Network Risk Scoring via IP Aggregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic fraud network (EFN) systems are inadequate in assigning risk scores, as they focus solely on individual IP addresses, allowing fraudsters to continue fraudulent activities by switching IP addresses without being associated with the initial risk score.

Innovation Solution

Calculating a risk score for networks or subnets by aggregating risk-related information from multiple IP addresses, including trust levels associated with entities, to assign a comprehensive risk score that encompasses all connected IP addresses, thereby increasing the accuracy of risk assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If risk scores are calculated based solely on individual IP address history, then the calculation process is simple and fast, but fraudsters can switch IP addresses to continue fraudulent activity without being detected

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidrisk scoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple IP addresses belonging to the same network into a single risk scoring unit. Instead of evaluating each IP address independently, the system aggregates risk-related information from all IP addresses within a network, creating a unified network-level risk score that reflects the collective behavior of all associated IP addresses.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent transitions from a one-dimensional IP address-level risk assessment to a two-dimensional approach by introducing the network dimension. This allows the system to evaluate risk at both the individual IP address level and the network level, providing a more comprehensive view of fraudulent activity patterns.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If risk scores are assigned to individual IP addresses only, then the data processing requirement is low, but the system cannot detect fraud when IP addresses are switched within the same network

Engineering Contradiction:
Improverisk assessment accuracyVSAvoiddata processing volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system combines risk-related information from multiple IP addresses into a unified network risk assessment. By merging data from all IP addresses within a network, the system achieves more precise risk measurement that captures fraudulent patterns across the entire network rather than isolating individual IP addresses.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network-level risk scoring system serves multiple functions: it evaluates individual IP addresses, assesses overall network risk, and provides a mechanism to detect fraudsters who switch between IP addresses. This multi-functional approach increases measurement precision without proportionally increasing data processing requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the system evaluates each IP address independently, then the processing speed is high, but fraud detection capability is limited when multiple IP addresses are used by the same fraudster

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidnetwork analysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies merging by consolidating the evaluation of multiple IP addresses into a single network-level assessment. This allows the system to maintain processing efficiency while significantly improving fraud detection capability, as the network-level risk score captures patterns that would be invisible when evaluating IP addresses in isolation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network serves as an intermediary concept that connects multiple IP addresses. By introducing this intermediate level of analysis, the system can efficiently evaluate fraud risk without directly comparing every individual IP address, thus improving detection capability while managing complexity through the network abstraction layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9438626B1Risk scoring for internet protocol networks
Publication Date: 2016.09.06 DELL EMC
  • US9438626B1 patent drawing
  • US9438626B1 patent drawing
  • US9438626B1 patent drawing

AI summary

Methods, apparatus and articles of manufacture for risk scoring for internet protocol networks are provided herein. A method includes identifying a network to which a first network element belongs, wherein said first network element comprises corresponding risk-related information, determining each of one or more network elements previously identified as belonging to the network, and calculating a risk score assigned to the network, wherein said calculating comprises aggregating (i) the risk-related information corresponding to the first network element and (ii) risk-related information corresponding to each of the one or more network elements previously identified as belonging to the network.