Fraud Detection System Correlating Cross-Application Event Logs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems for detecting fraud and misuse in computer environments are inadequate due to limited ability to recognize and access log file formats, especially when dealing with different applications, and fail to correlate user activities across various systems, leading to incomplete pattern recognition of fraudulent behavior.
Innovation Solution
A system and method that tracks user activities across multiple applications by accessing event log files, normalizing and correlating events to known users, and analyzing them against defined fraud scenarios using rules and algorithms, providing real-time monitoring and notification for potential fraud or misuse.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional systems access log files from different applications, then they can collect more data for fraud detection, but they fail to recognize different log file formats and cannot correlate user activities across applications
Solution Approach 1:
The patent introduces an intermediary component (fraud detection system with normalization engine) that mediates between diverse log file formats from different applications and the fraud detection analysis. This intermediary translates and standardizes various log formats into a common structure, enabling correlation of user activities across applications without requiring changes to the source applications or log generation processes.
Solution Approach 2:
The system changes the parameter of log data representation by normalizing different log file formats into a standardized structure. This parameter transformation allows the fraud detection system to process and correlate events from multiple applications uniformly, converting heterogeneous data into homogeneous form that can be analyzed for fraud patterns.
2Adaptability or versatility
If users access company systems through multiple user-ids and passwords for different applications, then they can utilize various applications, but fraud detection systems cannot correlate their activities across applications
Solution Approach 1:
The patent merges user activity data from multiple applications into a unified analysis framework. By correlating events across different applications and user sessions, the system combines dispersed information about user behavior into a comprehensive view, enabling fraud detection that considers cross-application patterns even when users access systems through different credentials.
Solution Approach 2:
The system implements feedback mechanisms that continuously monitor and analyze user activities across applications, using detected patterns to improve future fraud detection. The correlation of user behaviors across different applications provides feedback about actual usage patterns, which refines the fraud detection algorithms' ability to identify anomalous behavior.
3Measurement precision
If fraud detection systems analyze events from a single application, then they can focus on specific fraud patterns, but they cannot discern comprehensive patterns of fraudulent behavior across the organization's system
Solution Approach 1:
The fraud detection system is designed with multi-functionality to handle both application-specific fraud patterns and cross-application fraud scenarios. It processes events from multiple applications using unified fraud scenario definitions, enabling the same system to detect both narrow, application-specific fraud and broad, organization-wide fraud patterns simultaneously.
Data Source
AI summary
A system and method are provided for detecting fraud and/or misuse of data in a computer environment through generating a rule for monitoring at least one of transactions and activities that are associated with the data. The rule can be generated based on one or more criteria related to the at least one of the transactions and the activities that is indicative of fraud or misuse of the data. The rule can be applied to the at least one of the transactions and the activities to determine if an event has occurred, where the event occurs if the at least one criteria has been met. A hit is stored if the event has occurred and a notification can be provided if the event has occurred. A compilation of hits related to the rule can be provided.


