Real-Time Live-Data Analysis for Fraud Detection in Mobile Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network monitoring systems suffer from latency delays of up to 15 minutes for event data to be extracted and delivered to databases, limiting their ability to respond to time-critical events such as fraud detection in mobile carrier networks, and lack the capability for real-time identification and verification of transactions during data transmission.
Innovation Solution
A system and method for real-time live-data analysis that monitors and analyzes network traffic non-intrusively, allowing for immediate detection of potential fraud situations by comparing transactions to known fraud patterns and generating alerts, with the ability to verify the identity of parties involved during the transaction through a dialog verification process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network data is captured by inline probes and processed offline after events complete, then comprehensive analysis can be performed, but latency delays of up to 15 minutes occur and time-critical fraud detection is impossible
Solution Approach 1:
The system performs preliminary actions by continuously monitoring and analyzing network traffic in real-time as it flows through the network, rather than waiting for events to complete. This allows the system to detect fraud patterns during transaction processing and take preventive actions before financial losses occur, eliminating the 15-minute latency of offline processing
Solution Approach 2:
The patent introduces an intermediary real-time analysis system that sits between the network traffic flow and offline databases. This intermediary continuously captures and analyzes traffic patterns, comparing them against known fraud patterns while transactions are still in progress, enabling timely detection without disrupting the original offline processing architecture
2Quantity of substance
If multiple terabytes of data are written into databases for later analysis, then comprehensive event records are available, but Big Data analytical challenges arise and real-time decision making is prevented
Solution Approach 1:
The system extracts only the critical real-time analysis functions from the bulk data processing workload. By continuously monitoring traffic flows and comparing them against fraud patterns in real-time, the system separates time-critical detection tasks from offline archival storage, allowing rapid detection without being burdened by terabytes of historical data
Solution Approach 2:
The patent segments the data processing system into two independent components: a real-time monitoring engine that analyzes traffic patterns as they flow through the network, and an offline database system that stores comprehensive event records. This segmentation allows each component to optimize for its specific function without the performance constraints of handling both real-time and archival data together
3Reliability
If inline hardware probes are deployed to capture network data, then continuous monitoring is achieved, but significant capital expenditures are required and system complexity increases
Solution Approach 1:
The patent replaces the mechanical inline hardware probe system with a software-based real-time analysis solution. The software system captures and analyzes network traffic using virtual monitoring mechanisms that leverage existing network infrastructure, eliminating the need for expensive dedicated hardware probes while maintaining continuous monitoring capabilities
4Loss of information
If events are analyzed after they complete and are stored as log records, then comprehensive post-event analysis is possible, but the ability to respond flexibly to live conditions is limited
Solution Approach 1:
The system maintains continuous useful action by simultaneously performing both real-time analysis and comprehensive event recording. The real-time monitoring engine continuously compares active transactions against fraud patterns, while the same system continues to log complete event details for offline analysis, ensuring both immediate response capability and thorough investigative capability
Data Source
AI summary
A method for detecting a fraudulent attempt to activate a new PIN, SIM Card or mobile device includes monitoring, at a first processing node associated with a network interconnecting a first network point and a second network point, a mirrored live-data flow of a live data flow passing through the first processing node in a non-intrusive manner that does not affect the first live-data flow passing through the first processing node. The live-data flow comprises data that is in active transmission between the first network point and the second network point and prior to storage of the data in a database. The first processing node detects that a transaction within the monitored live-data flow relates to an activation of the new PIN, SIM card or mobile device and compares the detected transaction to a list of known fraud situations stored in the first processing node to determine if the detected transaction relates to a known fraud situation. The first processing node generates an alert indication responsive to a determination the detected data relates to one of a plurality of known fraud situations. The first processing node identifies the detected transaction as a potential fraud situation responsive to a determination the detected data does not relate to one of the plurality known fraud situations. An automatically generated dialog verification with a party requesting the new PIN, SIM Card or mobile device is performed to verify identity of the party requesting the new PIN, SIM Card or mobile device for the detected transaction identified as the potential fraud situation.


