Browser Injection Module for Fraudulent Money Transfer Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to effectively detect and prevent fraudulent money transfers from a victim's infected computer to a mule account, as malware operates invisibly within bank webpages, making it difficult to track and incriminate fraudsters, and mule accounts are often used in a chain of fraudulent activities.

Innovation Solution

A detection software module is injected into the browser or website to monitor webpage activities, detect exceptional conditions indicative of malware, and prevent fraudulent transactions by blocking or reporting them, while also identifying and aggregating mule accounts used in such transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If malware operates invisibly within bank webpages to perform fraudulent transfers, then the fraudster's ability to execute undetected transactions is improved, but the detection capability of the system deteriorates

Engineering Contradiction:
Improvefraudulent transaction executionVSAvoidmalware detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies the principle of color changes by making the invisible IFrame visible through detection software. The detection module identifies the presence of invisible IFrames that malware uses to perform fraudulent transactions, effectively changing the 'visibility state' from hidden to detected, allowing the system to see and block the fraudulent activity while maintaining the bank webpage's normal appearance to legitimate users

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The patent employs an intermediary approach by introducing detection software as a mediator between the user's browser and the malware-operated IFrame. This detection module acts as a middle layer that monitors and analyzes webpage activities, identifying suspicious patterns without interfering with legitimate banking operations, thereby detecting fraudulent attempts while allowing normal transactions to proceed

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If mule accounts are used as intermediaries in fraudulent activity chains, then the fraudster's ability to obscure their identity is improved, but the ability to track and incriminate fraudsters deteriorates

Engineering Contradiction:
Improvefraudster identity protectionVSAvoidfraudster tracking
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback by creating a closed-loop system where detection software continuously monitors transactions, identifies mule account usage patterns, and feeds this information back to law enforcement authorities. The system aggregates data from multiple transactions and accounts, providing cumulative evidence that progressively builds a case against fraudsters despite the use of intermediary mule accounts

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies merging by combining multiple data points from various transactions, accounts, and detection events into a unified fraud detection profile. By aggregating information across multiple mule accounts and transaction patterns, the system creates a comprehensive view that links otherwise isolated fraudulent activities to their originators, enabling effective tracking despite the use of intermediary accounts

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If detection software monitors all webpage activities to identify fraudulent transactions, then the accuracy of fraud detection is improved, but the processing time and system complexity deteriorate

Engineering Contradiction:
Improvefraud detection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies partial action by implementing selective monitoring that focuses detection resources on specific high-risk indicators rather than analyzing every single webpage element. The detection software targets particular patterns such as invisible IFrame creation, unusual transaction routes, and mule account characteristics, achieving effective fraud detection without the need to process and analyze every possible webpage activity in detail

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8725636B1Method for detecting fraudulent money transfer
Publication Date: 2014.05.13 ARKOSE LABS HOLDINGS INC
  • US8725636B1 patent drawing
  • US8725636B1 patent drawing

AI summary

A method detects fraudulent transaction of money transfer to a mule account, according to which a detection software module is injected into a browser or a website to be protected. The detection module traces the content and the activities performed on a webpage of the website and detects any exceptional activity/condition which may be fraudulent online activity performed by malware and waits until all sensitive data to perform a fraud transaction is entered. Then the detection module stores and/or forwards the details of the mule account that has been used for the fraudulent transaction.