Activity Threshold Determination for Fraud Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in accurately determining thresholds for identifying fraudulent and malicious activity from client devices, relying on manual methods that are inefficient and prone to inaccuracies.

Innovation Solution

Automatically determining thresholds by analyzing activity distributions, identifying peaks, and establishing relationships between them to set a target peak, which helps in identifying fraudulent activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual methods are used to determine activity thresholds, then the system can identify fraudulent activity, but the process is inefficient and prone to inaccuracies

Engineering Contradiction:
Improvethreshold determination accuracyVSAvoidthreshold determination efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system automatically determines activity thresholds by analyzing activity distributions and identifying peaks without human intervention. The processor independently performs statistical analysis on collected activity data, identifies peak activity levels, and sets thresholds based on these peaks, eliminating the need for manual threshold determination while improving both accuracy and efficiency

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system collects activity data from multiple client devices and performs analysis on a subset of this data to determine thresholds. By analyzing activity distributions from numerous devices and identifying peak patterns, the system derives thresholds that are sufficiently accurate without requiring exhaustive manual review of every data point

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If activity thresholds are set too low, then more fraudulent activity can be detected, but legitimate user activity may be blocked

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidfalse positive blocking
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system identifies multiple peaks in the activity distribution, each representing different levels of legitimate user behavior. By analyzing the relationships between these peaks and selecting an appropriate target peak, the system sets thresholds that are tailored to the specific activity patterns observed, ensuring that legitimate users at various activity levels are not incorrectly flagged

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system continuously monitors activity distributions and adjusts thresholds based on the identified peaks and their relationships. This feedback mechanism allows the system to learn from observed activity patterns and refine threshold settings over time, improving fraud detection accuracy while reducing false positives as the system becomes more familiar with legitimate user behavior ranges

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11102228B2System for determining whether activity of client device is malicious based on activity threshold
Publication Date: 2021.08.24 YAHOO ASSETS LLC
  • US11102228B2 patent drawing
  • US11102228B2 patent drawing
  • US11102228B2 patent drawing

AI summary

One or more computing devices, systems, and/or methods for determining thresholds are provided. For example, first activity associated with a plurality of client devices may be detected. A first activity distribution associated with the plurality of client devices may be determined based upon the first activity. A plurality of peaks of the first activity distribution may be identified. A plurality of gradients associated with pairs of peaks of the plurality of peaks may be determined. A target peak of the plurality of peaks may be determined based upon the plurality of gradients. A threshold amount of activity associated with the first activity may be determined based upon the target peak. A first set of activity associated with a first client device may be detected. A fraudulence label associated with the first client device may be determined based upon the first set of activity and/or the threshold amount of activity.