Multi-Platform Suspicious User Detection via Unified Message Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for identifying suspicious users in instant messaging systems are ineffective in detecting malicious users across multiple messengers and fail to identify groups of accomplices, leading to inadequate protection against targeted attacks.

Innovation Solution

A method and computing device that analyze user messages from multiple messaging systems for suspiciousness indicators, convert non-standard message formats, and classify users based on reputation scores, identifying malicious links, accounts, and email addresses, and clustering users with similar behavior or data to flag suspicious activity across multiple platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intelligent chat bots are used to analyze messages within a single messenger, then malicious users can be identified to some extent, but the system cannot detect malicious users across multiple messengers or identify groups of accomplices

Engineering Contradiction:
Improvedetection effectivenessVSAvoidmulti-platform coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal detection system that aggregates messages from multiple messaging platforms (WhatsApp, Telegram, Viber, etc.) into a single analysis environment. The computing device receives messages from different messengers, converts them to a unified format, and applies consistent suspiciousness indicators across all platforms, enabling multi-platform malicious user detection while maintaining reliable identification standards.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges detection capabilities across multiple independent messaging systems by collecting messages from various platforms into a centralized analysis system. By combining message data from different messengers and applying unified suspiciousness criteria, the system achieves both broad platform coverage and consistent detection reliability that single-messenger bots cannot provide.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If message analysis is performed across multiple messaging systems with unified formats, then detection coverage is improved, but data processing complexity increases

Engineering Contradiction:
Improvemulti-platform coverageVSAvoiddata processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary layer that acts as a message format converter and standardizer. This intermediary component receives messages in various formats from different messaging platforms, converts them to a unified internal format, and then processes them through the suspiciousness analysis engine. This mediator approach enables multi-platform coverage while isolating the complexity of format conversion from the core detection logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the detection system into distinct functional modules: message collection from multiple platforms, format conversion to unified standards, suspiciousness indicator application, and user classification. This segmentation allows each module to handle specific tasks independently, reducing overall system complexity while achieving comprehensive multi-platform coverage.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11153351B2Method and computing device for identifying suspicious users in message exchange systems
Publication Date: 2021.10.19 GRP IB GLOBAL PTE LTD
  • US11153351B2 patent drawing
  • US11153351B2 patent drawing
  • US11153351B2 patent drawing

AI summary

A computing device for detecting suspicious users in a plurality of messaging systems and a method for detecting suspicious users therein executable the computing device are proposed. The claimed method includes: receiving a plurality of user messages from a plurality of messaging systems; analyzing each of the received user messages to identify at least one message suspiciousness indicator from a predetermined set of message suspiciousness indicators; if at least one message suspiciousness indicator is detected in the analyzed user message, identifying at least one user associated with the analyzed user message in one of the plurality of messaging systems; assigning each of the identified users a user suspiciousness indicator depending on the identified message suspiciousness indicators; classifying users in the one of the plurality of messaging systems as suspicious their reputation score exceeds a predetermined reputation threshold limit.