Fraud Detection System Correlating Cross-Application Event Logs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems for detecting fraud and misuse in computer environments are inadequate due to limited ability to recognize and access log file formats, especially when dealing with different applications, and fail to correlate user activities across various systems, leading to incomplete pattern recognition of fraudulent behavior.

Innovation Solution

A system and method that tracks user activities across multiple applications by accessing event log files, normalizing and correlating events to known users, and analyzing them against defined fraud scenarios using rules and algorithms, providing real-time monitoring and notification for potential fraud or misuse.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional systems access log files from different applications, then they can collect more data for fraud detection, but they fail to recognize different log file formats and cannot correlate user activities across applications

Engineering Contradiction:
Improveability to recognize different log file formatsVSAvoidinability to correlate user activities across applications
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary component (fraud detection system with normalization engine) that mediates between diverse log file formats from different applications and the fraud detection analysis. This intermediary translates and standardizes various log formats into a common structure, enabling correlation of user activities across applications without requiring changes to the source applications or log generation processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameter of log data representation by normalizing different log file formats into a standardized structure. This parameter transformation allows the fraud detection system to process and correlate events from multiple applications uniformly, converting heterogeneous data into homogeneous form that can be analyzed for fraud patterns.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If users access company systems through multiple user-ids and passwords for different applications, then they can utilize various applications, but fraud detection systems cannot correlate their activities across applications

Engineering Contradiction:
Improveuser ability to access multiple applicationsVSAvoidinability to track user behavior patterns across applications
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent merges user activity data from multiple applications into a unified analysis framework. By correlating events across different applications and user sessions, the system combines dispersed information about user behavior into a comprehensive view, enabling fraud detection that considers cross-application patterns even when users access systems through different credentials.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback mechanisms that continuously monitor and analyze user activities across applications, using detected patterns to improve future fraud detection. The correlation of user behaviors across different applications provides feedback about actual usage patterns, which refines the fraud detection algorithms' ability to identify anomalous behavior.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If fraud detection systems analyze events from a single application, then they can focus on specific fraud patterns, but they cannot discern comprehensive patterns of fraudulent behavior across the organization's system

Engineering Contradiction:
Improvedetection accuracy for specific fraud patternsVSAvoidability to detect cross-application fraud patterns
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The fraud detection system is designed with multi-functionality to handle both application-specific fraud patterns and cross-application fraud scenarios. It processes events from multiple applications using unified fraud scenario definitions, enabling the same system to detect both narrow, application-specific fraud and broad, organization-wide fraud patterns simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10360399B2System and method for detecting fraud and misuse of protected data by an authorized user using event logs
Publication Date: 2019.07.23 LONG KURT JAMES
  • US10360399B2 patent drawing
  • US10360399B2 patent drawing
  • US10360399B2 patent drawing

AI summary

A system and method are provided for detecting fraud and/or misuse of data in a computer environment through generating a rule for monitoring at least one of transactions and activities that are associated with the data. The rule can be generated based on one or more criteria related to the at least one of the transactions and the activities that is indicative of fraud or misuse of the data. The rule can be applied to the at least one of the transactions and the activities to determine if an event has occurred, where the event occurs if the at least one criteria has been met. A hit is stored if the event has occurred and a notification can be provided if the event has occurred. A compilation of hits related to the rule can be provided.