Neural Network Fraud Detection Using Behavioral Biometrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security measures fail to detect unauthorized access when user credentials are compromised, as they rely on emulable device characteristics and cannot differentiate between authorized and unauthorized users, especially in cases of physical or remote control of the user's computer.

Innovation Solution

A method using a neural network to analyze user behavior biometric data, such as cursor movement, generating images from this data, and training a model to predict fraud, which cannot be easily emulated by attackers, and correlating results with log data for improved accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security measures compare device characteristics (IP address, device identifier) to historical records, then access control can be implemented, but unauthorized users can emulate these characteristics to evade detection

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidemulation resistance
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces conventional mechanical/authentication-based security measures (comparing IP addresses and device identifiers) with a biometric-based detection system that analyzes user behavior patterns. Specifically, it captures cursor movement data and generates biometric images representing unique user interaction patterns, which are then analyzed by a neural network to detect fraud. This substitution moves from emulable device characteristics to non-emulable behavioral biometrics.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If conventional techniques restrict access based on device identifier mismatches, then unauthorized access can be prevented in some cases, but legitimate users with modified devices or shared computers cannot access services

Engineering Contradiction:
Improveaccess control accuracyVSAvoidlegitimate access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system continuously monitors and analyzes user behavior patterns through cursor movement data, providing real-time feedback on authentication status. Instead of a single static authentication decision based on device identifiers, the system accumulates behavioral biometric data and uses neural network analysis to dynamically assess whether the current user matches the authorized user's behavioral pattern, allowing for more nuanced access decisions.

Inventive Principle:
Principle #23Feedback

3Reliability

If behavior biometric data is collected and analyzed using traditional machine learning methods, then fraud detection can be implemented, but small datasets lead to poor generalization and inaccurate predictions

Engineering Contradiction:
Improvefraud prediction accuracyVSAvoidtraining data volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent transforms the parameter representation of behavior biometric data by converting raw cursor movement data into biometric images. This parameter transformation allows the neural network to more effectively learn from small datasets by representing behavioral patterns in a visual format that captures essential characteristics while reducing dimensionality and noise, thereby improving generalization performance with limited training data.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11315010B2Neural networks for detecting fraud based on user behavior biometrics
Publication Date: 2022.04.26 CISCO TECHNOLOGY INC
  • US11315010B2 patent drawing
  • US11315010B2 patent drawing
  • US11315010B2 patent drawing

AI summary

One embodiment of the present invention sets forth a technique for predicting fraud by analyzing user behavior biometric data via a neural network (NN). The technique includes receiving cursor movement data generated via at least one client device, where the cursor movement data is associated with a group of one or more users. The technique further includes generating a plurality of images based on the cursor movement data and training a first neural network (NN) model based on the plurality of images and based on a discard rate that is greater than 50%.