Payment Risk Decisioning via Cyber Fraud Intelligence Merging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to accurately identify and address business email compromise (BEC) scams and other socially engineered fraudulent activities, as they primarily rely on payment data from requesting entities, lacking sufficient visibility into fraudulent behavior initiated by third-party fraudsters targeting clients.

Innovation Solution

A computer-implemented system and method that combines payment data with cyber fraud indicators to generate a risk score, incorporating indicators such as IP addresses, malware, and look-alike domain registrations, to determine the legitimacy of payment requests and prevent fraudulent transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current systems rely only on payment data from requesting entities, then the systems are simple to operate, but they fail to accurately identify BEC scams and socially engineered fraud

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges payment data from requesting entities with cyber fraud intelligence data from external sources (threat intelligence feeds, malware indicators, domain reputation services) into a unified fraud assessment system. This combination enables accurate detection of BEC scams by correlating payment request patterns with known fraud indicators, resolving the contradiction between detection accuracy and system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system introduces an intermediary fraud intelligence platform that aggregates and analyzes cyber threat data from multiple external sources. This intermediary layer processes complex fraud indicators (malware hashes, suspicious domains, IP reputation) and presents simplified risk scores to the payment processing system, enabling accurate fraud detection without overwhelming the core payment system with complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the system aggregates multiple cyber fraud indicators and payment data, then fraud detection accuracy improves, but the processing time and computational resources increase

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidpayment processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-aggregating and indexing cyber fraud intelligence data from external sources before payment requests arrive. Threat intelligence feeds, malware indicators, and domain reputation data are continuously updated and stored in ready-to-query formats. When a payment request is received, the system quickly queries pre-processed data rather than gathering information in real-time, maintaining high detection accuracy while minimizing processing delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies local quality by selectively applying different levels of analysis to different payment requests based on risk indicators. Low-risk transactions receive minimal scrutiny with fast processing, while transactions exhibiting suspicious patterns trigger deeper analysis of cyber fraud indicators. This differentiated approach maintains security accuracy while preventing time loss on legitimate transactions.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11494773B2System and method for integrating cyber fraud intelligence and payment risk decisions
Publication Date: 2022.11.08 JPMORGAN CHASE BANK NA
  • US11494773B2 patent drawing
  • US11494773B2 patent drawing
  • US11494773B2 patent drawing

AI summary

The invention relates to a method and system that combines payment data and cyber fraud indicators to identify potential fraud in payment requests from a client. The system comprises: a memory that stores and maintains a list of known fraud characteristics and cyber fraud indicators; and a computer processor, coupled to the memory, programmed to: receive, via an electronic input, a payment instruction from the client; identify one or more cyber fraud indicators associated with the payment instruction; apply payment decisioning to merge the one or more cyber fraud indicators to the payment instruction; generate a risk score based on the payment decisioning to determine whether the payment instruction should be executed; and automatically apply the payment decisioning to the payment instruction.