Merchant-Level Fraud Detection Platform for Enumeration Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current transaction monitoring systems fail to detect and block enumeration attacks effectively, as they analyze transactions at an individual card level, missing trends and patterns associated with hundreds of millions of authorization attempts, and often consume significant computational resources, leading to delays in identifying and preventing unauthorized or malicious transactions.

Innovation Solution

A fraud detection and prevention computing platform that analyzes card transactions at a merchant level, identifying trends and patterns across multiple merchants and users, generating notifications for suspicious activity, and taking actions such as adding merchants to a block list to prevent further unauthorized transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If transaction monitoring systems analyze transactions at an individual card level, then each transaction can be evaluated individually, but trends and patterns associated with hundreds of millions of authorization attempts cannot be identified

Engineering Contradiction:
Improvetransaction analysis accuracyVSAvoidtrend and pattern information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent transitions from analyzing transactions at the individual card level (one-dimensional) to analyzing transactions across multiple merchants and users simultaneously (multi-dimensional). This dimensional shift enables the system to identify enumeration attacks by observing patterns across the entire transaction network rather than isolated transactions.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Use of energy by moving object

If transaction monitoring systems evaluate each card transaction individually, then computational resources can be managed, but delays occur in identifying and blocking unauthorized transactions

Engineering Contradiction:
Improvecomputational resource consumptionVSAvoidresponse time
Core Design Contradiction:
Use of energy by moving objectVSLoss of time

Solution Approach 1:

The system performs preliminary analysis by establishing baseline transaction patterns and thresholds across multiple merchants before attacks occur. When transactions are evaluated, the system can quickly compare against pre-established patterns rather than analyzing each transaction from scratch, enabling rapid identification of enumeration attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where transaction outcomes are immediately fed back into the analysis engine. When an enumeration attack is detected through pattern recognition across multiple merchants, the system automatically updates block lists and adjusts monitoring parameters in real-time, preventing further fraudulent transactions.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If fraudulent actors funnel card testing attempts through multiple merchants, then individual merchants are not alerted to high volume of invalid attempts, but the overall attack pattern becomes detectable

Engineering Contradiction:
Improveattack detection capabilityVSAvoidsystem architecture
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent creates a universal monitoring system that serves multiple merchants simultaneously through a centralized analysis engine. This multi-functional system can evaluate transactions from any merchant against a common set of patterns and thresholds, enabling the detection of distributed enumeration attacks that target multiple merchants with the same fraudulent card information.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240311839A1Fraud detection and prevention system
Publication Date: 2024.09.19 BRIGHTWELL PAYMENTS
  • US20240311839A1 patent drawing
  • US20240311839A1 patent drawing
  • US20240311839A1 patent drawing

AI summary

Systems, apparatuses, and methods are described for detecting and preventing suspicious payment card authorization attempts at a merchant level. A computing device may receive a plurality of authorization attempts and store the plurality of authorization attempts in a database. Each authorization attempt may correspond to an attempted transaction and may be associated with a respective merchant. The computing device may generate a database query configured to retrieve a first plurality of authorization attempts corresponding to a first merchant. The database query may be generated based on first criteria corresponding to a first notification rule, and the first criteria may be configured to detect a pattern of authorization attempts at a given merchant and associated with a potential account testing attack. The computing device may determine a suspicious status for the merchant and perform one or more actions associated with the merchant.