Honeytoken Data Dissemination for Fraud Ring Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods fail to effectively defend against fraudulent activities in business computing systems and lack the capability to track and stop fraud organizations at their source, despite increasing online fraud and identity theft.

Innovation Solution

Generating and disseminating false honeytoken data to fraudulent systems, allowing organizations to monitor and collect information on access attempts, collaborate with external entities for effective seeding and law enforcement, and perform data analysis to track and investigate fraud rings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security layers (crosschecking, additional PINs, separate storage locations) are added to prevent fraud, then data security is improved, but costs increase and customer convenience deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidcustomer convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent converts the harmful effect of fraud attempts into beneficial intelligence by monitoring and analyzing access patterns. Instead of merely blocking access, the system learns from fraudulent behavior to improve detection accuracy and respond to evolving threats, transforming the fraudster's actions into useful security data.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The system continuously monitors access patterns, analyzes them against known fraud indicators, and adjusts security responses accordingly. This feedback loop enables the security system to adapt to new fraud techniques while maintaining high customer convenience by only intervening when actual fraud is detected.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If honeytoken data is stored within organization systems to monitor access, then data integrity monitoring is improved, but the ability to track and stop fraud at source remains unavailable

Engineering Contradiction:
Improvedata integrity monitoringVSAvoidfraud tracking and stopping capability
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extends monitoring from the traditional internal system dimension to the external network dimension. By placing honeytokens in external systems and analyzing access patterns across network boundaries, the system gains visibility into fraud operations outside the organization's direct control, enabling tracking and stopping capabilities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system introduces an intermediary analysis layer that processes access patterns from multiple sources including external systems. This intermediary layer aggregates data from various dimensions (internal logs, external access patterns, network metadata) to identify fraud connections that would be invisible through single-source monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If false honeytoken data is generated and made available to fraud rings, then fraud detection capability is improved, but the complexity of tracking and investigating fraud increases

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidtracking and investigation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex fraud detection task into distinct analytical dimensions: data integrity monitoring, access pattern analysis, network behavior tracking, and intelligence aggregation. Each segment handles specific aspects of fraud detection independently, making the overall complex system more manageable and scalable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The honeytoken system serves multiple functions simultaneously: it acts as a data integrity check, a fraud detection trigger, an intelligence gathering mechanism, and a network monitoring tool. This multi-functionality consolidates what would otherwise require separate systems into a single unified approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8880435B1Detection and tracking of unauthorized computer access attempts
Publication Date: 2014.11.04 BANK OF AMERICA CORP
  • US8880435B1 patent drawing
  • US8880435B1 patent drawing
  • US8880435B1 patent drawing

AI summary

False honeytoken data is generated, stored, and disseminated to a criminal organization such as an online banking fraud ring. After dissemination of the data, access attempts using the false honeytoken data are identified at an online banking web server or other organization resource. Data associated with the fraudulent access attempt, such as a source IP address, physical address, or related customer account numbers, are retrieved and stored so that this data may be compiled, analyzed, and used for tracking fraud rings.