Web Bug File Placement for Low-Interference Fraud Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing deception systems that use decoy data risk interfering with the work of legitimate users due to imperfect fraud assessment, potentially hindering legitimate processes with false data returns.

Innovation Solution

A placement location selection device that embeds a notification function in files not typically used by high-risk users, using a web bug to transmit data outside the system, monitored by a beacon unit to minimize interference with legitimate users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If false data is returned to detect fraud, then security assessment capability is improved, but legitimate users may be interfered with due to imperfect fraud assessment accuracy

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidinterference with legitimate user work
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by differentiating the treatment of different files based on their characteristics and usage patterns. High-risk files are identified through analysis of file properties (such as extension, size, creation date) and user behavior patterns, then targeted for deception while preserving normal operation for legitimate files. This localized approach ensures that deception is applied only where needed to detect fraud without interfering with legitimate user work.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements preliminary action by pre-identifying and marking high-risk files before they are accessed. The system analyzes file characteristics and user access patterns in advance to determine which files should contain deception, then prepares those files with the necessary markers or attributes. This preliminary identification ensures that when fraud detection occurs, the system already knows which files to treat with caution, reducing false positives for legitimate users.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If deception system uses decoy data to intercept reads, then fraud detection is enhanced, but work of legitimate users is hindered

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidlegitimate user work efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies local quality by selectively applying deception only to specific files identified as high-risk based on their characteristics and access patterns. Not all files are treated uniformly; instead, the system analyzes each file's properties (extension, size, creation date) and user interaction history to determine whether it requires deception. This ensures fraud detection capability is enhanced for suspicious files while legitimate user work on non-suspicious files remains unaffected.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements feedback by continuously monitoring user access patterns and file usage behavior to refine the identification of high-risk files. The system learns from actual usage data to improve its accuracy in distinguishing between fraudulent and legitimate access over time. This feedback mechanism allows the deception system to become more precise, reducing false alarms that would hinder legitimate user productivity while maintaining strong fraud detection.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250272396A1Placement location selection device, placement location selection method, and non-transitory computer readable medium
Publication Date: 2025.08.28 MITSUBISHI ELECTRIC CORP
  • US20250272396A1 patent drawing
  • US20250272396A1 patent drawing
  • US20250272396A1 patent drawing

AI summary

A placement location selection device (100) includes a web bug embedding unit (130) and a beacon monitoring unit (140). The web bug embedding unit (130) embeds a notification function in a target file that exists in a placement target area. The notification function is a function to transmit notification data to outside of a system where the target file is stored when the target file is opened outside the target system. The placement target area is an area corresponding to part of a file tree managed by the target system and including a file estimated not to be used by a high-risk user who is a user of the target system in normal work of the high-risk user among one or more files accessed by the high-risk user. The beacon monitoring unit (140) monitors whether the notification data has been transmitted.