Method for detecting merchant data breaches with a computer network server
Abstract
A method for minimizing merchant data breach damage depends on computers and financial networks to carry out its steps. Every payment card transaction witnessed each day by a network server is assessed by a “jury” of fraud classification algorithms and assigned a fraud-risk-verdict. Those payment transactions receiving a high-risk-fraud verdict are retained and sorted into a table according to transaction date, cardholder, and merchant. The raw verdicts are normalized and standardized according to merchant size groups, e.g., to even the comparisons that will be made. A daily tally is made for each merchant of the number of suspected-card-visits, the number of highly-probable-card-visits, and the number of total-card-visits. A merchant data-breach alert is issued if a final score and sum of the normalized verdicts exceeds a threshold.
Claims
exact text as granted — not AI-modifiedThe invention claimed is:
1 . A method for minimizing financial damage in merchant data breaches, and that depends on computers and financial networks to carry out its steps, comprising:
inputting payment authorization request records of real-time transactions received over a network from point-of-sale terminals; applying classification algorithms with a computer programmed for this purpose that depends on any data warehoused in preconditioned data structures or records; consulting a population of smart agents with a computer programmed for this purpose that depends on the data warehoused in said data structures or records; judging the weights and balances of a plurality of jurors in a jury panel of classification algorithms with a computer programmed for this purpose, and that depends on the data warehoused in said data structures or records; deciding each payment transaction request with a computer programmed for this purpose that depends on the data warehoused in said data structures or records; assessing all such records of payment card transactions witnessed each day through a network server executing a jury of fraud classification algorithms that then combine to allocate a fraud-risk-verdict for each payment card transaction; retaining those payment transactions having been allocated a high-risk-fraud verdict that exceeds a threshold value with a computer programmed for this purpose; sorting any retained payment transactions receiving a high-risk-fraud into a table according to transaction date, cardholder, and merchant with a computer programmed for this purpose; normalizing and standardizing said sorted and retained high-risk-fraud verdicts according to merchant size groups for evened comparisons using a multiplier with a computer programmed for this purpose; making a daily tally for each merchant of the number of suspected-card-visits, the number of highly-probable-card-visits, and the number of total-card-visits of normalized and standardized high-risk-fraud verdicts with a computer programmed for this purpose; and issuing a merchant data-breach alert with a computer programmed for this purpose if a final score and sum of normalized and standardized high-risk-fraud verdicts in a daily tally exceeds a threshold.
2 . The method of claim 1 , further comprising:
assembling a table for each merchant manifesting in the records of payment card transactions with a computer programmed for this purpose; and using a temporary key in place of an original merchant identifier to make for a more uniform data type with a computer programmed for this purpose; excluding records of payment card transactions corresponding to peak season dates with a computer programmed for this purpose.
3 . The method of claim 1 , further comprising with a computer programmed for this purpose:
computing the square root of a suspected number of card visits, mathematically:
Verdict
-
1
=
Suspect
Card
Visits
;
computing the square root of a suspected number of card visits divided by all card visits, mathematically:
Verdict
-
2
=
Suspect
Card
Visits
All
Card
Visits
;
computing the square root of the number of highly probable card visits divided by all card visits, mathematically:
Verdict
-
3
=
Highly
Probable
Visits
All
Card
Visits
;
and
that all then support an allocation of said fraud-risk-verdicts for each payment card transaction.
4 . The method of claim 3 , further comprising the steps of:
grouping transaction data received merchants into five size categories according to the number of card visits associated with them, and approximating (1) Small: 0 to 1000 cards seen; (2) Medium-Small: 1000 to 2,000 cards seen; (3) Medium: 2,000 to 5,000 cards seen; Medium-Large: 5,000 to 10,000 cards seen; and, Large: 10,000+ cards seen, all with a computer programmed for this purpose.
5 . The method of claim 4 , further comprising the steps of:
generating a population of smart agent profiles with a computer programmed for this purpose by data mining of historical transaction data, wherein a corresponding number of entities responsible for each transaction are sorted and each are paired with a newly minted smart agent profile; modeling with a computer programmed for this purpose each smart agent profile so generated to collect and list individual and expanded attributes of said transactions in one column dimension and by time interval series in another row dimension; storing each said smart agent profile with a computer programmed for this purpose; comparing and contrasting with a computer programmed for this purpose each transaction record attribute-by-attribute with a time-interval series of attributes archived in a paired smart agent profile, and each such comparison and contrast incrementally increases or decreases a computed fraud-risk-verdict; and outputting said computed fraud-risk-verdict with a computer programmed for this purpose as a determination of whether the newly arriving transaction record represents a genuine transaction, a suspicious transaction, or a fraudulent transaction.
6 . The of claim 5 , further comprising:
dividing each said time interval series with a computer programmed for this purpose into a real-time part and a long-term part; pre-computing with a computer programmed for this purpose each real-time part and long-term part a velocity count and statistics of said individual and expanded attributes; and comparing transaction records with a computer programmed for this purpose item-by-item to corresponding items in each said real-time part and long-term part, and thereby determine if each item represents fraud.
7 . The merchant data breach method of claim 6 , further comprising the steps of:
inspecting each newly arriving transaction record with a computer programmed for this purpose to see if the entity it represents has not yet been paired to a smart agent profile, and if not then generating and pairing a newly minted smart agent profile for it.
8 . The merchant data breach method of claim 7 , further comprising the steps of:
generating three populations of smart agent profiles with a computer programmed for this purpose by data mining of historical transaction data, wherein a corresponding number of cardholder, merchant, and identified device entities involved in each transaction are sorted and each are paired with a newly minted smart agent profile; comparing with a computer programmed for this purpose each attribute, attribute-by-attribute with a time interval series of attributes archived in the smart agent profiles paired with a particular cardholder, and with a particular merchant, and with a particular identified device, and each such comparison and contrast incrementally increases or decreases a computed overall fraud-risk-verdict.Join the waitlist — get patent alerts
Track US2015339673A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.