Coalition Network Identification for Fraud Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to effectively detect fraudulent activity on a network level, as they primarily focus on entity- or event-level detection, which can be evaded by malicious entities using automated programs to spread fraudulent traffic across compromised systems, necessitating a method to identify coalition networks involved in fraudulent activities.

Innovation Solution

The approach involves identifying a first plurality of sets of event information associated with events, generating a network profile based on these events, and using clustering techniques to identify related entities, iteratively refining the identification of coalition networks until a threshold difference is reached, to detect fraudulent activity on a network level.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If entity-level or event-level detection methods are used, then the detection process is simpler, but fraudulent activity can be evaded by malicious entities spreading traffic across compromised systems

Engineering Contradiction:
Improvedetection process complexityVSAvoidfraudulent activity detection reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent transitions from entity-level or event-level detection to network-level detection by constructing network profiles that represent relationships between multiple entities and events. This dimensional shift allows the system to detect fraudulent coalitions that span across multiple compromised systems, preventing evasion tactics where malicious entities distribute fraudulent traffic across numerous individual systems.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent segments the detection process into distinct phases: identifying individual events and entities, constructing network profiles that capture relationships, generating representations from these profiles, and performing clustering analysis. This segmentation allows the complex network-level detection to be broken down into manageable steps while maintaining the ability to detect coordinated fraudulent activities.

Inventive Principle:
Principle #1Segmentation

2Reliability

If network-level detection is implemented, then fraudulent activity detection reliability improves, but the device complexity increases

Engineering Contradiction:
Improvefraudulent activity detection reliabilityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces network profiles as intermediary structures that capture relationships between entities and events. These profiles serve as a bridge between raw event data and clustering analysis, organizing complex relationship information in a structured format that facilitates network-level detection without requiring direct analysis of all individual entity interactions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent generates representations that are simplified copies or abstractions of the full network profiles. These representations capture essential relationship patterns while reducing data complexity, enabling efficient clustering analysis and coalition detection without processing the complete detailed network structure.

Inventive Principle:
Principle #26Copying

3Measurement precision

If clustering techniques are used to identify related entities, then the accuracy of coalition network identification improves, but the processing time increases

Engineering Contradiction:
Improvecoalition network identification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by constructing network profiles and generating representations before executing clustering analysis. This preprocessing organizes relationship data in advance, creating structured inputs that accelerate the clustering process and improve its accuracy by pre-highlighting relevant relationship patterns and entity connections.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11409581B2Coalition network identification
Publication Date: 2022.08.09 YAHOO ASSETS LLC
  • US11409581B2 patent drawing
  • US11409581B2 patent drawing
  • US11409581B2 patent drawing

AI summary

One or more computing devices, systems, and/or methods are provided. Event information associated with a plurality of events may be identified. The plurality of events may be associated with first entities corresponding to a first entity type and second entities associated with a second entity type. A first network profile associated with the first entities and the second entities may be generated based upon the event information. First representations associated with the first entities and second representations associated with the second entities may be generated based upon the first network profile. Clusters in the first representations and/or the second representations may be identified. One or more coalition networks associated with fraudulent activity may be identified based upon the clusters.