Video Conferencing Fraud Detection via ML Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current video conferencing systems lack effective mechanisms to detect and prevent fraud, particularly through IP network and telephony network interfaces, which can lead to unauthorized access and resource exploitation.

Innovation Solution

The implementation of a video conferencing system that generates event data to train machine learning models for fraud detection, such as IP fraud detection and telephony fraud detection models, to identify anomalous traffic patterns and take countermeasures like blocking IP addresses or telephone numbers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If machine learning models are implemented for fraud detection, then system security is improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces machine learning models as intermediary components between the video conferencing system and fraudulent activities. These models act as mediators that analyze traffic patterns, evaluate features, and make security decisions without requiring complex manual security management. The models are trained on historical data and automatically detect anomalies, providing security through an intelligent intermediary layer rather than through complex system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If fraud detection models are deployed, then fraudulent activities are prevented, but computing resources are consumed

Engineering Contradiction:
Improvefraud prevention capabilityVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements partial action by not analyzing all traffic uniformly. Instead, the machine learning models focus computational resources on evaluating specific features and patterns that indicate potential fraud. The system processes only relevant portions of traffic data that contain fraud indicators, rather than performing exhaustive analysis on all communications, thereby reducing overall computing resource consumption while maintaining effective fraud detection.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If event data is collected and processed, then fraud detection accuracy is improved, but loss of time increases

Engineering Contradiction:
Improvefraud detection accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-processing and preparing event data in advance for fraud detection. The system collects and stores event data with relevant features extracted and organized beforehand, so that when fraud detection is needed, the machine learning models can quickly evaluate pre-prepared information rather than processing raw data from scratch. This preliminary preparation of data significantly reduces the time required for accurate fraud detection while maintaining high detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12342099B2Systems and methods for detecting and preventing fraud in a video conferencing system
Publication Date: 2025.06.24 VERIZON PATENT & LICENSING INC
  • US12342099B2 patent drawing
  • US12342099B2 patent drawing
  • US12342099B2 patent drawing

AI summary

A device may receive event data identifying events associated with user devices utilizing a video conferencing system, and may utilize the event data to train one or more fraud detection models. The device may receive, from a user device, user traffic including at least one of API traffic or media traffic, and may identify characteristics of the user traffic, such as activity related features, application-specific features, and dial-in number-specific features. The device may process at least one of the activity related features, the application-specific features, or the dial-in number-specific features, with the one or more fraud detection models, to determine whether the user traffic from the user device is anomalous or normal, and may block at least one of an IP address of the user device, a telephone number of the user device, or a meeting of the user device, based on determining that the user traffic is anomalous.