Payment Transaction Roughness Profiling for Adaptive Cyber-Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cyber-attack detection systems in payment networks are ineffective in detecting low-level and changing tactics of fraudulent activity due to their static nature, leading to undetected cyber-attacks, increased network load, and computational burdens.
Innovation Solution
A cyber-attack detection system utilizing a roughness profiling engine that groups and profiles transaction authorization requests, calculates cumulative metrics, and generates roughness ratio values to input into a machine learning model for real-time detection of cyber-attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static models are used to monitor payment transactions, then the system is simple to implement, but the system cannot detect low-level cyber-attacks or changing tactics of fraudulent activity
Solution Approach 1:
The patent implements dynamic modeling where the system continuously learns and adapts to new fraudulent patterns. The model evolves over time by incorporating new data and adjusting its parameters, allowing it to detect changing tactics of fraudulent activity rather than relying on fixed static rules.
Solution Approach 2:
The system incorporates feedback mechanisms where detection results are fed back into the model to continuously improve its accuracy. The model learns from both detected fraudulent transactions and legitimate transactions, adjusting its parameters to reduce false positives and improve detection of new attack patterns.
2Reliability
If comprehensive transaction monitoring is performed, then detection capability is improved, but network load and computational burden increase
Solution Approach 1:
The patent segments the transaction monitoring process into multiple stages: initial filtering using roughness profiling to identify suspicious transactions, then applying more computationally intensive machine learning analysis only to those segmented suspicious cases. This hierarchical segmentation reduces overall computational burden while maintaining detection capability.
Solution Approach 2:
The system applies partial monitoring actions to all transactions (roughness profiling) and excessive/detailed analysis only to suspicious transactions identified by the initial filter. This selective application of computational resources optimizes the balance between detection capability and computational burden.
Data Source
AI summary
A computing system for detecting cyber-attack events is described. The computing system executes a roughness profiling engine and a cyber-attack detection model. The roughness profiling engine is configured to receive a plurality of payment transaction authorization request messages and generate a plurality of groups, each group of the plurality of groups associated with a first data field. The roughness profiling engine is also configured to profile the plurality of groups into a plurality of sub-groups, each sub-group of the plurality of sub-groups associated with a second data field and calculate a respective cumulative metric from the payment transaction authorization request messages associated with one of the plurality of sub-groups. The roughness profiling engine is further configured to determine a roughness ratio value, generate a set of feature inputs based on the roughness ratio value, and transmit the set of feature inputs to the cyber-attack detection model.


