Network Risk Scoring via IP Aggregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic fraud network (EFN) systems are inadequate in assigning risk scores, as they focus solely on individual IP addresses, allowing fraudsters to continue fraudulent activities by switching IP addresses without being associated with the initial risk score.
Innovation Solution
Calculating a risk score for networks or subnets by aggregating risk-related information from multiple IP addresses, including trust levels associated with entities, to assign a comprehensive risk score that encompasses all connected IP addresses, thereby increasing the accuracy of risk assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If risk scores are calculated based solely on individual IP address history, then the calculation process is simple and fast, but fraudsters can switch IP addresses to continue fraudulent activity without being detected
Solution Approach 1:
The patent merges multiple IP addresses belonging to the same network into a single risk scoring unit. Instead of evaluating each IP address independently, the system aggregates risk-related information from all IP addresses within a network, creating a unified network-level risk score that reflects the collective behavior of all associated IP addresses.
Solution Approach 2:
The patent transitions from a one-dimensional IP address-level risk assessment to a two-dimensional approach by introducing the network dimension. This allows the system to evaluate risk at both the individual IP address level and the network level, providing a more comprehensive view of fraudulent activity patterns.
2Measurement precision
If risk scores are assigned to individual IP addresses only, then the data processing requirement is low, but the system cannot detect fraud when IP addresses are switched within the same network
Solution Approach 1:
The system combines risk-related information from multiple IP addresses into a unified network risk assessment. By merging data from all IP addresses within a network, the system achieves more precise risk measurement that captures fraudulent patterns across the entire network rather than isolating individual IP addresses.
Solution Approach 2:
The network-level risk scoring system serves multiple functions: it evaluates individual IP addresses, assesses overall network risk, and provides a mechanism to detect fraudsters who switch between IP addresses. This multi-functional approach increases measurement precision without proportionally increasing data processing requirements.
3Reliability
If the system evaluates each IP address independently, then the processing speed is high, but fraud detection capability is limited when multiple IP addresses are used by the same fraudster
Solution Approach 1:
The patent applies merging by consolidating the evaluation of multiple IP addresses into a single network-level assessment. This allows the system to maintain processing efficiency while significantly improving fraud detection capability, as the network-level risk score captures patterns that would be invisible when evaluating IP addresses in isolation.
Solution Approach 2:
The network serves as an intermediary concept that connects multiple IP addresses. By introducing this intermediate level of analysis, the system can efficiently evaluate fraud risk without directly comparing every individual IP address, thus improving detection capability while managing complexity through the network abstraction layer.
Data Source
AI summary
Methods, apparatus and articles of manufacture for risk scoring for internet protocol networks are provided herein. A method includes identifying a network to which a first network element belongs, wherein said first network element comprises corresponding risk-related information, determining each of one or more network elements previously identified as belonging to the network, and calculating a risk score assigned to the network, wherein said calculating comprises aggregating (i) the risk-related information corresponding to the first network element and (ii) risk-related information corresponding to each of the one or more network elements previously identified as belonging to the network.


