EP3553713A1

Modeling users for fraud detection and analysis

Abstract

Systems and methods are provided for predicting expected behavior of a user in an account. The systems and methods automatically generate a causal model corresponding to a user. The systems and methods estimate a plurality of components of the causal model using event parameters of a first set of events undertaken by the user in an account of the user. The systems and methods predict expected behavior of the user during a second set of events using the causal model.

EP3553713A1, drawing sheet 1
Sheet 1 of 156

Term

Projected expiry 12 June 2029.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

13 claims: 4 independent, 9 dependent

  1. 1
    A processor-implemented method for online event based fraud detection, by executing at least one application, the application configured for:receiving event parameters of a first set of events comprising at least an online event, and optionally one or more offline events or multiple channel events undertaken by the user in an account of the user, wherein the received event parameters of the first set of events comprises one or both of Internet Protocol (IP) parameters and Hypertext Transfer Protocol (HTTP) parameters corresponding to the online event undertaken by the user, the IP parameters including one or more of an IP address, IP address country, IP address city, IP network block, and internet service provider corresponding to the online event, and the HTTP parameters including one or more of data of an operating system, a user agent string, a referrer string, and internet browser of a computer used for the online event undertaken by the user;automatically generating a first causal model corresponding to a user, wherein generating the first causal model comprises: generating individual probability distributions for each of the received event parameters corresponding to at least the first set of events, wherein each probability distribution of an IP parameter or an HTTP parameter is a determined statistical distribution for the parameter over the first set of events;and combining the generated individual probability distributions into a joint probability distribution of the received event parameters across the first set of events;receiving event parameters of a second set of events corresponding to an online event or session event related to one or more entities other than the user, wherein the received event parameters of the second set of events comprises one or both of IP parameters and HTTP parameters corresponding to the online event or session event, the IP parameters including one or more of an IP address, IP address country, IP address city, IP network block, and internet service provider corresponding to the online event or session event related to the one or more entities other than the user, and the HTTP parameters including one or more of data of an operating system, a user agent string, a referrer string, and internet browser of a computer used for the online event or session event related to the one or more entities other than the user;automatically generating a second causal model representative of fraudsters, wherein generating the second causal model comprises generating a probability distribution of the received event parameters corresponding to the second set of events: using the first causal model to output a prediction of expected behaviour of the user during a next set of events comprising at least one of a session login event or a session termination event or a session activity event, said prediction of expected behaviour of the user comprising predicted event parameters corresponding to the expected behaviour of the user during the next set of events and wherein predicting the expected event parameters of said next set of events includes generating a first set of predicted probability distributions that represents expected event parameters corresponding to said next set of events assuming that the user is conducting the next set of events;using the second causal model to output a prediction of expected behaviour of a fraudster during a next set of events initiated by an entity other than the user and comprising at least one of a session login event or a session termination event or a session activity event, said prediction of expected behaviour of a fraudster comprising predicted event parameters corresponding to the expected behaviour of such entity other than the user during said next set of events and wherein predicting the expected event parameters of said next set of events includes generating a second set of predicted probability distributions that represents expected event parameters corresponding to the next set of events assuming that such entity other than the user is conducting the next set of events;comparing a third set of event parameters comprising actual event parameters collected during a third set of events, against the first set of predicted probability distributions corresponding to the expected behaviour of the user and identifying a predicted probability of occurrence of the third set of events assuming the user conducted the third set of events, wherein the third set of event parameters comprises one or both of IP parameters and HTTP parameters corresponding to the third set of events, the IP parameters including one or more of an IP address, IP address country, IP address city, IP network block, and internet service provider corresponding to the online event, and the HTTP parameters including one or more of data of an operating system, a user agent string, a referrer string, and internet browser of a computer used for the online event undertaken by the user;comparing the third set of event parameters, against the second set of predicted probability distributions corresponding to the expected behaviour of an entity other than the user and identifying a predicted probability of occurrence of the third set of events assuming such entity other than the user conducted the third set of events;identifying fraudulent activity associated with the account of the user, wherein the identification of fraudulent activity comprises the step of generating a risk score based on the predicted probability of occurrence of the third set of events assuming the user conducted the third set of events, and on the predicted probability of occurrence of the third set of events assuming an entity other than the user conducted the third set of events;and automatically updating at least one of the first causal model and the second causal model using the third set of event parameters, wherein automatically updating the first causal causal model or the second causal model includes updating at least one of a plurality of probability distribution functions that represent the event parameters based on which the first causal model or the second causal model have been generated, wherein the updating comprises modifying the at least one of the plurality of probability distribution functions based on the third set of event parameters.
  2. 11
    A system for online event based fraud detection, the system comprising at least one processor implemented server configured for implementing the steps of:receiving event parameters of a first set of events comprising at least an online event, and optionally one or more offline event or multiple channel event, undertaken by the user in an account of the user, wherein the received event parameters of the first set of events comprises one or both of Internet Protocol (IP) parameters and Hypertext Transfer Protocol (HTTP) parameters corresponding to the online event undertaken by the user, the IP parameters including one or more of an IP address, IP address country, IP address city, IP network block, and internet service provider corresponding to the online event, and the HTTP parameters including one or more of data of an operating system, a user agent string, a referrer string, and internet browser of a computer used for the online event undertaken by the user;automatically generating a first causal model corresponding to a user, wherein generating the first causal model comprises: generating individual probability distributions for each of the received event parameters corresponding to at least the first set of events, wherein each probability distribution of an IP parameter or an HTTP parameter is a determined statistical distribution for the parameter over the first set of events;and combining the generated individual probability distributions into a joint probability distribution of the received event parameters across the first set of events;receiving event parameters of a second set of events corresponding to an online event or session event related to one or more entities other than the user, wherein the received event parameters of the second set of events comprises one or both of IP parameters and HTTP parameters corresponding to the online event or session event, the IP parameters including one or more of an IP address, IP address country, IP address city, IP network block, and internet service provider corresponding to the online event or session event related to the one or more entities other than the user, and the HTTP parameters including one or more of data of an operating system, a user agent string, a referrer string, and internet browser of a computer used for the online event or session event related to the one or more entities other than the user;automatically generating a second causal model representative of fraudsters, wherein generating the second causal model comprises generating a probability distribution of the received event parameters corresponding to the second set of events: using the first causal model to output a prediction of expected behaviour of the user during a next set of events comprising at least one of a session login event or a session termination event or a session activity event, said prediction of expected behaviour of the user comprising predicted event parameters corresponding to the expected behaviour of the user during the next set of events and wherein predicting the expected event parameters of said next set of events includes generating a first set of predicted probability distributions that represents expected event parameters corresponding to said next set of events assuming that the user is conducting the next set of events;using the second causal model to output a prediction of expected behaviour of a fraudster during a next set of events initiated by an entity other than the user and comprising at least one of a session login event or a session termination event or a session activity event, said prediction of expected behaviour of a fraudster comprising predicted event parameters corresponding to the expected behaviour of such entity other than the user during said next set of events and wherein predicting the expected event parameters of said next set of events includes generating a second set of predicted probability distributions that represents expected event parameters corresponding to the next set of events assuming that such entity other than the user is conducting the next set of events;comparing a third set of event parameters comprising actual event parameters collected during a third set of events, against the first set of predicted probability distributions corresponding to the expected behaviour of the user and identifying a predicted probability of occurrence of the third set of events assuming the user conducted the third set of events, wherein the third set of event parameters comprises one or both of IP parameters and HTTP parameters corresponding to the third set of events, the IP parameters including one or more of an IP address, IP address country, IP address city, IP network block, and internet service provider corresponding to the online event, and the HTTP parameters including one or more of data of an operating system, a user agent string, a referrer string, and internet browser of a computer used for the online event undertaken by the user;comparing the third set of event parameters, against the second set of predicted probability distributions corresponding to the expected behaviour of an entity other than the user and identifying a predicted probability of occurrence of the third set of events assuming such entity other than the user conducted the third set of events;identifying fraudulent activity associated with the account of the user, wherein the identification of fraudulent activity comprises the step of generating a risk score based on the predicted probability of occurrence of the third set of events assuming the user conducted the third set of events, and on the predicted probability of occurrence of the third set of events assuming an entity other than the user conducted the third set of events;and automatically updating at least one of the first causal model and the second causal model using the third set of event parameters, wherein automatically updating the first causal causal model or the second causal model includes updating at least one of a plurality of probability distribution functions that represent the event parameters based on which the first causal model or the second causal model have been generated, wherein the updating comprises modifying the at least one of the plurality of probability distribution functions based on the third set of event parameters.
  3. 12
    A method comprising:automatically generating a causal model corresponding to a user;estimating a plurality of components of the causal model using event parameters of a first set of events undertaken by the user in an account of the user;and predicting expected behaviour of the user during a second set of events using the causal model.
  4. 13
    A system comprising a processor executing at least one application, the application:receiving event parameters of a first set of events undertaken by the user in an account of the user, the application automatically generating a causal model corresponding to a user by estimating a plurality of components of the causal model using the event parameters of the first set of events, the application using the causal model to output a prediction of expected behaviour of the user during a second set of events.