Server-Based Fraud Detection via Behavioral Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for detecting fraudulent online transactions, such as using anti-malware software, are ineffective due to user resistance and the constant need for updates, as they fail to detect hidden malware controlling a client device without interfering with device performance or requiring frequent software upgrades.

Innovation Solution

Analyzing activity patterns on a client device to detect improbable processes, such as simultaneous mouse locations or active windows, which indicate potential fraudulent activity, allowing for real-time detection and notification of unauthorized access without the need for up-to-date anti-virus or anti-malware software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anti-malware software is installed on the client device to detect fraudulent activity, then detection capability is improved, but user convenience deteriorates due to performance reduction and software incompatibility concerns

Engineering Contradiction:
Improvefraud detection capabilityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a server-based fraud detection system that acts as an intermediary between the client device and the fraudulent activity. Instead of installing detection software on the client, the server collects data from the client and performs analysis remotely, eliminating the need for client-side anti-malware software while maintaining detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of installing local anti-malware software with a network-based data collection and analysis system. The server remotely gathers device information and analyzes it for fraudulent patterns, substituting the need for local security software with a centralized analytical system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If anti-malware software is frequently updated to keep up with changing malware, then detection accuracy is improved, but maintenance complexity increases due to continuous update requirements

Engineering Contradiction:
Improvedetection accuracyVSAvoidsoftware maintenance complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent inverts the traditional approach by not trying to detect specific known malware signatures, but rather detecting the presence of any fraudulent activity through behavioral analysis. The server analyzes device data for improbable processes and fraudulent patterns without needing to know what specific malware is present, eliminating the need for continuous signature updates.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent changes the detection parameters from static malware signatures to dynamic behavioral patterns. Instead of looking for specific known malicious code, the system monitors device behavior parameters such as process execution patterns, network activity, and system resource usage to identify fraudulent activity regardless of the specific malware variant.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive fraud detection methods are implemented, then security is improved, but system resource consumption increases due to continuous monitoring requirements

Engineering Contradiction:
Improvesecurity levelVSAvoiddevice energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the computationally intensive fraud detection processes from the client device and relocates them to the server. The client only needs to collect and transmit data, while the server performs the heavy lifting of analyzing device information and identifying fraudulent patterns, significantly reducing client-side energy consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a balanced approach where the client collects necessary device data without continuous comprehensive monitoring. Data collection occurs at appropriate intervals and only when needed, while the server performs thorough analysis on the received data, achieving effective security without excessive client-side resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9565205B1Detecting fraudulent activity from compromised devices
Publication Date: 2017.02.07 EMC IP HLDG CO LLC
  • US9565205B1 patent drawing
  • US9565205B1 patent drawing
  • US9565205B1 patent drawing

AI summary

A technique for detecting fraudulent activity in a compromised device involves downloading a software application from a processor that controls access to a resource to an electronic device requesting access to the resource. The software application includes instructions that gather selected information from the electronic device such as mouse coordinates and active windows at a selected time and transmitting the information to the processor for analysis. The analysis includes determining whether more than a single input operation is occurring simultaneously. Simultaneous input operations are an improbable combination of processes for a single electronic device, and suggest a potential fraudulent activity. The technique may include sending a message to a security location for further analysis of the potential fraudulent activity, or the user may be contacted while the transaction attempt is delayed, or the attempted transaction operation may be terminated until enhanced security procedures are implemented.