Payment Transaction Roughness Profiling for Adaptive Cyber-Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber-attack detection systems in payment networks are ineffective in detecting low-level and changing tactics of fraudulent activity due to their static nature, leading to undetected cyber-attacks, increased network load, and computational burdens.

Innovation Solution

A cyber-attack detection system utilizing a roughness profiling engine that groups and profiles transaction authorization requests, calculates cumulative metrics, and generates roughness ratio values to input into a machine learning model for real-time detection of cyber-attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static models are used to monitor payment transactions, then the system is simple to implement, but the system cannot detect low-level cyber-attacks or changing tactics of fraudulent activity

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic modeling where the system continuously learns and adapts to new fraudulent patterns. The model evolves over time by incorporating new data and adjusting its parameters, allowing it to detect changing tactics of fraudulent activity rather than relying on fixed static rules.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where detection results are fed back into the model to continuously improve its accuracy. The model learns from both detected fraudulent transactions and legitimate transactions, adjusting its parameters to reduce false positives and improve detection of new attack patterns.

Inventive Principle:
Principle #23Feedback

2Reliability

If comprehensive transaction monitoring is performed, then detection capability is improved, but network load and computational burden increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidcomputational burden
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the transaction monitoring process into multiple stages: initial filtering using roughness profiling to identify suspicious transactions, then applying more computationally intensive machine learning analysis only to those segmented suspicious cases. This hierarchical segmentation reduces overall computational burden while maintaining detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial monitoring actions to all transactions (roughness profiling) and excessive/detailed analysis only to suspicious transactions identified by the initial filter. This selective application of computational resources optimizes the balance between detection capability and computational burden.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12368727B2Systems and methods for improved detection of network attacks
Publication Date: 2025.07.22 MASTERCARD INT INC
  • US12368727B2 patent drawing
  • US12368727B2 patent drawing
  • US12368727B2 patent drawing

AI summary

A computing system for detecting cyber-attack events is described. The computing system executes a roughness profiling engine and a cyber-attack detection model. The roughness profiling engine is configured to receive a plurality of payment transaction authorization request messages and generate a plurality of groups, each group of the plurality of groups associated with a first data field. The roughness profiling engine is also configured to profile the plurality of groups into a plurality of sub-groups, each sub-group of the plurality of sub-groups associated with a second data field and calculate a respective cumulative metric from the payment transaction authorization request messages associated with one of the plurality of sub-groups. The roughness profiling engine is further configured to determine a roughness ratio value, generate a set of feature inputs based on the roughness ratio value, and transmit the set of feature inputs to the cyber-attack detection model.