Host Address Organization Mapping via Statistical Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods fail to accurately and automatically detect organizational affiliations of host addresses, which is crucial for preventing fraudulent activities such as phishing and social engineering, as self-reported affiliations are unreliable and existing whitelists and blacklists are insufficient.
Innovation Solution
A computer system that analyzes records of user access and membership to determine organizational affiliations by identifying statistical patterns, such as entropies and frequencies, to associate host addresses with organizations, applying thresholds to suppress noise and ensure accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If self-reporting of user identity and affiliations is used, then ease of operation is improved, but reliability deteriorates due to fraudulent activities
Solution Approach 1:
The patent introduces an intermediary system that acts as a mediator between users and the platform. This system automatically detects organizational affiliations by analyzing network traffic patterns, device characteristics, and behavioral data, rather than relying directly on self-reported information. The intermediary verification process cross-checks multiple data sources to validate user claims, thereby maintaining ease of registration while significantly improving reliability by detecting fraudulent affiliations through automated analysis of indirect evidence.
2Measurement precision
If third party whitelists and blacklists are used, then measurement precision is improved to some extent, but device complexity increases and coverage remains insufficient
Solution Approach 1:
The patent merges multiple detection approaches into a unified system. It combines third-party whitelist/blacklist data with proprietary automated analysis of network traffic patterns, device fingerprints, user behavior metrics, and organizational network relationships. By integrating these diverse data sources and analysis methods into a single coherent detection framework, the system achieves comprehensive coverage and high precision without requiring separate complex systems for each detection method.
Solution Approach 2:
The detection system is designed as a universal multi-functional platform that can handle various types of fraud detection simultaneously. It uses a common analytical framework that processes different data types (network traffic, device information, user behavior, organizational relationships) through the same machine learning models and decision algorithms, enabling the system to detect multiple fraud patterns with a single unified structure rather than requiring separate specialized systems for each fraud type.
3Reliability
If automated detection of fraudulent campaigns is implemented, then reliability is improved, but device complexity and computational requirements increase
Solution Approach 1:
The automated detection system is segmented into distinct functional modules: data collection module that gathers network traffic and user information, feature extraction module that identifies relevant patterns, machine learning analysis module that processes the features, and decision module that generates detection results. Each module operates independently with well-defined interfaces, allowing the complex detection task to be divided into manageable components that can be developed, maintained, and scaled separately while working together as an integrated system.
Data Source
AI summary
Techniques are provided for automatically detecting organizational affiliation of host addresses based on analysis of records. In an embodiment, computers store membership records and access records. Each membership record has an organization identifier that identifies an organization and a member identifier that identifies a member. Each access record has a member identifier that identifies a member and an address that identifies a host. The computers identify a localized subset of access records that have a particular address. The computers identify an involved subset of membership records having a member identifier that matches a member identifier of an access record of the localized subset. The computers determine statistical information based on the localized subset of access records and the involved subset of membership records. Based on the statistical information, the computers identify an organization identifier whose frequency within organization identifiers of the membership records of the involved subset exceeds a threshold.


