Behavioral and Account Fingerprinting for Fraud Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for identifying fraudulent behavior in online software services are cumbersome due to the complexity of monitoring numerous activities, making it difficult to extrapolate general results and detect potential security risks.
Innovation Solution
Implementing a process for behavioral and account fingerprinting that monitors specific user interactions, logs activities with associated properties, and analyzes these to detect computer security risk fingerprints, triggering appropriate security actions based on predefined specifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional tools are used to piece together different activities and their timing to identify fraudulent behavior, then security review capability is maintained, but the process becomes tedious and difficult to extrapolate general results
Solution Approach 1:
The patent segments the complex monitoring task into distinct components: individual activity detection, activity logging with properties, fingerprint specification definition, and pattern matching. Each component handles a specific aspect of fraud detection, making the overall system more manageable and scalable while maintaining detection accuracy.
Solution Approach 2:
The patent creates fingerprints as simplified copies or representations of fraudulent behavior patterns. Instead of manually analyzing each individual activity sequence, the system creates reusable fingerprint templates that capture the essential characteristics of fraudulent patterns, enabling efficient comparison and detection across multiple cases.
2Reliability
If numerous user activities are monitored to improve security detection, then fraudulent pattern identification capability is enhanced, but the complexity of monitoring and analyzing these activities increases
Solution Approach 1:
The patent extracts only the relevant activities and properties needed for fraud detection from the vast universe of user activities. By defining specific activity specifications and selecting only pertinent properties (such as timing, sequence, and specific activity types), the system reduces analysis complexity while maintaining detection reliability.
Solution Approach 2:
The patent performs preliminary actions by pre-defining fingerprint specifications that encode knowledge about fraudulent patterns. These specifications are created in advance based on security expertise, allowing the system to automatically match monitored activities against known fraud patterns without requiring complex real-time analysis.
3Loss of information
If detailed logging of all monitored activities is performed for security review, then complete security analysis is enabled, but data processing burden and analysis time increase
Solution Approach 1:
The patent applies local quality by logging and analyzing only specific properties of activities that are relevant to fraud detection, rather than processing all possible activity attributes. Each activity is logged with selectively chosen properties based on the fingerprint specification, reducing data volume while preserving essential security information.
Solution Approach 2:
The patent uses partial action by focusing on detecting specific fraudulent patterns rather than attempting to analyze all possible security scenarios. The system logs and processes only the subset of activities that match defined fingerprint specifications, enabling faster detection of known fraud patterns without the burden of comprehensive analysis.
Data Source
AI summary
Activity specifications of a plurality of activities to be monitored are received. Each activity specification of the activity specifications identifies properties of a corresponding activity of the activities to be monitored. A fingerprint specification of a computer security risk fingerprint is received. The fingerprint specification identifies a combination of two or more of the activities to be detected. A log of activities to identify occurrences of the activities to be monitored is analyzed. Based on the analysis, the computer security risk fingerprint in the log of activities is detected, including by detecting an occurrence of at least a portion of the combination of the activities identified by the fingerprint specification. A computer security action based on the detection of the computer security risk fingerprint is performed.


