Fraud Detection via Device-Level Event Records
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing fraud detection systems are inadequate for monitoring user interactions with native applications on end-user devices, as they rely solely on network traffic analysis, which is limited, and behaviometrics-based approaches are inefficient and inaccurate.
Innovation Solution
Monitoring and analyzing user interactions with applications executing on end-user devices by generating event records that include interaction details and timestamps, which are then compared to expected patterns to detect anomalous behavior indicative of fraud.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network traffic interception and analysis is used to monitor user behavior, then fraud detection capability is improved for Web-based applications, but monitoring capability deteriorates for native applications with offline interactions
Solution Approach 1:
The patent segments the monitoring approach into two distinct components: network traffic interception for Web-based applications and device-level event recording for native applications. This segmentation allows each component to be optimized for its specific application type, resolving the contradiction between reliability for Web apps and adaptability across all application types.
Solution Approach 2:
The patent introduces an intermediary layer in the form of application programming interfaces (APIs) and event recording mechanisms that bridge the gap between native applications and the fraud detection system. These intermediaries capture user interactions at the device level, enabling monitoring of offline interactions without relying solely on network traffic analysis.
2Measurement precision
If behaviometrics-based monitoring is used to track user behavior, then user identification accuracy is improved, but system resource utilization deteriorates
Solution Approach 1:
The patent employs lightweight event records that capture essential user interaction data in a compact, efficient format. These event records are generated locally on the device and transmitted only when needed, avoiding the continuous resource-intensive processing of traditional behaviometrics while maintaining sufficient accuracy for fraud detection.
Solution Approach 2:
The patent implements partial monitoring by selectively capturing specific user interaction events rather than continuously analyzing all user behaviors. This partial action approach reduces system resource utilization while maintaining adequate user identification accuracy for detecting fraudulent activities.
3Extent of automation
If behaviometrics-based monitoring is used to authenticate users, then user identification capability is improved, but accuracy deteriorates due to high false-accept and false-rejection rates
Solution Approach 1:
The patent merges multiple data sources including device information, application context, and user interaction patterns into a comprehensive fraud detection model. This combination of diverse indicators improves measurement precision by cross-validating multiple signals rather than relying on a single behaviometric parameter, thereby reducing false-accept and false-rejection rates.
Solution Approach 2:
The patent implements feedback mechanisms where fraud detection results are used to refine and update the detection model over time. This continuous learning process improves user identification accuracy by adapting to new fraud patterns while reducing erroneous classifications through iterative optimization.
Data Source
AI summary
Techniques for fraud detection based on user behavior that monitor and analyze user interactions with an application executing on an end user device. The techniques include monitoring behavior of an end user device user by tracking user interactions with the application executing on the end user device, and generating event records describing the user interactions and the times at which they occurred. The event records are sent to an analytics engine that uses the event records to perform a fraud detection operation by comparing the user interactions described in the event records to an expected pattern of user interactions with the application, and detecting anomalous user behavior indicative of fraud in response to the user interactions described in the event records not matching the expected pattern of user interactions with the application.


