Watchdog Transaction Accounts for Security Breach Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting security breaches in merchants are inefficient, as they often fail to pinpoint the source and timeframe of data breaches, requiring a large volume of fraudulent transactions to identify compromised accounts, leading to delayed detection and remediation.

Innovation Solution

Implementing a network environment with a security agent that initiates watchdog transactions using fictitious accounts to monitor merchant systems, allowing for precise identification of breached merchants and timely detection of security incidents by analyzing watchdog transaction records.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If financial institutions monitor fraudulent transactions to detect security breaches, then they can identify compromised card accounts, but they cannot pinpoint the specific merchant or timeframe of the breach due to delays and large data volumes required

Engineering Contradiction:
Improveprecision of breach detectionVSAvoiddetection delay
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by having the security agent proactively initiate watchdog transactions and store their records in advance before any breach occurs. This allows the system to have detection data ready immediately when a breach is suspected, eliminating detection delays while maintaining high precision in identifying both the merchant and timeframe of the breach.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a large volume of fraudulent transactions is required to identify common points of purchase, then statistical significance is achieved, but detection time is significantly delayed

Engineering Contradiction:
Improvereliability of breach identificationVSAvoiddetection speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system introduces an intermediary mechanism - the watchdog transaction records stored by the security agent - that serves as a reference benchmark. When fraud is detected, this pre-stored record allows immediate comparison and identification of the specific merchant, achieving both high reliability and fast detection without requiring analysis of large volumes of fraudulent transactions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If traditional fraud monitoring is used, then compromised accounts can be identified eventually, but the specific merchant and exact timeframe of the breach cannot be determined

Engineering Contradiction:
Improveinformation about breach sourceVSAvoidprecision of breach location
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The system creates a copy of the legitimate transaction process by having the security agent initiate watchdog transactions that mirror normal customer transactions. These copied transactions are stored with full details including merchant identifier and timestamp, enabling precise reconstruction and identification of the breach source when fraud occurs, thereby recovering all lost information about the breach.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20230196383A1Detecting security breaches with watchdog transaction accounts
Publication Date: 2023.06.22 AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC
  • US20230196383A1 patent drawing
  • US20230196383A1 patent drawing
  • US20230196383A1 patent drawing

AI summary

Disclosed are various embodiments for detecting security breaches using watchdog transaction accounts. A security agent can initiate a purchase with a first electronic commerce system and provide a watchdog transaction account as payment for the purchase. The security agent can then store a record of the purchase which includes a merchant identifier for the merchant and the watchdog transaction account. Subsequently, a transaction authorization system can determine that authorization for a transaction with second electronic commerce system failed. If the transaction authorization system determines that the account used in the transaction with the second electronic commerce system, then the transaction authorization system can determine that the first electronic commerce system has suffered a security breach.