Network Risk Scores for Anomalous Activity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Detecting anomalous activities, such as fraudulent activities, in multi-provider transactional environments is challenging due to the large volume of transactional data and complex inter-provider relationships, which existing solutions struggle to effectively model and process, leading to inefficiencies and inaccuracies in anomaly detection.

Innovation Solution

The method involves generating network risk scores for provider-centric networks based on relational proximity criteria, using graph interface views to visualize relationships and apply domain-specific pattern recognition, and preprocessing transactional data to reduce computational complexity, enabling efficient detection of anomalous activity patterns across multi-provider environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If graph-based solutions with network risk scores are implemented, then anomaly detection accuracy is improved, but computational complexity increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex multi-provider transactional environment into provider-centric networks, where each provider is analyzed within their own localized network context. This segmentation allows the system to apply graph-based analysis to manageable subsets of data rather than attempting to process all transactional data globally, thereby improving detection accuracy while controlling computational complexity through localized processing.

Inventive Principle:
Principle #1Segmentation

2Reliability

If comprehensive transactional data from multiple providers is processed, then detection coverage is improved, but processing time increases

Engineering Contradiction:
Improvedetection coverageVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-processing transactional data to construct provider-centric networks and calculate network risk scores before actual anomaly detection occurs. Relationships between providers are pre-identified and stored in graph structures, allowing the system to quickly query pre-computed risk scores and relationships during detection operations rather than computing everything from raw transactional data in real-time.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If relational proximity criteria are applied to multiple relationship types, then relationship modeling accuracy is improved, but data processing complexity increases

Engineering Contradiction:
Improverelationship modeling accuracyVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by using different relational proximity criteria for different types of relationships within the provider network. Direct relationships between providers use one set of proximity criteria, while indirect relationships use different criteria, allowing the system to model each relationship type with the most appropriate metrics for its specific characteristics rather than applying a uniform approach to all relationships.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11361082B2Anomalous activity detection in multi-provider transactional environments
Publication Date: 2022.06.14 OPTUM SERVICES IRELAND LTD
  • US11361082B2 patent drawing
  • US11361082B2 patent drawing
  • US11361082B2 patent drawing

AI summary

To detect anomalous activity within a multi-provider environment of transactional data, a particular target entity of a plurality of entities, such as a provider, is identified; multiple relationships associated with the multi-provider environment are determined, wherein each relationship is associated with a relationship score, and wherein the relationship score is determined based on a relational proximity criterion satisfied by the relationship; one or more risk scores are generated; a network risk score is generated for the target entity, multiple levels of related entities are identified, and anomalous activity detection is performed based on the network risk score. Anomalous activity and entity relationships are presented in a graph interface.