Breach Detection System Using Merged PAN Data Records

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for identifying compromised data breaches are expensive and only operate after a fraudulent transaction has occurred, requiring the analysis of vast amounts of data, which is inefficient and reactive rather than proactive.

Innovation Solution

A database system that organizes data records by merging transaction data from multiple institutions with dump site data to create unique and multiple PAN data records, allowing for separate evaluation to identify breached systems before fraudulent transactions occur, using a multi-institution database, an extracted database, a unique PAN database, and a multiple PAN database.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If prior systems analyze vast amounts of transaction data to identify breaches, then breach identification accuracy is improved, but system cost and processing time increase significantly

Engineering Contradiction:
Improvebreach identification accuracyVSAvoidvolume of data to be analyzed
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system performs preliminary actions by proactively monitoring for indicators of compromise (IOCs) such as compromised credentials, leaked data, and suspicious login patterns before actual fraudulent transactions occur. This allows the system to identify breaches early by analyzing security logs and authentication data rather than waiting for and analyzing vast transaction volumes after fraud occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts and analyzes only the critical security-related data elements necessary for breach detection, such as authentication logs, login locations, device information, and credential patterns, rather than analyzing entire transaction databases. This extraction approach maintains high breach identification accuracy while significantly reducing the volume of data that needs to be processed.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If prior systems wait for fraudulent transactions to occur before identifying breaches, then operational simplicity is maintained, but response time is delayed and preventive action is lost

Engineering Contradiction:
Improvesystem operational simplicityVSAvoidbreach detection time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system implements preliminary action by continuously monitoring security indicators and authentication patterns in real-time, enabling it to detect breaches before they result in fraudulent transactions. The system proactively identifies compromised accounts by analyzing login behaviors, geographic anomalies, and credential patterns, allowing preventive action to be taken before financial loss occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system employs feedback mechanisms that continuously monitor security events and provide real-time alerts when breach indicators are detected. This feedback loop enables the system to respond dynamically to emerging threats, adjusting monitoring parameters and triggering alerts based on detected patterns, thereby maintaining operational simplicity while achieving proactive breach detection.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive data analysis is performed to identify all compromised accounts, then detection completeness is improved, but processing cost and complexity increase

Engineering Contradiction:
Improvedetection completenessVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies local quality by tailoring its monitoring and analysis focus to specific high-risk indicators and data elements most indicative of breaches, such as authentication failures, unusual login patterns, and compromised credential patterns. Rather than uniformly analyzing all data, the system concentrates resources on these critical local areas, maintaining detection completeness for breach identification while reducing overall processing complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system segments its data processing into distinct modules that handle different types of security indicators separately, such as authentication monitoring, credential analysis, and behavior pattern detection. This segmentation allows each module to process specific data types with specialized algorithms, improving detection completeness for various breach types while managing processing complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11403425B2System and method for storing data used by breach detection systems
Publication Date: 2022.08.02 FIRST DATA CORP
  • US11403425B2 patent drawing
  • US11403425B2 patent drawing
  • US11403425B2 patent drawing

AI summary

A system for detecting breach of merchant systems includes an extraction management system for extracting wildcard data from a dump site at which stolen account data is offered for sale. The system also includes an account breach identifying system for accessing stored transaction data from multiple banks and merging the extracted dump site data with the transaction data to create unique PAN (primary account number) data records (each set of wildcard data corresponds to only a single PAN) and multiple PAN data records (each set of wildcard data corresponds to multiple PANs). The unique and multiple PAN data records are stored and analyzed separately, and reduce the amount of data needed to identify a breached merchant.