Merchant-Level Fraud Detection Platform for Enumeration Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current transaction monitoring systems fail to detect and block enumeration attacks effectively, as they analyze transactions at an individual card level, missing trends and patterns associated with hundreds of millions of authorization attempts, and often consume significant computational resources, leading to delays in identifying and preventing unauthorized or malicious transactions.
Innovation Solution
A fraud detection and prevention computing platform that analyzes card transactions at a merchant level, identifying trends and patterns across multiple merchants and users, generating notifications for suspicious activity, and taking actions such as adding merchants to a block list to prevent further unauthorized transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If transaction monitoring systems analyze transactions at an individual card level, then each transaction can be evaluated individually, but trends and patterns associated with hundreds of millions of authorization attempts cannot be identified
Solution Approach 1:
The patent transitions from analyzing transactions at the individual card level (one-dimensional) to analyzing transactions across multiple merchants and users simultaneously (multi-dimensional). This dimensional shift enables the system to identify enumeration attacks by observing patterns across the entire transaction network rather than isolated transactions.
2Use of energy by moving object
If transaction monitoring systems evaluate each card transaction individually, then computational resources can be managed, but delays occur in identifying and blocking unauthorized transactions
Solution Approach 1:
The system performs preliminary analysis by establishing baseline transaction patterns and thresholds across multiple merchants before attacks occur. When transactions are evaluated, the system can quickly compare against pre-established patterns rather than analyzing each transaction from scratch, enabling rapid identification of enumeration attacks.
Solution Approach 2:
The system implements continuous feedback loops where transaction outcomes are immediately fed back into the analysis engine. When an enumeration attack is detected through pattern recognition across multiple merchants, the system automatically updates block lists and adjusts monitoring parameters in real-time, preventing further fraudulent transactions.
3Object-affected harmful factors
If fraudulent actors funnel card testing attempts through multiple merchants, then individual merchants are not alerted to high volume of invalid attempts, but the overall attack pattern becomes detectable
Solution Approach 1:
The patent creates a universal monitoring system that serves multiple merchants simultaneously through a centralized analysis engine. This multi-functional system can evaluate transactions from any merchant against a common set of patterns and thresholds, enabling the detection of distributed enumeration attacks that target multiple merchants with the same fraudulent card information.
Data Source
AI summary
Systems, apparatuses, and methods are described for detecting and preventing suspicious payment card authorization attempts at a merchant level. A computing device may receive a plurality of authorization attempts and store the plurality of authorization attempts in a database. Each authorization attempt may correspond to an attempted transaction and may be associated with a respective merchant. The computing device may generate a database query configured to retrieve a first plurality of authorization attempts corresponding to a first merchant. The database query may be generated based on first criteria corresponding to a first notification rule, and the first criteria may be configured to detect a pattern of authorization attempts at a given merchant and associated with a potential account testing attack. The computing device may determine a suspicious status for the merchant and perform one or more actions associated with the merchant.


