Attack Narrative Tree for Fraud Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in detecting and mitigating fraudulent attempts to access computer systems, as fraud techniques constantly evolve and new trends emerge, making it difficult to effectively identify and prevent fraudulent electronic transactions.
Innovation Solution
The method involves determining factors indicative of fraudulent electronic transactions by grouping transactions based on various variables and calculating a concentration of loss factor. This information is used to build an attack narrative tree (ANT) that identifies high-risk transactions and helps in flagging or blocking potentially fraudulent activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional fraud detection methods are used, then the system can process transactions, but the accuracy of detecting fraudulent transactions is insufficient
Solution Approach 1:
The patent segments the fraud detection process into multiple hierarchical levels using an attack narrative tree structure. Transactions are divided into groups based on various variables (device, location, behavior patterns), and each segment is analyzed independently to calculate concentration of loss factors. This segmentation allows the system to focus computational resources on high-risk segments while maintaining overall detection accuracy.
Solution Approach 2:
The patent introduces a new dimensional approach by calculating concentration of loss factors that combine both the percentage of fraudulent transactions and the percentage of fraudulent amounts within each group. This dual-dimensional metric (frequency + value) provides a more comprehensive view of fraud risk than traditional single-metric approaches, enabling more accurate identification of high-risk transaction patterns.
2Measurement precision
If comprehensive analysis of all transaction variables is performed, then fraud detection accuracy improves, but system complexity increases
Solution Approach 1:
The system divides the complex task of analyzing all transaction variables into manageable segments by creating an attack narrative tree. Each node in the tree represents a specific variable or group of variables, and the tree structure organizes the analysis hierarchy. This segmentation reduces computational complexity by processing variables in a structured, step-by-step manner rather than analyzing all variables simultaneously.
Solution Approach 2:
The patent applies local quality by calculating concentration of loss factors for specific groups of transactions based on particular variable combinations, rather than uniformly analyzing all transactions with the same depth. The system focuses computational effort on groups showing higher fraud indicators, adjusting the level of analysis locally to match the suspected risk level of each transaction group.
3Measurement precision
If multiple variables and grouping methods are used to identify fraudulent transactions, then detection accuracy improves, but processing time increases
Solution Approach 1:
The system performs preliminary actions by pre-calculating and storing concentration of loss factors for different transaction groups during off-peak periods or as transactions are received. This pre-computation allows the system to quickly retrieve and compare pre-analyzed group characteristics during actual transaction processing, significantly reducing real-time processing time while maintaining high detection accuracy.
Solution Approach 2:
By segmenting transactions into predefined groups based on key variables (device type, geographic location, time patterns), the system can process and analyze each segment independently and in parallel. This segmentation enables the system to handle multiple variables efficiently by distributing the computational load across different transaction groups rather than processing all variables for all transactions sequentially.
Data Source
AI summary
A method includes determining for each one of at least two variables associated with each one of a plurality of electronic transactions, at least a first group of the plurality of electronic transactions and a second group of the plurality of electronic transactions. The method further includes determining, for each of the at least the first group of transactions and the second group of transactions, a factor indicative of both a percentage of electronic transactions in a group that are fraudulent and a percentage of a total amount associated with the electronic transactions in the group that are fraudulent. The method further includes determining a subset of the plurality of electronic transactions based on a variable of the at least two variables having or exceeding a predetermined threshold value. The predetermined threshold value is determined based on the factor of the first group and the second group.


