Payment Network Ransomware Merchant Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identifying entities involved in the distribution and profiting from ransomware is challenging due to the clandestine nature of ransomware propagation and the difficulty in tracing the source from the point of contact, often leading to unaware distributors and significant financial gains for nefarious entities.

Innovation Solution

A system and method that involve storing merchant profiles with identifiers, receiving authorization requests for transactions initiated by infected devices, and updating profiles to indicate association with ransomware, using a payment network to identify and update merchant profiles, thereby associating merchants with ransomware distribution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional methods are used to identify ransomware distributors by analyzing installed malware and distribution channels, then identification accuracy may be improved, but the complexity and difficulty of the process increases significantly

Engineering Contradiction:
Improveidentification accuracyVSAvoidprocess complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a payment network as an intermediary between the ransomware distribution system and law enforcement investigators. Instead of directly analyzing complex malware distribution channels, the system uses payment transaction data as an intermediary indicator to identify merchants associated with ransomware, thereby simplifying the identification process while maintaining accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the identification problem from the complex ransomware distribution system by focusing on a specific observable element - payment transactions. By taking out the payment transaction data from the overall ransomware ecosystem, the system can identify merchants without needing to analyze the entire distribution chain, reducing process complexity

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If payment transaction monitoring is used to identify merchants associated with ransomware, then the ease of operation is improved, but the ability to identify the actual source of ransomware distribution deteriorates

Engineering Contradiction:
Improveidentification easeVSAvoidsource identification accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system performs preliminary action by monitoring and recording payment transactions in advance. By capturing transaction data before the actual harm is completed, the system creates a trail that can be used for identification. The merchant profile database is updated proactively with transaction information, enabling easier identification without losing source tracking capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring payment transactions and updating merchant profiles based on identified ransomware-associated transactions. This feedback loop allows the system to refine its identification accuracy over time while maintaining ease of operation through automated processes

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11017383B2Method and system for identifying merchants selling ransomware
Publication Date: 2021.05.25 MASTERCARD INT INC
  • US11017383B2 patent drawing
  • US11017383B2 patent drawing
  • US11017383B2 patent drawing

AI summary

A method for identifying a merchant associated with ransomware includes: storing, in a profile database, a plurality of merchant profiles, wherein each merchant profile is related to a merchant and includes at least a merchant identifier; receiving, by a receiving device, an authorization request for a payment transaction, wherein the authorization request includes a specific merchant identifier associated with a merchant involved in the payment transaction, and the payment transaction is initiated by a computing device infected with one or more ransomware application programs; identifying, by a processing device, a specific merchant profile in the profile database where the included merchant identifier corresponds to the specific merchant identifier included in the received authorization request; and updating, by the processing device, the specific merchant profile in the profile database to include an indication that the related merchant is associated with the distribution of the one or more ransomware application programs.