Account Graph Link Analysis for Cybersecurity Breach Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Financial institutions face challenges in detecting synthetic accounts and account takeovers, which are forms of cybersecurity breaches that involve fraudulent activities, as existing systems struggle to identify linked compromised accounts effectively.

Innovation Solution

A method and system that utilize electronic account data to generate nodes and edges representing accounts and their metadata, applying link analysis methods like PageRankā„¢ to determine a ranking of accounts, identifying those likely to be associated with a cybersecurity breach by constructing visual network graphs and scoring potentially compromised accounts based on their proximity to flagged accounts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional account monitoring systems are used to detect fraudulent accounts, then the system is simple to operate, but the detection precision of synthetic accounts and account takeovers is insufficient

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transitions from traditional linear account monitoring to a multi-dimensional network graph approach. Accounts are represented as nodes and relationships as edges in a graph structure, enabling detection across multiple dimensions including transaction patterns, device relationships, location data, and temporal sequences. This dimensional expansion allows the system to identify synthetic accounts and takeovers by analyzing complex interconnections that single-dimension systems miss.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system dynamically adjusts detection parameters including risk thresholds, time windows for pattern analysis, and weighting factors for different metadata types. The graph-based approach enables continuous parameter optimization as new fraudulent patterns emerge, with the ability to modify edge weight calculations, node importance metrics, and ranking algorithms based on evolving threat landscapes while maintaining operational flexibility.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If advanced link analysis methods are applied to rank accounts, then the detection reliability improves, but the computational time and processing complexity increase

Engineering Contradiction:
Improvedetection reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-computes and stores graph structures, node attributes, and edge relationships in optimized data formats before actual detection is needed. Metadata is aggregated and normalized in advance, and the graph database is pre-indexed to enable rapid traversal during detection operations. This preliminary preparation significantly reduces real-time processing requirements while maintaining high detection reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The graph-based detection system automatically updates its own structure as new accounts and transactions are added, continuously refining its detection capabilities without manual intervention. The system self-optimizes by learning from detected patterns, automatically adjusting edge weights and node priorities based on confirmed fraudulent cases, thereby improving reliability over time while requiring minimal additional processing resources.

Inventive Principle:
Principle #25Self-service

3Quantity of substance

If graph-based network analysis is used to identify connected compromised accounts, then the quantity of detected fraudulent accounts increases, but the device complexity for implementing the system increases

Engineering Contradiction:
Improvenumber of detected accountsVSAvoidsystem complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent introduces a graph database as an intermediary layer between raw account data and detection algorithms. This graph structure serves as a mediator that naturally represents complex relationships without requiring complex query logic in the detection system itself. The graph database handles the complexity of traversing and analyzing interconnected accounts, while the detection layer operates on simplified graph operations, thereby enabling detection of large numbers of connected fraudulent accounts without proportionally increasing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12438896B2Method and system for detecting a cybersecurity breach
Publication Date: 2025.10.07 ROYAL BANK OF CANADA
  • US12438896B2 patent drawing
  • US12438896B2 patent drawing
  • US12438896B2 patent drawing

AI summary

Methods, systems, and techniques for detecting a cybersecurity breach. The cybersecurity breach may be a synthetic account or an account having been subjected to an account takeover. Electronic account data representative of accounts is obtained in which a first group of the accounts includes accounts flagged as being associated with the breach, and a second group of the accounts includes a remainder of the accounts. The computer system generates from the account data nodes representing the accounts and edges based on account metadata that connect the nodes. The computer system determines, such as by applying a link analysis method to the nodes and edges, a ranking of the accounts of at least part of the second group indicative of a likelihood that those accounts are also associated with the cybersecurity breach. That ranking may be used to identify which of those accounts is also identified with the cybersecurity breach.