Correlating Financial Transactions with Network Telemetry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems and methods fail to effectively distinguish between legitimate and fraudulent online transactions, particularly those initiated from unauthorized devices, leading to inadequate protection for financial accounts.

Innovation Solution

The proposed solution involves correlating reported financial activities with online financial activities tracked in network telemetry on authorized devices to identify transactions initiated by unauthorized devices, enabling security actions such as alerts or account freezes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If antivirus and security software are installed on consumer devices to provide visibility into web traffic, then legitimate online transactions can be observed, but fraudulent transactions initiated on unauthorized devices cannot be detected

Engineering Contradiction:
Improvedetection accuracyVSAvoidcoverage scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent combines two previously separate monitoring approaches: (1) device-level web traffic monitoring from antivirus/security software on authorized devices, and (2) financial transaction monitoring from identity theft monitoring systems. By merging these data sources and correlating them through a common platform, the system achieves both high detection accuracy for legitimate transactions and comprehensive coverage including unauthorized devices.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If identity theft monitoring systems track all financial transactions, then comprehensive financial activity monitoring is achieved, but the ability to distinguish between authorized and unauthorized transactions is lost

Engineering Contradiction:
Improvedetection accuracyVSAvoidcontext information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system introduces an intermediary correlation layer that connects financial transaction data with web traffic telemetry data. This intermediary process matches financial transactions against corresponding web browsing activities, device identifiers, timestamps, and merchant information to determine whether each transaction was initiated from an authorized or unauthorized device, thereby recovering the lost context information.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If correlation between financial activities and network telemetry is performed, then unauthorized transactions can be identified, but system complexity increases

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal correlation engine that handles multiple types of financial transactions (credit card purchases, account openings, identity verification) and multiple data sources (web traffic telemetry, financial transaction feeds, device identifiers) through a single integrated platform. This multi-functional approach reduces overall system complexity compared to having separate specialized systems for each transaction type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20230376964A1Systems and methods for detecting unauthorized online transactions
Publication Date: 2023.11.23 GEN DIGITAL INC
  • US20230376964A1 patent drawing
  • US20230376964A1 patent drawing
  • US20230376964A1 patent drawing

AI summary

The disclosed computer-implemented method for detecting unauthorized online transactions may include correlating, by at least one processor, one or more reported financial activities to one or more online financial activities tracked in network telemetry on one or more authorized devices. The method may additionally include identifying, by the at least one processor based on the correlation, at least one of the reported financial activities that was initiated by an unauthorized device. The method may also include performing, by the at least one processor, a security action in response to the identification. Various other methods, systems, and computer-readable media are also disclosed.