Beacon Server Network for Online Fraud Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Online fraud detection systems face challenges in accurately identifying man-in-the-middle attacks and IP spoofing, which compromise the security of online transactions, especially in environments where accessing low-level transport protocol information is difficult or costly.
Innovation Solution
A real-time fraud detection system that uses a combination of beacon servers and a trained neural network to monitor HTTP conversations, collect detailed IP and TCP packet header information, and recognize user behavior, thereby detecting changes indicative of fraudulent activities without requiring direct access to the web server's communication channel.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If direct access to web server communication channels is used to collect fraud detection information, then measurement precision is improved, but device complexity and implementation cost increase
Solution Approach 1:
The patent introduces beacon servers as intermediary components that indirectly observe and collect communication metadata (IP addresses, packet headers, timing information) without requiring direct access to the web server's communication channels. This mediator approach enables fraud detection while avoiding the complexity of deep packet inspection or direct channel access.
Solution Approach 2:
The patent replaces direct mechanical/access-based information collection methods with statistical and behavioral analysis techniques. Instead of directly intercepting communications, the system uses beacon servers to collect metadata and applies neural networks to analyze user behavior patterns, substituting physical access requirements with computational analysis.
2Reliability
If comprehensive packet header information is collected for fraud detection, then reliability is improved, but loss of information and processing overhead increase
Solution Approach 1:
The patent extracts only the essential and most informative packet header fields (IP addresses, ports, timing data) required for fraud detection, rather than collecting and processing complete packet contents. This selective extraction reduces data volume and processing overhead while maintaining detection reliability.
Solution Approach 2:
The patent collects slightly more information than strictly necessary by monitoring multiple beacon servers and gathering various packet header fields, then uses neural network filtering to identify the most relevant features. This partial excess approach ensures sufficient data is captured for reliable detection while the system processes only what is needed.
3Reliability
If multiple geographically dispersed beacon servers are deployed to detect man-in-the-middle attacks, then detection capability is improved, but device complexity and infrastructure cost increase
Solution Approach 1:
The patent divides the fraud detection function into multiple geographically dispersed beacon servers, each independently collecting local communication metadata. This segmentation allows the system to detect man-in-the-middle attacks by comparing data from multiple locations while distributing infrastructure complexity across independent nodes rather than requiring a single complex centralized system.
Solution Approach 2:
The beacon servers are designed as universal, multi-functional components that can be deployed in various geographic locations and perform the same core functions (collecting packet headers, timing information, and IP data). This universality simplifies infrastructure management while enabling distributed detection capabilities across multiple locations.
Data Source
AI summary
A fraud detection and protection method and system are disclosed. The method and system utilize a fraud detection and protection server to monitor online commercial transactions between a webserver and a client computer, and generate a risk assessment of a user associated with the client computer. The system and method further utilize a number of beacon servers geographically dispersed in an area. Each beacon server is configured to receive packet header information associated with the online commercial transactions, analyze the packet header information for authenticating information, and send the authenticating information to the fraud detection and protection server for the risk assessment.


