Fraud Alert Consolidation and Prioritization System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing fraud detection systems face challenges in managing high volumes of alerts, leading to operational inefficiencies and increased processing power requirements, which can result in delayed detection and increased costs, as well as difficulties in prioritizing alerts effectively.

Innovation Solution

A system that consolidates fraud indicators into a holistic risk score using learning algorithms to prioritize alerts, dynamically re-evaluates risk as new information becomes available, and reduces false positives, thereby optimizing resource allocation and alert management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple reporting devices generate alerts through various channels, then detection coverage and fraud detection capability are improved, but alert volume increases and operational capacity is exceeded

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidalert volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent consolidates alerts from multiple reporting devices (webservers, firewalls, intrusion detection systems) into a unified alert management system. The system merges similar alerts and aggregates them by customer and alert type, reducing the total number of individual alerts while maintaining comprehensive fraud detection coverage across all monitoring channels.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The alert management system serves multiple functions simultaneously: it collects alerts from diverse sources, prioritizes them based on risk criteria, aggregates similar alerts, and distributes them to appropriate analysts. This multi-functional approach eliminates the need for separate processing systems for each alert type and source.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If automated fraud detection rules are deployed to assign alerts to scenarios, then alert triage efficiency is improved, but alert volume increases due to rule overlap

Engineering Contradiction:
Improvealert triage efficiencyVSAvoidalert volume
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The system applies different prioritization and aggregation rules to different alert types and customer segments. Rather than applying a uniform rule set, the system tailors its processing behavior based on the specific characteristics of each alert, allowing for more efficient triage while reducing redundant alerts through localized aggregation strategies.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system continuously learns from analyst actions and alert outcomes to refine its automated triage rules. By feedback from analyst processing decisions, the system improves its alert assignment accuracy over time, reducing the need for manual intervention while maintaining high triage efficiency.

Inventive Principle:
Principle #23Feedback

3Productivity

If high processing power is allocated to process large volume of alerts, then alert processing capability is improved, but infrastructure cost increases

Engineering Contradiction:
Improvealert processing capabilityVSAvoidprocessing power consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The system extracts and removes redundant alerts early in the processing pipeline through aggregation and deduplication. By eliminating duplicate and low-priority alerts before they reach the analysis stage, the system reduces the computational burden on processing infrastructure while maintaining the ability to handle high volumes of unique, high-priority alerts.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system dynamically adjusts processing parameters based on alert priority and risk level. High-priority alerts receive intensive processing resources, while low-priority alerts are processed with reduced computational effort. This parameter-based resource allocation optimizes processing capability utilization and reduces overall infrastructure requirements.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If large volume of alerts is processed, then detection coverage is improved, but detection time increases causing delays

Engineering Contradiction:
Improvedetection coverageVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments alerts into priority tiers and categories, allowing for parallel processing and prioritized handling. By dividing the alert stream into manageable segments based on urgency and type, the system maintains comprehensive detection coverage while reducing overall detection time through concurrent processing of lower-priority alerts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary aggregation and prioritization actions immediately upon alert receipt, before alerts enter the analysis queue. This preliminary processing reduces the effective volume of alerts requiring full analysis, enabling faster detection while maintaining coverage through continuous real-time processing of new alerts.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12074891B1Systems and methods of detecting and mitigating malicious network activity
Publication Date: 2024.08.27 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US12074891B1 patent drawing
  • US12074891B1 patent drawing
  • US12074891B1 patent drawing

AI summary

Disclosed herein are systems and methods executing a security server that perform various processes using alert elements containing various data fields indicating threats of fraud or attempts to penetrate an enterprise network. Using alert elements, the security server generate integrated alerts that are associated with customers of the system and assign a risk score for the integrated alerts, which the security server uses to store and sort the integrated alerts according to a priority, based on the relative risk scores. Analyst computers may query and fetch integrated alerts from an integrate alert database, and then present the integrate alerts to be addressed by an analyst according to the priority level of the respective integrated alerts. This allows to ensure that the right customer, is worked by the right analyst, at the right time, to maximize fraud prevention and minimize customer impact.