US20220108331A1

Systems and methods for detection of and response to account range fraud attacks

Claim Score by NHIP

Read claim 15, the broadest

Abstract

Computing systems and methods for detecting account range fraud attacks in a payment card network are described herein. An attack detection and response (ADR) computing device detects a fraud attack in which a set of primary account numbers (PANs) that share a common bank identification number (BIN) are subject to potential fraud, retrieves transaction records associated with transactions initiated during the fraud attack, and, for each transaction, determines an issuer response that indicates whether the transaction was authorized or declined. The ADR computing device also extracts, for each authorized transaction, the PAN from the transaction record, identifies a respective issuer of the payment card associated with each extracted PAN, and transmits a fraud attack alert to each identified issuer, the fraud attack alert identifying the fraud attack, a time period associated therewith, and the PANs associated with the authorized transactions, causing the issuer to record the PANs as compromised.

US20220108331A1, drawing sheet 1
Sheet 1 of 6

Term

Projected expiry 7 October 2040.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

16 claims: 3 independent, 13 dependent

  1. 1
    A computing system for detecting account range fraud attacks on a payment card network, said computing system comprising an attack detection and response (ADR) computing device comprising at least one processor in communication with a database of transaction records, the transaction records associated with transactions processed by a plurality of issuers via a payment processing network, each of the transaction records including a primary account number (PAN) and an issuer response code indicating whether the transaction was authorized or declined by a respective issuer of the plurality of issuers, the at least one processor configured to:receive, via the payment processing network, a real-time stream of electronic messages generated in response to transactions initiated at a plurality of online merchant portals, each of the electronic messages including the PAN tendered at the online merchant portal, wherein a bank identification number (BIN) portion of each PAN identifies the respective issuer associated with the PAN;apply a detection model to the real-time stream of electronic messages, wherein the detection model is programmed to apply at least one machine learning algorithm trained to detect, within the real-time stream, that a velocity of the transactions for a range of PANs having a common value in the BIN portion exceeds a threshold;in response to detecting that the velocity of the transactions for the range of PANs having the common value in the BIN portion exceeds the threshold, identify a time period associated with an account range fraud attack on the range of PANs;query the database of transaction records to retrieve a plurality of transaction records associated with a respective plurality of transactions initiated during the time period associated with the fraud attack and for which the PAN has the common value in the BIN portion;extract the PAN from each of the retrieved plurality of transaction records for which the issuer response code indicates authorized;identify a respective issuer of the payment card associated with each extracted PAN based on the common value in the BIN portion;andfor each subsequent real-time electronic message that includes the PAN matching the extracted PAN from one of the retrieved plurality of transaction records for which the issuer response code indicates authorized, automatically initiate, via the payment processing network, an enhanced authentication procedure prior to transmitting the subsequent real-time electronic message to the respective issuer of the payment card associated with the PAN.
  2. 9
    A computer-implemented method for detecting account range fraud attacks on a payment card network, the method implemented using an attack detection and response (ADR) computing device comprising at least one processor in communication with a database of transaction records, the transaction records associated with transactions processed by a plurality of issuers via a payment processing network, each of the transaction records including a primary account number (PAN) and an issuer response code indicating whether the transaction was authorized or declined by a respective issuer of the plurality of issuers, including a memory and a processor, the method comprising:receiving, via the payment processing network, a real-time stream of electronic messages generated in response to transactions initiated at a plurality of online merchant portals, each of the electronic messages including the PAN tendered at the online merchant portal, wherein a bank identification number (BIN) portion of each PAN identifies the respective issuer associated with the PAN;applying a detection model to the real-time stream of electronic messages, wherein the detection model is programmed to apply at least one machine learning algorithm trained to detect, within the real-time stream, that a velocity of the transactions for a range of PANs having a common value in the BIN portion exceeds a threshold;in response to detecting that the velocity of the transactions for the range of PANs having the common value in the BIN portion exceeds the threshold, identify a time period associated with an account range fraud attack on the range of PANs;querying the database of transaction records to retrieve a plurality of transaction records associated with a respective plurality of transactions initiated during the time period associated with the fraud attack and for which the PAN has the common value in the BIN portion;extracting the PAN from each of the retrieved plurality of transaction records for which the issuer response code indicates authorized;identifying a respective issuer of the payment card associated with each extracted PAN based on the common value in the BIN portion;andfor each subsequent real-time electronic message that includes the PAN matching the extracted PAN from one of the retrieved plurality of transaction records for which the issuer response code indicates authorized, automatically initiate, via the payment processing network, an enhanced authentication procedure prior to transmitting the subsequent real-time electronic message to the respective issuer of the payment card associated with the PAN.
  3. 15
    Broadest claimClaim Score 18, narrow(NHIP)A non-transitory computer-readable storage medium including computer-executable instructions stored thereon, wherein when executed by an attack detection and response (ADR) computing device comprising at least one processor in communication with a database of transaction records, the transaction records associated with transactions processed by a plurality of issuers via a payment processing network, each of the transaction records including a primary account number (PAN) and an issuer response code indicating whether the transaction was authorized or declined by a respective issuer of the plurality of issuers, including a processor and a memory, the computer-executable instructions cause the processor to:receive, via the payment processing network, a real-time stream of electronic messages generated in response to transactions initiated at a plurality of online merchant portals, each of the electronic messages including the PAN tendered at the online merchant portal, wherein a bank identification number (BIN) portion of each PAN identifies the respective issuer associated with the PAN;apply a detection model to the real-time stream of electronic messages, wherein the detection model is programmed to apply at least one machine learning algorithm trained to detect, within the real-time stream, that a velocity of the transactions for a range of PANs having a common value in the BIN portion exceeds a threshold;in response to detecting that the velocity of the transactions for the range of PANs having the common value in the BIN portion exceeds the threshold, identify a time period associated with an account range fraud attack on the range of PANs;query the database of transaction records to retrieve a plurality of transaction records associated with a respective plurality of transactions initiated during the time period associated with the fraud attack and for which the PAN has the common value in the BIN portion;extract the PAN from each of the retrieved plurality of transaction records for which the issuer response code indicates authorized;identify a respective issuer of the payment card associated with each extracted PAN based on the common value in the BIN portion;andfor each subsequent real-time electronic message that includes the PAN matching the extracted PAN from one of the retrieved plurality of transaction records for which the issuer response code indicates authorized, automatically initiate, via the payment processing network, an enhanced authentication procedure prior to transmitting the subsequent real-time electronic message to the respective issuer of the payment card associated with the PAN.