Cross-Customer Transaction Anomaly Detection for Malware Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security software often fails to detect sophisticated malicious threats such as Banking Trojan malware and ransomware, leading to potential significant monetary losses for financial account customers.
Innovation Solution
A system and method that uses machine-learning algorithms to detect anomalies in cross-customer financial transactions, identifies clusters of suspicious transactions, links affected accounts with customer threat protection accounts, and determines potential malware attacks by analyzing artifacts on user devices, ultimately performing security actions to protect against these threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security software monitors and reviews account data to detect suspicious activity, then basic fraudulent transactions may be identified, but sophisticated malware attacks (such as Banking Trojan and ransomware) evade detection
Solution Approach 1:
The patent combines multiple data sources (financial transaction data, device metadata, artifact information) and multiple analysis techniques (anomaly detection algorithms, machine learning models, clustering methods) into a unified security system. This integration allows the system to detect sophisticated malware attacks that individual monitoring components would miss, resolving the contradiction between detection accuracy and system complexity by creating a coordinated multi-component approach.
Solution Approach 2:
The patent introduces cross-customer transaction analysis as a new dimension to traditional single-account security monitoring. By analyzing transactions across multiple customer accounts simultaneously and identifying patterns that span accounts, the system detects malware campaigns that would be invisible in isolated account reviews, improving detection accuracy without requiring fundamentally new complexity.
2Loss of time
If security software flags unusual activity for subsequent communication to customers, then potential threats can be identified, but significant monetary losses occur before customers can respond
Solution Approach 1:
The system performs preliminary actions by proactively identifying malware attacks through cross-customer pattern recognition before individual victims suffer significant losses. By detecting anomalies across multiple accounts and identifying coordinated attack patterns, the system can issue warnings to potentially affected customers before their accounts are compromised, reducing both response time and false positives through contextual awareness.
Solution Approach 2:
The patent implements feedback mechanisms where detected anomalies and confirmed malware patterns are fed back into the system to refine detection algorithms and update threat intelligence. This continuous learning process improves the system's ability to distinguish between legitimate unusual activity and actual malware attacks, reducing false positives while maintaining rapid response capabilities.
3Measurement precision
If machine-learning algorithms analyze cross-customer transactions to detect anomalies, then malware attack detection accuracy improves, but computational resources and processing time increase
Solution Approach 1:
The patent segments the large-scale cross-customer transaction analysis into manageable components: individual account anomaly detection, clustering of similar anomalies across accounts, and pattern recognition for malware identification. This segmentation allows the system to process data efficiently at each stage rather than analyzing all transactions simultaneously, reducing computational energy while maintaining high detection precision through progressive filtering and analysis.
Data Source
AI summary
The disclosed computer-implemented method for detecting malware based on anomalous cross-customer financial transactions may include (i) detecting, using a machine-learning algorithm, a set of anomalies associated with fraudulent financial transactions for source user accounts in a group of customer financial accounts, (ii) identifying, based on customer transaction metadata associated with a group of target user accounts in the customer financial accounts, a cluster of financial transactions having anomaly instances in common with the set of anomalies, (iii) linking each of the customer financial accounts having the common anomaly instances in the cluster of financial transactions with a corresponding customer threat protection account to discover a user device identification, (iv) determining that artifacts appearing on a group of user devices are associated with a potential malware attack, and (v) performing a security action that protects against the potential malware attack. Various other methods, systems, and computer-readable media are also disclosed.


