Server-Based Fraud Detection via Behavioral Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for detecting fraudulent online transactions, such as using anti-malware software, are ineffective due to user resistance and the constant need for updates, as they fail to detect hidden malware controlling a client device without interfering with device performance or requiring frequent software upgrades.
Innovation Solution
Analyzing activity patterns on a client device to detect improbable processes, such as simultaneous mouse locations or active windows, which indicate potential fraudulent activity, allowing for real-time detection and notification of unauthorized access without the need for up-to-date anti-virus or anti-malware software.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anti-malware software is installed on the client device to detect fraudulent activity, then detection capability is improved, but user convenience deteriorates due to performance reduction and software incompatibility concerns
Solution Approach 1:
The patent introduces a server-based fraud detection system that acts as an intermediary between the client device and the fraudulent activity. Instead of installing detection software on the client, the server collects data from the client and performs analysis remotely, eliminating the need for client-side anti-malware software while maintaining detection capability.
Solution Approach 2:
The patent replaces the mechanical approach of installing local anti-malware software with a network-based data collection and analysis system. The server remotely gathers device information and analyzes it for fraudulent patterns, substituting the need for local security software with a centralized analytical system.
2Reliability
If anti-malware software is frequently updated to keep up with changing malware, then detection accuracy is improved, but maintenance complexity increases due to continuous update requirements
Solution Approach 1:
The patent inverts the traditional approach by not trying to detect specific known malware signatures, but rather detecting the presence of any fraudulent activity through behavioral analysis. The server analyzes device data for improbable processes and fraudulent patterns without needing to know what specific malware is present, eliminating the need for continuous signature updates.
Solution Approach 2:
The patent changes the detection parameters from static malware signatures to dynamic behavioral patterns. Instead of looking for specific known malicious code, the system monitors device behavior parameters such as process execution patterns, network activity, and system resource usage to identify fraudulent activity regardless of the specific malware variant.
3Reliability
If comprehensive fraud detection methods are implemented, then security is improved, but system resource consumption increases due to continuous monitoring requirements
Solution Approach 1:
The patent extracts the computationally intensive fraud detection processes from the client device and relocates them to the server. The client only needs to collect and transmit data, while the server performs the heavy lifting of analyzing device information and identifying fraudulent patterns, significantly reducing client-side energy consumption.
Solution Approach 2:
The patent implements a balanced approach where the client collects necessary device data without continuous comprehensive monitoring. Data collection occurs at appropriate intervals and only when needed, while the server performs thorough analysis on the received data, achieving effective security without excessive client-side resource consumption.
Data Source
AI summary
A technique for detecting fraudulent activity in a compromised device involves downloading a software application from a processor that controls access to a resource to an electronic device requesting access to the resource. The software application includes instructions that gather selected information from the electronic device such as mouse coordinates and active windows at a selected time and transmitting the information to the processor for analysis. The analysis includes determining whether more than a single input operation is occurring simultaneously. Simultaneous input operations are an improbable combination of processes for a single electronic device, and suggest a potential fraudulent activity. The technique may include sending a message to a security location for further analysis of the potential fraudulent activity, or the user may be contacted while the transaction attempt is delayed, or the attempted transaction operation may be terminated until enhanced security procedures are implemented.


