Cross-Customer Transaction Anomaly Detection for Malware Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security software often fails to detect sophisticated malicious threats such as Banking Trojan malware and ransomware, leading to potential significant monetary losses for financial account customers.

Innovation Solution

A system and method that uses machine-learning algorithms to detect anomalies in cross-customer financial transactions, identifies clusters of suspicious transactions, links affected accounts with customer threat protection accounts, and determines potential malware attacks by analyzing artifacts on user devices, ultimately performing security actions to protect against these threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security software monitors and reviews account data to detect suspicious activity, then basic fraudulent transactions may be identified, but sophisticated malware attacks (such as Banking Trojan and ransomware) evade detection

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple data sources (financial transaction data, device metadata, artifact information) and multiple analysis techniques (anomaly detection algorithms, machine learning models, clustering methods) into a unified security system. This integration allows the system to detect sophisticated malware attacks that individual monitoring components would miss, resolving the contradiction between detection accuracy and system complexity by creating a coordinated multi-component approach.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces cross-customer transaction analysis as a new dimension to traditional single-account security monitoring. By analyzing transactions across multiple customer accounts simultaneously and identifying patterns that span accounts, the system detects malware campaigns that would be invisible in isolated account reviews, improving detection accuracy without requiring fundamentally new complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of time

If security software flags unusual activity for subsequent communication to customers, then potential threats can be identified, but significant monetary losses occur before customers can respond

Engineering Contradiction:
Improveresponse timeVSAvoidfalse positive rate
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system performs preliminary actions by proactively identifying malware attacks through cross-customer pattern recognition before individual victims suffer significant losses. By detecting anomalies across multiple accounts and identifying coordinated attack patterns, the system can issue warnings to potentially affected customers before their accounts are compromised, reducing both response time and false positives through contextual awareness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where detected anomalies and confirmed malware patterns are fed back into the system to refine detection algorithms and update threat intelligence. This continuous learning process improves the system's ability to distinguish between legitimate unusual activity and actual malware attacks, reducing false positives while maintaining rapid response capabilities.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If machine-learning algorithms analyze cross-customer transactions to detect anomalies, then malware attack detection accuracy improves, but computational resources and processing time increase

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidcomputational energy
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent segments the large-scale cross-customer transaction analysis into manageable components: individual account anomaly detection, clustering of similar anomalies across accounts, and pattern recognition for malware identification. This segmentation allows the system to process data efficiently at each stage rather than analyzing all transactions simultaneously, reducing computational energy while maintaining high detection precision through progressive filtering and analysis.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12034764B1Systems and methods for detecting malware based on anomalous cross-customer financial transactions
Publication Date: 2024.07.09 GEN DIGITAL INC
  • US12034764B1 patent drawing
  • US12034764B1 patent drawing
  • US12034764B1 patent drawing

AI summary

The disclosed computer-implemented method for detecting malware based on anomalous cross-customer financial transactions may include (i) detecting, using a machine-learning algorithm, a set of anomalies associated with fraudulent financial transactions for source user accounts in a group of customer financial accounts, (ii) identifying, based on customer transaction metadata associated with a group of target user accounts in the customer financial accounts, a cluster of financial transactions having anomaly instances in common with the set of anomalies, (iii) linking each of the customer financial accounts having the common anomaly instances in the cluster of financial transactions with a corresponding customer threat protection account to discover a user device identification, (iv) determining that artifacts appearing on a group of user devices are associated with a potential malware attack, and (v) performing a security action that protects against the potential malware attack. Various other methods, systems, and computer-readable media are also disclosed.