Blockchain Anomaly Detection via Behavioral Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting anomalous activities in blockchain networks, which offer user anonymity, are inefficient and lack real-time analysis capabilities, making it difficult to monitor and prevent financial crimes like money laundering and terrorist financing, especially since they do not effectively account for user-level statistics and transaction behavior with other users.

Innovation Solution

A system and method utilizing an anomaly detection engine that identifies users and generates data clusters based on transactional behavior, employing clustering techniques and anomaly detection algorithms to classify users into clusters with similar behavior, thereby identifying users with high anomaly detection values as potentially involved in anomalous activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user anonymity is maintained in blockchain networks, then user privacy is protected, but detection of anomalous activities becomes difficult

Engineering Contradiction:
Improveuser privacy protectionVSAvoidanomaly detection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces cluster analysis as an intermediary layer between anonymous blockchain transactions and anomaly detection. Instead of directly analyzing individual transactions, the system groups transactions into clusters based on behavioral patterns, using these clusters as mediators to detect anomalies while preserving user anonymity. The cluster-level analysis allows detection of suspicious patterns without exposing individual user identities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If cluster analysis is used for anomaly detection, then some anomaly detection capability is achieved, but detection accuracy is insufficient without user-level data

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidanomaly detection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent transitions from traditional single-dimension transaction analysis to multi-dimensional cluster-based analysis. By introducing cluster membership, cluster density, and behavioral pattern dimensions, the system enriches the analysis framework. This dimensional expansion allows accurate anomaly detection using only transaction data, eliminating the need for external user-level data while improving detection precision.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Speed

If real-time analysis is implemented, then anomaly detection timeliness is improved, but computational complexity and cost increase

Engineering Contradiction:
Improveanomaly detection timelinessVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent segments the blockchain network into multiple clusters based on transactional behavior patterns. This segmentation allows parallel processing of cluster analyses, reducing the computational burden on any single system component. By dividing the monolithic anomaly detection task into smaller cluster-level tasks, the system achieves real-time detection capability while managing computational complexity through distributed, modular processing.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10484413B2System and a method for detecting anomalous activities in a blockchain network
Publication Date: 2019.11.19 COGNIZANT TECH SOLUTIONS INDIA PVT LTD
  • US10484413B2 patent drawing
  • US10484413B2 patent drawing
  • US10484413B2 patent drawing

AI summary

A system and a method for detecting anomalous activities in a distributed and decentralised network is provided. Anonymous users transacting in the network are identified and one or more transactional attributes are retrieved to define characteristics of users and associated transactional behaviour with other users. Further, user-level statistics are evaluated based on transactional attributes. Datatype representative of transactional behavior of users with other users is generated using user-level statistics of identified users. Users with similar transactional behavior are classified based on generated transactional attributes. One or more anomaly detection techniques are implemented for identifying optimum classification of users into data clusters based on the change detected in the classification of users in data clusters. Anomalous users are identified from the optimum classification for efficiently and effectively detecting anomalous activities in the network.