Network Element Group Profiling for Fraud Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current telecommunications systems lack effective methods to detect fraudulent activity, which manifests as unusual increases in network element activity, due to the impracticality of maintaining statistics for each element in large networks, leading to revenue loss and operational inefficiencies.
Innovation Solution
A system that maintains group profiles of network elements, accumulates data stream values over configurable periods, compares them to collation thresholds, and creates collation instances to identify extreme behavior, allowing for the detection of unusual activity patterns indicative of potential fraud.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If statistics are maintained for each network element individually, then measurement precision of network element activity is improved, but device complexity and storage requirements become impractically large
Solution Approach 1:
The patent segments the network element monitoring system into hierarchical levels: global network level, network element group level, and individual network element level. Instead of maintaining statistics for all tens of billions of elements individually at the global level, the system divides elements into groups (e.g., by geographic region, service type, or network function) and maintains aggregated statistics at each level. This segmentation allows precise monitoring of suspicious patterns at the group level while avoiding the impractical storage requirements of individual element monitoring across the entire global network.
2Difficulty of detecting and measuring
If monitoring coverage is expanded to all network elements, then detection capability is improved, but loss of time for data processing increases
Solution Approach 1:
The patent extracts and focuses monitoring resources on suspicious network element groups that exhibit unusual activity patterns, rather than uniformly monitoring all network elements. The system identifies groups with abnormal statistics (such as unexpected call volume increases or unusual routing patterns) and concentrates analytical efforts on these extracted subsets. This approach maintains high detection capability for fraudulent activity while significantly reducing data processing time by excluding normal, low-risk elements from intensive monitoring.
Solution Approach 2:
The system performs preliminary filtering and aggregation of network element data into groups before detailed analysis. By pre-processing data to identify suspicious patterns at the group level and only then drilling down to individual elements within suspicious groups, the system reduces the overall data processing time while maintaining comprehensive detection capability.
3Reliability
If monitoring sensitivity is increased to detect all fraudulent activity, then reliability of fraud detection is improved, but false alerts increase reducing operational efficiency
Solution Approach 1:
The patent applies different monitoring sensitivities and analytical methods to different network element groups based on their local characteristics. Instead of using a uniform high-sensitivity threshold across all elements (which would generate excessive false alerts), the system tailors monitoring parameters to each group's normal behavior patterns, traffic volume, and risk profile. This local quality approach maintains high detection reliability for actual fraud while reducing false alerts in normal operating conditions, thereby preserving operational efficiency.
Data Source
AI summary
A system for identifying extreme behavior in elements of a network comprises a profiler and a collator. The profiler and the collator perform a method of identifying extreme behavior in the network elements. The profiler maintains one or more group profiles of network elements. Each group profile is associated with a plurality of network elements. The profiler accumulates values of a first function of the contents of an input data stream over a first period of time for each group profile. The input data stream includes at least one field containing a network element reference. The accumulated values of each group profile are compared with a corresponding collation threshold. The collator creates a collation instance for each group profile that reaches the collation threshold. Each collation instance creates a plurality of collation profiles. Each collation profile is associated with one or more network elements from the plurality of network elements corresponding to the group profile that caused the creation of the collation instance. The collator instance accumulates values of a second function of the contents of the input data stream for each collation profile over a second period of time. Extreme behavior of network elements is identified from the accumulated values of the collation profiles.


