whether or not the transaction is malicious is determined based on the malicious judgment criterion of the fraud detection system (FDS), thereby effectively detecting and taking immediate action on fraudulent transactions due to telecommunication financial fraud in electronic finance, and preventing and preventing financial damage due to financial fraud.
[0165]
[0166] Although the above description has presented and described various embodiments of the present invention, the present invention is not necessarily limited thereto, and a person having ordinary skill in the technical field to which the present invention pertains will easily understand that various substitutions, modifications, and changes are possible within a scope that does not depart from the technical spirit of the present invention.
[0167]
[0168] [Explanation of symbols]
[0169] 100: Multiple user terminals
[0170] 200: Log collection server
[0171] 300: Financial institution server
[0172] 400: Communications network
Claims
1. A plurality of user terminals that create a domain list corresponding to multiple websites accessed through a communication network, label the domains as either normal, malicious, or caution, collect search results for the multiple websites, preprocess the collected search results to extract target sentences for determining malicious URLs, perform sentiment analysis on the extracted target sentences using a text summarization algorithm and a frequency calculation algorithm, and then create and store a security dictionary for determining the malicious URL according to the results of the sentiment analysis, extract a malicious judgment criterion for determining the malicious URL using the security dictionary, create an analysis module, and transmit detection results detected by a malicious URL detection engine including the created analysis module through the communication network; A log collection server that collects the detection results transmitted from the plurality of user terminals and creates and stores user log information; and A financial institution server that, while monitoring all financial transactions through the installed fraud detection system (FDS), if a suspicious transaction using a financial transaction means is detected, requests target log information corresponding to the suspicious transaction to the log collection server through the communication network, and, if the target log information is provided from the log collection server, determines whether or not it is a suspicious transaction by considering a preset time range, and, if it is determined to be a suspicious transaction, stops the suspicious transaction; Electronic financial abnormal transaction detection system including .
2. In claim 1, The above multiple user terminals are each A communication module unit that provides a wired or wireless communication environment by connecting through at least one communication module corresponding to the above communication network; A list generation unit that generates the domain list corresponding to the plurality of websites accessed through the communication module unit; A labeling unit that labels the above domain list as one of normal, malicious, and caution; A data collection unit that crawls the multiple websites included in the above domain list and collects the search results; A preprocessing unit that extracts the target sentence for determining the malicious URL by preprocessing the search results by performing plaintext parsing, labeling whether or not they are malicious, removing stop words, and tokenizing; A sentiment analysis unit that performs keyword summary using the text summary algorithm for sentiment analysis on the target sentence, and calculates keyword importance using the frequency calculation algorithm for sentiment analysis on the keyword summary; A security dictionary generation unit that generates and stores the security dictionary for determining the malicious URL based on the keyword summary and keyword importance; An analysis module generation unit that generates the analysis module by extracting the malicious judgment criterion value for determining the malicious URL using the keyword vector value assigned corresponding to each keyword included in the security dictionary according to the keyword importance; and A control unit that controls data processing of each component and controls the communication module unit to transmit detection results detected by a malicious URL detection engine including the analysis module through the communication network; Electronic financial abnormal transaction detection system including .
3. In claim 2, The above preprocessing unit, A parsing block that performs plain text parsing for the search results transmitted from the data collection unit in English and Korean; A labeling block that labels each sentence on which plaintext parsing is performed as normal or malicious, transmitted from the parsing block; A removal block that analyzes morphemes for each labeled sentence transmitted from the labeling block and then removes stop words; and A tokenizing block that performs tokenization on an output sentence transmitted from the above removal block to extract the target sentence; Electronic financial abnormal transaction detection system including .
4. In claim 3, The above sentiment analysis section, The textRank algorithm is used as the text summarization algorithm above. Electronic financial fraud detection system.
5. In claim 4, The above sentiment analysis section, The keyword summary is performed by using at least one sequence for the target sentence as a vertex of the graph, adding edges of the graph by considering co-occurrence, repeatedly performing the textRank algorithm to converge on the importance of the initial vertex, and then sorting them according to each importance and designating a preset number of vertices as keywords. Electronic financial fraud detection system.
6. In claim 5, The above sentiment analysis section, The above frequency calculation algorithm uses the BM25 algorithm based on the TF-IDF (Term Frequency-Inverse Document Frequency) algorithm. Electronic financial fraud detection system.
7. In claim 6, The above sentiment analysis section, The keyword importance is calculated based on the TF-IDF algorithm calculated based on the word frequency and inverse document frequency for the keyword summary, but the BM25 algorithm is corrected so that the IDF converges to 0 as the TF converges to the reference value. Electronic financial fraud detection system.
8. In claim 7, The above analysis module generation unit is, The maliciousness judgment criterion is generated by calculating a maliciousness score using each keyword vector value for the collected document or sentence, and analyzing the calculated maliciousness score to determine a threshold value between labels. Electronic financial fraud detection system.
9. In claim 8, The above analysis module, When a URL is received from the above multiple user terminals or the URL is accessed, the URL is transmitted to the analysis module, and the URL is detected in real time or continuously through the analysis module in a manner of detecting whether the URL is normal, malicious, or cautionary. Electronic financial fraud detection system.
10. A step of creating a domain list corresponding to multiple websites accessed through a communication network from multiple user terminals, labeling them as either normal, malicious, or cautionary, and then collecting search results for the multiple websites; A step of preprocessing the collected search results from the plurality of terminals to extract target sentences for determining malicious URLs; A step of performing sentiment analysis on the target sentences extracted from the plurality of terminals using a text summary algorithm and a frequency calculation algorithm; A step of creating a security dictionary for determining the malicious URL based on the results of the sentiment analysis performed on the plurality of terminals; A step of extracting a malicious judgment criterion value for determining the malicious URL using the security dictionary in the plurality of terminals and creating an analysis module; A step of transmitting detection results detected through a malicious URL detection engine including the generated analysis module in the above multiple terminals; A step of collecting the above detection results from the log collection server and creating and storing user log information; A step of requesting target log information corresponding to the suspicious transaction to the log collection server through the communication network when a suspicious transaction using a financial transaction means is detected while monitoring the entire financial transaction through the abnormal transaction detection system (FDS) installed in the financial institution server; A step of extracting the target log information from the user log information in the log collection server and transmitting it through the communication network; A step of determining whether a transaction is abnormal by considering a preset time range when the target log information is provided from the log collection server to the financial institution server; A step of stopping the suspicious transaction if the financial institution server determines that the transaction is abnormal; A method for detecting abnormal electronic financial transactions including:
11. In claim 10, The step of extracting the above target sentence is: The preprocessing unit of the user terminal extracts the target sentence for determining the malicious URL by performing plaintext parsing, labeling for maliciousness, removing stop words, and tokenizing the search result. Method for detecting abnormal electronic financial transactions.
12. In claim 11, The step of extracting the above target sentence is: A step of performing plain text parsing for each of English and Korean on the search results transmitted from the parsing block of the above preprocessing unit; A step of labeling each sentence, for which plaintext parsing is performed and transmitted from the parsing block, as one of normal, malicious, and caution in the labeling block of the preprocessing unit; A step of analyzing morphemes for each labeled sentence transmitted from the labeling block in the removal block of the above preprocessing unit and then removing stop words; and A step of extracting the target sentence by performing tokenization on the output sentence transmitted from the removal block in the tokenizing block of the preprocessing unit; A method for detecting abnormal electronic financial transactions including:
13. In claim 12, The steps for performing the above sentiment analysis are: In the sentiment analysis unit of the user terminal, keyword summary is performed using the textRank algorithm as the text summary algorithm for the target sentence, and the sentiment analysis unit calculates keyword importance using the BM25 algorithm based on the TF-IDF (Term Frequency-Inverse Document Frequency) algorithm as the frequency calculation algorithm for the keyword summary. Method for detecting abnormal electronic financial transactions.
14. In claim 13, The steps for performing the above sentiment analysis are: In the sentiment analysis section, at least one sequence for the target sentence is used as a vertex of a graph, an edge of the graph is added by considering co-occurrence, and the textRank algorithm is repeatedly performed to converge on the importance of the initial vertex, and then the keyword summary is performed by sorting the vertices according to each importance and designating a preset number of vertices as keywords. Method for detecting abnormal electronic financial transactions.
15. In claim 14, The steps for performing the above sentiment analysis are: The keyword importance is calculated through the BM25 algorithm, which is based on the TF-IDF algorithm calculated based on the word frequency and inverse document frequency for the keyword summary in the above sentiment analysis section, but is corrected so that the IDF converges to 0 as the TF converges to the reference value. Method for detecting abnormal electronic financial transactions.
16. In claim 15, The steps for creating the above analysis module are: The analysis module generation unit provided in the above multiple terminals assigns a keyword vector value corresponding to each keyword included in the security dictionary according to the keyword importance, calculates a malicious score using each keyword vector value for the collected document or sentence, and generates the malicious judgment criterion value by analyzing the calculated malicious score to determine a threshold value between labels. Method for detecting abnormal electronic financial transactions.
17. In claim 16, The step of transmitting the above detection results is: When a URL is received from the above multiple user terminals or the URL is accessed, the URL is transmitted to the analysis module, and the URL is detected in real time or continuously through the analysis module in a manner of detecting whether the URL is normal, malicious, or cautionary. Method for detecting abnormal electronic financial transactions.
Citation Information
Patent Citations
Domain risk estimation system and method
JP2022063785A
Collected data sentiment analysis method and apparatus
KR101561464B1
System and method for realtime detection of abnormal financial transaction
KR1020160013733A
Detection and categorization of malicious urls
US20120158626A1
Text keyword extraction method, electronic device, and computer readable storage medium
US20230136368A1