Communications Server Abstention Attack Detection via Handshake Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current fraud prevention systems fail to effectively detect and remediate abstention attacks, where attackers evade data collection by not participating in the data collection exercise, leading to undetected fraud and financial losses, especially in mobile fraud scenarios.
Innovation Solution
A communications server apparatus initiates a handshake process with user communications devices, monitoring for a response within a defined time duration, and upon expiry without a response, determines an abstention attack, generating termination data to block access and prevent further communication, incorporating a nonce to prevent replay attacks and buffer for network issues.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If fraud prevention systems monitor data collection participation, then detection capability improves, but system complexity increases
Solution Approach 1:
The system implements feedback by monitoring whether devices send expected data payloads during data collection and providing feedback through abstention attack detection when payloads are missing, enabling automatic remediation without complex additional monitoring infrastructure
Solution Approach 2:
The system uses self-service by leveraging existing communication channels and data collection mechanisms to detect abstention attacks, rather than requiring separate complex detection systems. The fraud prevention system monitors its own data collection process and automatically identifies when devices fail to participate
2Reliability
If the system blocks access upon detecting abstention attacks, then fraud prevention effectiveness improves, but false positive rate increases
Solution Approach 1:
The system changes parameters by introducing a configurable time duration threshold for determining abstention attacks. By adjusting this parameter, the system can balance between detecting fraud effectively and avoiding false positives from legitimate slow connections or processing delays
Solution Approach 2:
The system applies dynamics by making the detection threshold configurable and adaptable. The time duration parameter can be tuned based on network conditions and service requirements, allowing the system to dynamically adjust its sensitivity to abstention attacks versus legitimate delays
3Object-affected harmful factors
If the system waits for a defined time duration before flagging abstention attacks, then false positives decrease, but detection delay increases
Solution Approach 1:
The system uses parameter changes by implementing a configurable time duration that balances false positive reduction with timely detection. This parameter can be optimized to match typical network response times while still catching deliberate abstention attacks within an acceptable time frame
Data Source
AI summary
A communications server apparatus for determination of an abstention attack associated with a user communications device, configured to transmit handshake data to the user communications device, monitor, for a defined time duration, for a handshake response from the user communications device corresponding to the handshake data, and in response to expiry of the defined time duration with no handshake response corresponding to the handshake data being received by the communications server apparatus, and, further, in response to the communications server apparatus determining presence of an event that is indicative of the user communications device being in a communication mode with the communications server apparatus, determine that there is the abstention attack, and generate termination data in response to the determination of the abstention attack for denying the user communications device access to a service associated with the communications server apparatus.


