Communications Server Abstention Attack Detection via Handshake Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current fraud prevention systems fail to effectively detect and remediate abstention attacks, where attackers evade data collection by not participating in the data collection exercise, leading to undetected fraud and financial losses, especially in mobile fraud scenarios.

Innovation Solution

A communications server apparatus initiates a handshake process with user communications devices, monitoring for a response within a defined time duration, and upon expiry without a response, determines an abstention attack, generating termination data to block access and prevent further communication, incorporating a nonce to prevent replay attacks and buffer for network issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If fraud prevention systems monitor data collection participation, then detection capability improves, but system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements feedback by monitoring whether devices send expected data payloads during data collection and providing feedback through abstention attack detection when payloads are missing, enabling automatic remediation without complex additional monitoring infrastructure

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system uses self-service by leveraging existing communication channels and data collection mechanisms to detect abstention attacks, rather than requiring separate complex detection systems. The fraud prevention system monitors its own data collection process and automatically identifies when devices fail to participate

Inventive Principle:
Principle #25Self-service

2Reliability

If the system blocks access upon detecting abstention attacks, then fraud prevention effectiveness improves, but false positive rate increases

Engineering Contradiction:
Improvefraud prevention effectivenessVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system changes parameters by introducing a configurable time duration threshold for determining abstention attacks. By adjusting this parameter, the system can balance between detecting fraud effectively and avoiding false positives from legitimate slow connections or processing delays

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies dynamics by making the detection threshold configurable and adaptable. The time duration parameter can be tuned based on network conditions and service requirements, allowing the system to dynamically adjust its sensitivity to abstention attacks versus legitimate delays

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If the system waits for a defined time duration before flagging abstention attacks, then false positives decrease, but detection delay increases

Engineering Contradiction:
Improvefalse positivesVSAvoiddetection delay
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The system uses parameter changes by implementing a configurable time duration that balances false positive reduction with timely detection. This parameter can be optimized to match typical network response times while still catching deliberate abstention attacks within an acceptable time frame

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20220277089A1Communications server apparatus and method for determination of an abstention attack
Publication Date: 2022.09.01 GRABTAXI HOLDINGS PTE LTD
  • US20220277089A1 patent drawing
  • US20220277089A1 patent drawing
  • US20220277089A1 patent drawing

AI summary

A communications server apparatus for determination of an abstention attack associated with a user communications device, configured to transmit handshake data to the user communications device, monitor, for a defined time duration, for a handshake response from the user communications device corresponding to the handshake data, and in response to expiry of the defined time duration with no handshake response corresponding to the handshake data being received by the communications server apparatus, and, further, in response to the communications server apparatus determining presence of an event that is indicative of the user communications device being in a communication mode with the communications server apparatus, determine that there is the abstention attack, and generate termination data in response to the determination of the abstention attack for denying the user communications device access to a service associated with the communications server apparatus.