Coalition Network Identification for Fraud Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to effectively detect fraudulent activity on a network level, as they primarily focus on entity- or event-level detection, which can be evaded by malicious entities using automated programs to spread fraudulent traffic across compromised systems, necessitating a method to identify coalition networks involved in fraudulent activities.
Innovation Solution
The approach involves identifying a first plurality of sets of event information associated with events, generating a network profile based on these events, and using clustering techniques to identify related entities, iteratively refining the identification of coalition networks until a threshold difference is reached, to detect fraudulent activity on a network level.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If entity-level or event-level detection methods are used, then the detection process is simpler, but fraudulent activity can be evaded by malicious entities spreading traffic across compromised systems
Solution Approach 1:
The patent transitions from entity-level or event-level detection to network-level detection by constructing network profiles that represent relationships between multiple entities and events. This dimensional shift allows the system to detect fraudulent coalitions that span across multiple compromised systems, preventing evasion tactics where malicious entities distribute fraudulent traffic across numerous individual systems.
Solution Approach 2:
The patent segments the detection process into distinct phases: identifying individual events and entities, constructing network profiles that capture relationships, generating representations from these profiles, and performing clustering analysis. This segmentation allows the complex network-level detection to be broken down into manageable steps while maintaining the ability to detect coordinated fraudulent activities.
2Reliability
If network-level detection is implemented, then fraudulent activity detection reliability improves, but the device complexity increases
Solution Approach 1:
The patent introduces network profiles as intermediary structures that capture relationships between entities and events. These profiles serve as a bridge between raw event data and clustering analysis, organizing complex relationship information in a structured format that facilitates network-level detection without requiring direct analysis of all individual entity interactions.
Solution Approach 2:
The patent generates representations that are simplified copies or abstractions of the full network profiles. These representations capture essential relationship patterns while reducing data complexity, enabling efficient clustering analysis and coalition detection without processing the complete detailed network structure.
3Measurement precision
If clustering techniques are used to identify related entities, then the accuracy of coalition network identification improves, but the processing time increases
Solution Approach 1:
The patent performs preliminary actions by constructing network profiles and generating representations before executing clustering analysis. This preprocessing organizes relationship data in advance, creating structured inputs that accelerate the clustering process and improve its accuracy by pre-highlighting relevant relationship patterns and entity connections.
Data Source
AI summary
One or more computing devices, systems, and/or methods are provided. Event information associated with a plurality of events may be identified. The plurality of events may be associated with first entities corresponding to a first entity type and second entities associated with a second entity type. A first network profile associated with the first entities and the second entities may be generated based upon the event information. First representations associated with the first entities and second representations associated with the second entities may be generated based upon the first network profile. Clusters in the first representations and/or the second representations may be identified. One or more coalition networks associated with fraudulent activity may be identified based upon the clusters.


