Fraud Detection via Composite Risk Score and Device Reputation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing e-commerce fraud detection systems often produce false negatives due to unidentifiable network devices, lack sufficient information for risk assessment, and require established device-account associations, leading to inadequate fraud prevention.

Innovation Solution

A subscription-based fraud detection service that gathers information from a community of merchant subscribers, computes a Composite Risk Score by combining Profile-Based and Transaction-Based Risk Scores, and shares negative device reputations to accurately identify and quantify risks without relying on actual device identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing fraud detection systems rely on device identifiers to identify network devices, then device identification can be achieved, but false negatives occur when device identifiers are deleted or when devices use anonymous proxies to cloak themselves

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidfraud detection reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces an intermediary approach by using multiple alternative device identifiers (cookies, device fingerprints, IP addresses) as mediators when primary identifiers are unavailable or falsified. This intermediary layer allows the system to indirectly identify devices through surrogate markers, resolving the contradiction between maintaining identification accuracy and handling identifier obfuscation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes identification parameters by switching between different identifier types based on availability and reliability. When device identifiers are deleted or proxies are detected, the system transitions to using cookies, then device fingerprints, then IP addresses, effectively changing the identification parameter to maintain detection reliability despite identifier manipulation.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If fraud detection systems require established device-account associations to make valid associations, then accurate device-account linking can be achieved, but the system cannot assess risk for devices without established associations

Engineering Contradiction:
Improvedevice-account association accuracyVSAvoidsystem applicability to unidentified devices
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-establishing device profiles with multiple identifier types and risk assessment frameworks before actual transactions occur. This allows the system to immediately assess new or unidentified devices using pre-configured identification methods and risk parameters, eliminating the need for prior device-account associations while maintaining assessment accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system achieves universality by creating a multi-functional identification framework that can handle both established and unidentified devices through the same risk assessment process. The device profile structure and risk evaluation methodology work universally across all device types, whether they have prior associations or are completely new, resolving the contradiction between association accuracy and system versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If fraud detection systems use only network device reputation data, then the system operation is simple, but the reputation information may be insufficient to aid merchant decision-making

Engineering Contradiction:
Improvesystem operational simplicityVSAvoidinformation sufficiency for decision-making
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent segments the risk assessment information into distinct components: device reputation score, transaction risk factors, and detailed device profile data. This segmentation allows the system to maintain simple operation through the primary reputation score while providing comprehensive information through segmented detailed data when merchants need to make informed decisions, resolving the contradiction between operational simplicity and information sufficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds another dimension to the information provided by expanding from a single reputation score to a multi-dimensional risk assessment framework that includes transaction-specific factors, device profile characteristics, and contextual risk indicators. This dimensional expansion provides merchants with comprehensive decision-making information while maintaining the simplicity of the core reputation-based operation through layered information architecture.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8676684B2System and method for evaluating risk in fraud prevention
Publication Date: 2014.03.18 IOVATION INC
  • US8676684B2 patent drawing
  • US8676684B2 patent drawing
  • US8676684B2 patent drawing

AI summary

A method of determining a risk score indicating a risk that an electronic transaction will involve fraud and/or abuse. The method includes receiving transaction data associated with a not yet completed transaction from a merchant. The transaction data includes one or more characteristics related to the transaction. A profile is selected that identifies network devices each associated with the characteristics and having a device reputation. Next, a profile-based risk factor is determined as a function of a percentage of the network devices having a negative reputation. The risk score is determined as a function of the profile-based risk factor. In some embodiments, a transaction-based risk factor may also be determined. In such embodiments, the risk score is determined as a function of the profile-based and transaction-based risk factors. The risk score is provided to the merchant to be used thereby to determine whether to proceed with the transaction.