Behavior Analysis System for Fraudulent Transaction Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing remote bank transactions are inadequate as they can be vulnerable to fraudulent activities, even with multifactor authentication, as malicious software can mimic user behavior, compromising account security.

Innovation Solution

A system that collects user behavior data through a computing device's graphical interface, calculates an anomalous user behavior coefficient, and blocks interactions with a remote bank server if fraudulent activity is detected, using a processor to classify behavior patterns and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multifactor authentication is used, then account security is improved, but the system becomes vulnerable to fraudulent activities when criminals have access to all authentication devices

Engineering Contradiction:
Improveaccount securityVSAvoidfraudulent activity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary layer between authentication and transaction execution. A behavior analysis module monitors user interactions with graphical interface elements and calculates anomaly coefficients, acting as a mediator that can block transactions even when authentication succeeds, thereby protecting against fraudulent activities where criminals have access to authentication devices

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous feedback by monitoring user behavior patterns during transaction processes. The behavior analysis module collects data on user interactions, calculates anomaly coefficients in real-time, and provides feedback to the transaction processing system, enabling dynamic adjustment of security measures based on observed behavior rather than static authentication credentials

Inventive Principle:
Principle #23Feedback

2Measurement precision

If behavior monitoring and analysis are implemented, then fraudulent activity detection is improved, but system complexity increases

Engineering Contradiction:
Improvefraudulent activity detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The behavior analysis system is segmented into distinct functional modules: a behavior data collection module that gathers interaction data, a behavior analysis module that calculates anomaly coefficients, and a transaction control module that executes blocking decisions. This segmentation allows each module to perform a specific function with optimized complexity, reducing overall system complexity while maintaining detection accuracy

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transforms complex behavioral data into simplified parameter representations through anomaly coefficients. By converting diverse user interaction patterns into standardized coefficient values that can be compared against thresholds, the system achieves high detection precision without requiring complex analysis algorithms, thereby reducing system complexity

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10943235B2System and method of software-imitated user transactions using machine learning
Publication Date: 2021.03.09 AO KASPERSKY LAB
  • US10943235B2 patent drawing
  • US10943235B2 patent drawing
  • US10943235B2 patent drawing

AI summary

Systems and methods for detecting fraudulent activity in user transactions. An exemplary method includes, by a hardware processor, receiving user behavior data provided by an input device specifying a user interaction with graphical user interface (GUI) elements of a first application on a computing device for a transaction with a remote server, training a behavior classification algorithm using known behavior of the user, calculating an anomalous user behavior coefficient based on the user behavior data and the behavior classification algorithm, wherein the anomalous user behavior coefficient represents a likelihood that the user's interaction with the plurality of groups of elements of the graphical interface was fraudulent, detecting whether the user interaction is a software-imitated user interaction based on the anomalous user behavior coefficient, and responsive to detecting a software-imitated user interaction, blocking the transaction with the remote server.