US2023351400A1PendingUtilityA1

Systems and methods for early detection of network fraud events

Assignee: MASTERCARD INTERNATIONAL INCPriority: Dec 28, 2018Filed: Jul 10, 2023Published: Nov 2, 2023
Est. expiryDec 28, 2038(~12.4 yrs left)· nominal 20-yr term from priority
G06N 3/0499G06N 3/09G06Q 20/4016G06Q 30/0185G06N 20/00G06N 20/20G06N 20/10G06N 3/08G06Q 20/34
76
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A computing system for detecting a pattern of fraudulent network events in a payment card network is configured to continuously receive a plurality of scored transaction authorization requests each including a respective account number and a respective fraud score. The computing system is also configured to sort the scored transaction authorization requests into account ranges based the account number, and sort the transaction authorization requests within each of the account ranges into a fraud score range stripes based on the corresponding fraud score. The computing system is further configured to calculate, for the scored transaction authorization requests within each fraud score range stripe, a ratio of a cumulative metric for a shorter time period over a longer time period, and detect, in near real-time, a fraud event associated with one of the account ranges based on the ratio for one of the fraud score range stripes within the account range.

Claims

exact text as granted — not AI-modified
1 . A computing system for detecting a pattern of fraudulent network events in a payment card network, said computing system comprising at least one processor programmed to:
 receive a plurality of scored transaction authorization requests each including a respective account number and a respective fraud score, wherein the respective fraud score is proportional to indicia of fraud present in an individual transaction corresponding to the respective scored transaction authorization request;   sort the scored transaction authorization requests into a plurality of account ranges, wherein each of the account ranges includes the scored transaction authorization requests having the account number within the corresponding account range;   sort the transaction authorization requests within each of the account ranges into a plurality of fraud score range stripes based on the corresponding fraud score;   calculate, for the scored transaction authorization requests within each fraud score range stripe within each account range, a ratio of i) a cumulative metric for a first time period to ii) the cumulative metric for a second time period; and   detect, in near real-time relative to the common starting point, a fraud event associated with one of the account ranges based on the ratio for one of the fraud score range stripes within the one of the account ranges.   
     
     
         2 . The computing system of  claim 1 , wherein the first time period and the second time period extend back from a common starting point, and wherein the at least one processor is further configured to set the common starting point to be one of a present time and a timestamp associated with the most recently received one of the scored transaction authorization requests. 
     
     
         3 . The computing system of  claim 1 , wherein the at least one processor is further configured to:
 provide the ratios for each fraud score range stripe within each account range as inputs to a downstream fraud detection model; and   execute the downstream fraud detection model.   
     
     
         4 . The computing system of  claim 3 , wherein the downstream fraud detection model is a machine learning model, and wherein the at least one processor is further configured to use the ratios to calculate feature inputs to the machine learning model. 
     
     
         5 . The computing system of  claim 1 , wherein the at least one processor is further configured to determine at least one of the plurality of account ranges based on a corresponding bank identification number (BIN). 
     
     
         6 . The computing system of  claim 1 , wherein the at least one processor is further configured to output a potential fraud attack alert associated with all account numbers within the one of the account ranges. 
     
     
         7 . The computing system of  claim 1 , wherein the cumulative metric is i) a tally of the scored transaction authorization requests within the respective time period, or ii) a cumulative total of transaction amounts within the respective time period. 
     
     
         8 . A computer-implemented method for detecting a pattern of fraudulent network events in a payment card network, said method implemented by a computing system including at least one processor, said method comprising, by the at least one processor:
 receiving a plurality of scored transaction authorization requests each including a respective account number and a respective fraud score, wherein the respective fraud score is proportional to indicia of fraud present in an individual transaction corresponding to the respective scored transaction authorization request;   sorting the scored transaction authorization requests into a plurality of account ranges, wherein each of the account ranges includes the scored transaction authorization requests having the account number within the corresponding account range;   sorting the transaction authorization requests within each of the account ranges into a plurality of fraud score range stripes based on the corresponding fraud score;   calculating, for the scored transaction authorization requests within each fraud score range stripe within each account range, a ratio of i) a cumulative metric for a first time period to ii) the cumulative metric for a second time period; and   detecting, in near real-time relative to the common starting point, a fraud event associated with one of the account ranges based on the ratio for one of the fraud score range stripes within the one of the account ranges.   
     
     
         9 . The computer-implemented method of  claim 8 , wherein the first time period and the second time period extend back from a common starting point, and further comprising setting, by the at least one processor, the common starting point to be one of a present time and a timestamp associated with the most recently received one of the scored transaction authorization requests. 
     
     
         10 . The computer-implemented method of  claim 8 , further comprising:
 providing, by the at least one processor, the ratios for each fraud score range stripe within each account range as inputs to a downstream fraud detection model; and   executing. by the at least one processor, the downstream fraud detection model.   
     
     
         11 . The computer-implemented method of  claim 10 , wherein the downstream fraud detection model is a machine learning model, said method further comprising using, by the at least one processor, the ratios to calculate feature inputs to the machine learning model. 
     
     
         12 . The computer-implemented method of  claim 8 , further comprising determining, by the at least one processor, at least one of the plurality of account ranges based on a corresponding bank identification number (BIN). 
     
     
         13 . The computer-implemented method of  claim 8 , further comprising outputting, by the at least one processor, a potential fraud attack alert associated with all account numbers within the one of the account ranges. 
     
     
         14 . The computer-implemented method of  claim 8 , wherein the cumulative metric is i) a tally of the scored transaction authorization requests within the respective time period, or ii) a cumulative total of transaction amounts within the respective time period. 
     
     
         15 . At least one non-transitory computer-readable storage media having computer-executable instructions embodied thereon wherein, when executed by at least one processor, the computer-executable instructions cause the at least one processor to:
 receive a plurality of scored transaction authorization requests each including a respective account number and a respective fraud score, wherein the respective fraud score is proportional to indicia of fraud present in an individual transaction corresponding to the respective scored transaction authorization request;   sort the scored transaction authorization requests into a plurality of account ranges, wherein each of the account ranges includes the scored transaction authorization requests having the account number within the corresponding account range;   sort the transaction authorization requests within each of the account ranges into a plurality of fraud score range stripes based on the corresponding fraud score;   calculate, for the scored transaction authorization requests within each fraud score range stripe within each account range, a ratio of i) a cumulative metric for a first time period to ii) the cumulative metric for a second time period; and   detect, in near real-time relative to the common starting point, a fraud event associated with one of the account ranges based on the ratio for one of the fraud score range stripes within the one of the account ranges.   
     
     
         16 . The at least one non-transitory computer-readable storage media of  claim 15 , wherein the first time period and the second time period extend back from a common starting point, and wherein the computer-executable instructions further cause the at least one processor to set the common starting point to be one of a present time and a timestamp associated with the most recently received one of the scored transaction authorization requests. 
     
     
         17 . The computing system of  claim 1 , wherein the at least one processor is further configured to:
 provide the ratios for each fraud score range stripe within each account range as inputs to a downstream fraud detection model; and   execute the downstream fraud detection model.   
     
     
         18 . The at least one non-transitory computer-readable storage media of  claim 17 , wherein the downstream fraud detection model is a machine learning model, and wherein the computer-executable instructions further cause the at least one processor to use the ratios to calculate feature inputs to the machine learning model. 
     
     
         19 . The computing system of  claim 1 , wherein the computer-executable instructions further cause the at least one processor to determine at least one of the plurality of account ranges based on a corresponding bank identification number (BIN). 
     
     
         20 . The computing system of  claim 1 , wherein the computer-executable instructions further cause the at least one processor to output a potential fraud attack alert associated with all account numbers within the one of the account ranges.

Join the waitlist — get patent alerts

Track US2023351400A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.