Dynamic Record Identification System for Proactive Account Compromise Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems face challenges in promptly identifying compromised merchants and minimizing losses from unauthorized account activities, as they rely on actual unauthorized transactions as leading indicators, which can result in significant delays and increased losses before detection and mitigation.
Innovation Solution
A dynamic record identification and analysis computer system with event monitoring components that utilizes account reconnaissance data to analyze transaction history and identify common interactions, pinpointing potential points of compromise without waiting for unauthorized transactions, by using suspicious phone contacts as a leading indicator and incorporating merchant weighting and temporal grouping analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If systems rely on actual unauthorized transactions as leading indicators to identify compromised merchants, then detection accuracy is improved, but detection time is significantly delayed and losses increase
Solution Approach 1:
The system performs preliminary actions by monitoring account reconnaissance events (suspicious phone contacts, data requests) before actual unauthorized transactions occur. This early detection approach identifies compromised merchants proactively, reducing both detection time and potential losses while maintaining detection accuracy through multiple validation signals.
Solution Approach 2:
The patent inverts the traditional detection approach by using account reconnaissance events as leading indicators instead of waiting for unauthorized transactions. This reversal enables the system to detect compromises earlier in the attack lifecycle, transforming the detection timeline from reactive (after loss) to proactive (before loss).
2Reliability
If systems wait for unauthorized transactions to occur before detecting compromises, then false positives are reduced, but detection time increases and losses mount
Solution Approach 1:
The system implements feedback mechanisms by continuously monitoring account reconnaissance events and adjusting detection thresholds based on patterns observed across multiple accounts and merchants. This feedback loop enables early detection while maintaining reliability through adaptive validation, reducing false positives even when detecting earlier in the attack cycle.
Solution Approach 2:
The patent applies partial action by monitoring a subset of account events (reconnaissance activities) rather than waiting for complete unauthorized transaction sequences. This partial monitoring approach enables earlier detection without requiring full compromise confirmation, balancing early detection with false positive reduction through multi-event validation.
3Loss of time
If systems implement proactive monitoring of account reconnaissance events, then detection time is reduced, but system complexity increases
Solution Approach 1:
The system segments the monitoring process into distinct event types (phone contacts, data requests, account access attempts) and processes each segment through specialized detection rules. This segmentation reduces overall system complexity by breaking down the complex monitoring task into manageable, independently configurable components while enabling comprehensive proactive detection.
Solution Approach 2:
The patent implements universality by creating a multi-functional monitoring system that handles multiple event types (reconnaissance, transactions, access attempts) through a unified detection framework. This universal approach reduces complexity compared to separate specialized systems for each event type, while maintaining comprehensive detection capabilities across all account activities.
4Measurement precision
If systems monitor multiple account events and interactions to identify points of compromise, then detection accuracy is improved, but data processing requirements increase
Solution Approach 1:
The system extracts and focuses on specific high-value data elements (account reconnaissance events, merchant interactions, temporal patterns) from the broader account data stream. This extraction approach improves detection accuracy by concentrating on the most informative signals while reducing overall data processing requirements by filtering out less relevant information.
Solution Approach 2:
The patent applies local quality by assigning different analysis depths and processing intensities to different event types and account contexts. High-risk events receive more intensive analysis while lower-risk events undergo lighter processing, optimizing the balance between detection accuracy and data processing requirements through context-aware resource allocation.
Data Source
AI summary
Aspects of the disclosure relate to deploying and utilizing a dynamic record identification and analysis computer system with event monitoring components. A computing device may receive account reconnaissance data identifying a first plurality of user accounts that have experienced at least one event associated with account security concern characteristics. The computing platform may analyze event history data associated with the first plurality of user accounts to identify one or more common interactions associated with a subset of the first plurality of user accounts. The computing platform may identify a point of compromise among the subset of the first plurality of user accounts. Subsequently, the computing platform may search enterprise user account records to identify a second plurality of user accounts that have at least one event associated with the point of compromise. The computing platform may add the second plurality of user accounts to an alert table.


