Activity Heatmap Cooldown for Fraud Detection in Messaging Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The rising issues of fraud and spam through communication channels like SMS, MMS, and RCS pose significant challenges due to deceptive practices such as revenue share fraud, where attackers manipulate revenue-sharing systems to generate illicit profits, leading to financial losses and increased costs for businesses managing these systems.
Innovation Solution
The implementation of enhanced security features using activity heatmaps with cooldown periods to detect and mitigate spam, fraud, and malicious bot activity by generating scores for mobile numbers based on message and call patterns, and invoking security measures when thresholds are exceeded, such as requiring alternative authentication methods to reduce costs and prevent message interception by virtual carriers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security measures are increased to detect and prevent fraud, then security reliability is improved, but false alarms increase and legitimate communication is disrupted
Solution Approach 1:
The system dynamically adjusts security thresholds and detection sensitivity based on learned patterns from historical data. The detection model evolves over time, adapting to new fraud techniques while maintaining tolerance for legitimate communication patterns, thereby reducing false alarms while improving security reliability
Solution Approach 2:
The system implements feedback loops where detection results and outcomes are fed back into the model to continuously improve accuracy. By analyzing true positives, false positives, and false negatives, the system refines its detection algorithms to better distinguish fraud from legitimate activity, reducing false alarms while maintaining high security detection
2Reliability
If message filtering and security checks are intensified, then fraud detection capability is improved, but communication throughput decreases
Solution Approach 1:
The system applies partial security checking by using lightweight detection methods for low-risk messages and reserving intensive security analysis for suspicious patterns. This tiered approach allows most legitimate communication to pass through quickly while maintaining strong fraud detection capability for targeted cases
Solution Approach 2:
The security system is segmented into multiple layers: initial filtering, pattern matching, and deep analysis. Each layer handles specific types of detection tasks, allowing the system to process messages efficiently through appropriate checkpoints without subjecting all messages to the full security regimen, thus maintaining throughput while improving detection
3Reliability
If security thresholds are lowered to catch more fraud, then fraud detection sensitivity is improved, but false positive rate increases
Solution Approach 1:
The system uses multiple detection parameters and thresholds rather than a single fixed value. By adjusting sensitivity parameters dynamically based on context, message type, and sender reputation, the system can maintain high fraud detection sensitivity while adapting thresholds to minimize false positives for different communication scenarios
4Reliability
If comprehensive message analysis is performed on all messages, then fraud detection accuracy is improved, but computing resource consumption increases
Solution Approach 1:
The system performs comprehensive analysis only on messages that trigger suspicion based on initial lightweight checks. Most legitimate messages receive minimal processing, while potentially fraudulent messages undergo full analysis. This selective approach maintains high detection accuracy for fraud while dramatically reducing overall computing resource consumption
Data Source
AI summary
The techniques disclosed herein provide a method of fraud mitigation in messaging and call systems using a heatmap with a cooldown approach. The heatmap is created using scores assigned to the mobile numbers. The score for each number is calculated based on the historical record of calls or messages to numbers within a predetermined range. In general, an increased number of messages or calls for numbers within a range increases a score for numbers within that range. The system can reduce the scores or reset the scores over a period of time. This reduction or reset of the scores, which is referred to herein as “forgetting” deliverables, provides a cooldown approach. With this cooldown approach, new and fresh patterns can be identified faster using accurate and current data. When a score for a number reaches or exceeds an activity threshold, one or more security measures may be implemented.


