Dynamic Authentication Scoring for Internet Banking Fraud
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Internet banking faces challenges in mitigating fraud risks due to inadequate security measures, particularly with single-factor authentication methods that compromise ease of use and convenience, and existing intrusion detection systems often generate false positives, affecting user experience.
Innovation Solution
A method and system that employ a composite scoring system to assess the improbability of login attributes, requiring additional authentication if the score exceeds a threshold, and provide real-time and daily reports on unusual login activity to enhance security without compromising convenience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multifactor authentication or hardware tokens are implemented, then security against fraud is improved, but ease of use and convenience deteriorate
Solution Approach 1:
The system automatically analyzes login attributes and calculates improbability scores without requiring user intervention. The system self-determines when additional authentication is needed based on the calculated scores, eliminating the need for users to manually select or configure security measures.
Solution Approach 2:
The system dynamically changes the authentication requirement parameter based on the calculated improbability score. When the score exceeds the threshold, the system transitions from single-factor to multifactor authentication. This dynamic parameter adjustment resolves the contradiction by applying enhanced security only when necessary.
2Reliability
If traditional intrusion detection systems are implemented, then fraud detection capability is improved, but false positive rate increases affecting user experience
Solution Approach 1:
The system uses multiple login attributes (IP address, browser ID, time of day, time since last logon) and dynamically calculates improbability scores based on combinations of these parameters. This multi-parameter approach improves fraud detection accuracy while reducing false positives compared to single-parameter detection systems.
Solution Approach 2:
The system creates a composite improbability score by combining multiple login attributes together. Just as composite materials combine different properties to achieve superior performance, the composite score combines multiple attributes to achieve more accurate fraud detection with fewer false positives.
Data Source
AI summary
A method and system are provided for mitigating the risk of fraud in Internet banking. In an embodiment comprising an end user seeking access to the Internet banking site of a financial institution, the end user having already satisfied a first authentication requirement (such as providing a valid user ID and password), the end user is required to satisfy a second authentication test when a measure of improbability associated with the login exceeds a threshold. The measure of improbability, in an embodiment, is based on the improbability of a combination of session statistics such as IP address, browser ID, hour of day, and time since the user's last valid login.


