Activity Heatmap Cooldown for Fraud Detection in Messaging Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The rising issues of fraud and spam through communication channels like SMS, MMS, and RCS pose significant challenges due to deceptive practices such as revenue share fraud, where attackers manipulate revenue-sharing systems to generate illicit profits, leading to financial losses and increased costs for businesses managing these systems.

Innovation Solution

The implementation of enhanced security features using activity heatmaps with cooldown periods to detect and mitigate spam, fraud, and malicious bot activity by generating scores for mobile numbers based on message and call patterns, and invoking security measures when thresholds are exceeded, such as requiring alternative authentication methods to reduce costs and prevent message interception by virtual carriers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security measures are increased to detect and prevent fraud, then security reliability is improved, but false alarms increase and legitimate communication is disrupted

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidfalse alarms
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system dynamically adjusts security thresholds and detection sensitivity based on learned patterns from historical data. The detection model evolves over time, adapting to new fraud techniques while maintaining tolerance for legitimate communication patterns, thereby reducing false alarms while improving security reliability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback loops where detection results and outcomes are fed back into the model to continuously improve accuracy. By analyzing true positives, false positives, and false negatives, the system refines its detection algorithms to better distinguish fraud from legitimate activity, reducing false alarms while maintaining high security detection

Inventive Principle:
Principle #23Feedback

2Reliability

If message filtering and security checks are intensified, then fraud detection capability is improved, but communication throughput decreases

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidcommunication throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies partial security checking by using lightweight detection methods for low-risk messages and reserving intensive security analysis for suspicious patterns. This tiered approach allows most legitimate communication to pass through quickly while maintaining strong fraud detection capability for targeted cases

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The security system is segmented into multiple layers: initial filtering, pattern matching, and deep analysis. Each layer handles specific types of detection tasks, allowing the system to process messages efficiently through appropriate checkpoints without subjecting all messages to the full security regimen, thus maintaining throughput while improving detection

Inventive Principle:
Principle #1Segmentation

3Reliability

If security thresholds are lowered to catch more fraud, then fraud detection sensitivity is improved, but false positive rate increases

Engineering Contradiction:
Improvefraud detection sensitivityVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system uses multiple detection parameters and thresholds rather than a single fixed value. By adjusting sensitivity parameters dynamically based on context, message type, and sender reputation, the system can maintain high fraud detection sensitivity while adapting thresholds to minimize false positives for different communication scenarios

Inventive Principle:
Principle #35Parameter changes

4Reliability

If comprehensive message analysis is performed on all messages, then fraud detection accuracy is improved, but computing resource consumption increases

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs comprehensive analysis only on messages that trigger suspicion based on initial lightweight checks. Most legitimate messages receive minimal processing, while potentially fraudulent messages undergo full analysis. This selective approach maintains high detection accuracy for fraud while dramatically reducing overall computing resource consumption

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240419805A1Enhanced security features for message and call systems using an activity heatmap with cooldown periods
Publication Date: 2024.12.19 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20240419805A1 patent drawing
  • US20240419805A1 patent drawing
  • US20240419805A1 patent drawing

AI summary

The techniques disclosed herein provide a method of fraud mitigation in messaging and call systems using a heatmap with a cooldown approach. The heatmap is created using scores assigned to the mobile numbers. The score for each number is calculated based on the historical record of calls or messages to numbers within a predetermined range. In general, an increased number of messages or calls for numbers within a range increases a score for numbers within that range. The system can reduce the scores or reset the scores over a period of time. This reduction or reset of the scores, which is referred to herein as “forgetting” deliverables, provides a cooldown approach. With this cooldown approach, new and fresh patterns can be identified faster using accurate and current data. When a score for a number reaches or exceeds an activity threshold, one or more security measures may be implemented.