IP Library Granted Patent US 8,413,234
Granted Patent B1
US 8,413,234 · App. 12/775,579 · Granted Apr 2, 2013

Communications-service fraud detection using special social connection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,413,234
App. No.
12/775,579
Granted
Apr 2, 2013
Kind
B1
Abstract

A method, system, and medium are provided for detecting fraud, the method comprising: initializing a fraud hypothesis variable associated with a communications device, receiving data that describes a plurality of outgoing communication records that are associated with said communications device, wherein the data is related to activity that took place over a given period of time, extracting a plurality of destination identifiers from said plurality of communication records, for each of at least a portion of said plurality of destination identifiers, modifying said fraud hypothesis variable based on a fraud metric associated with said destination identifier, comparing said fraud hypothesis variable to a first predetermined threshold, and when said fraud hypothesis variable exceeds said first predetermined threshold, generating a fraud indication that is related to said communications device.

Claims (70)

1. One or more nontransitory computer-readable media having computer-executable instructions embodied thereon that, when executed, perform a method of detecting fraud, the method comprising:

initializing a fraud hypothesis variable associated with a communications device;

receiving data that describes a plurality of outgoing communication records that are associated with said communications device, wherein the data is related to activity that took place over a given period of time;

extracting a plurality of destination identifiers from said plurality of communication records;

for each destination identifier of a portion of said plurality of destination identifiers, obtaining a fraud metric associated with the destination identifier, wherein the fraud metric is based at least in part on an amount of fraudulent communications associated with the destination identifier;

for each destination identifier of the portion of said plurality of destination identifiers, modifying said fraud hypothesis variable associated with the communications device based on the fraud metric associated with said destination identifier;

comparing said fraud hypothesis variable to a first predetermined threshold; and

when said fraud hypothesis variable exceeds said first predetermined threshold, generating a fraud indication that is related to said communications device.

2. The media of claim 1 , wherein the fraud hypothesis variable is initialized such that no fraud indication is generated for a communications device with no associated communications records.

3. The media of claim 1 , wherein the portion of the plurality of destination identifiers consists of those destination identifiers associated with one or more specified area codes.

4. The media of claim 1 , wherein the portion of the plurality of destination identifiers consists of those destination identifiers associated with one or more specified international country codes.

5. The media of claim 1 , wherein modifying said fraud hypothesis variable comprises adding said fraud metric to said fraud hypothesis variable.

6. The media of claim 5 , wherein the fraud metric is constrained to have an absolute value less than or equal to one-half.

7. The media of claim 1 , wherein the first predetermined threshold is at least three.

8. The media of claim 1 , the method further comprising:

comparing said fraud hypothesis variable to a second predetermined threshold, wherein said second predetermined threshold is greater than said first predetermined threshold;

when said fraud hypothesis variable exceeds said second predetermined threshold, causing the communications device to be classified as a fraudulent source when calculating a destination fraud metric.

9. The media of claim 8 , the method further comprising:

when said fraud hypothesis variable is greater than said first predetermined threshold but less than said second predetermined threshold, causing said fraud indication to be verified by other means; and

when said other means confirm the fraud indication, causing the communications device to be classified as a fraudulent source when calculating a destination fraud metric.

10. The media of claim 1 , the method further comprising

receiving feedback regarding the fraud indication and updating one of

(A) a false positive counter; and

(B) a true positive counter;

based on said feedback;

calculating a precision value associated with the first predetermined threshold;

comparing said precision value to a target precision range;

when said precision value is below said target precision range, increasing said first predetermined threshold; and

when said precision value is above said target precision range, decreasing said predetermined threshold.

11. The media of claim 10 , wherein the target precision range is 0.8-0.9.

12. One or more nontransitory computer-readable media having computer-executable instructions embodied thereon that, when executed, perform a method of detecting fraud, the method comprising:

receiving data that describes a plurality of communication records that are associated with a destination identifier, wherein the destination identifier is associated with a communication device, and wherein the data is related to activity that took place over a given period of time;

extracting a plurality of source identifiers from said plurality of communication records, wherein each source identifier identifies a source of a communication received by the communication device;

for each of said source identifiers, determining whether said source identifier is classified as fraudulent or nonfraudulent;

based on a number of fraudulent source identifiers and a number of nonfraudulent source identifiers, calculating a fraud metric associated with the destination identifier.

13. The media of claim 12 , wherein calculating the fraud metric comprises:

dividing a count of communication records associated with fraudulent source identifiers by a count of all communication records to obtain a result; and

applying a transformation to map the result onto a desired interval.

14. The media of claim 12 , wherein calculating the fraud metric comprises:

dividing a count of distinct fraudulent source identifiers associated with said communication records by a count of all distinct source identifiers associated with said communication records to obtain a result; and

applying a transformation to map the result onto a desired interval.

15. A system for detecting fraud, comprising:

a device classification component that performs a method comprising:

(A) receiving a first data set that describes a plurality of communication outgoing records that are associated with a communications device, wherein the data is related to activity that took place over a first period of time;

(B) extracting a plurality of destination identifiers from said plurality of outgoing communication records;

(C) initializing a fraud hypothesis variable associated with said communications device;

(D) for each destination identifier of a portion of said plurality of destination identifiers, obtaining from a destination classification component a fraud metric associated with the destination identifier, wherein the fraud metric is based at least in part on an amount of fraudulent communications associated with the destination identifier;

(E) for each destination identifier of the portion of said plurality of destination identifiers, modifying said fraud hypothesis variable associated with said communications device based on the fraud metric associated with said destination identifier; and

(F) comparing said fraud hypothesis variable to a first predetermined threshold;

(G) when said fraud hypothesis variable exceeds said first predetermined threshold, generating a fraud indication that is related to said communications device; and

(H) passing said fraud indication to a confirmation component;

the destination classification component that performs a method comprising:

(A) receiving a second data set that describes a plurality of communication records that are associated with a potentially fraudulent destination identifier, wherein the data set is related to activity that took place over a second period of time;

(B) extracting a plurality of source identifiers from said plurality of communication records;

(C) for each source identifier of said plurality of source identifiers, determining whether said source identifier has been classified as fraudulent or non-fraudulent by the device classification component and confirmed as fraudulent by the confirmation component;

(D) based on a number of source identifiers that have been classified as fraudulent and a number of source identifiers that have been classified as non-fraudulent, calculating a fraud metric associated with the destination identifier; and

(E) passing the fraud metric to the device classification component upon request; and

a confirmation component that performs a method comprising:

(A) receiving fraud indications from the device classification component;

(B) for each fraud indication so received, determining whether said fraud indication requires corroboration;

(C) if said fraud indication requires corroboration, performing additional analysis to classify a device associated with the fraud indication as fraudulent or non-fraudulent;

(D) if said fraud indication does not require corroboration, classifying the device associated with the fraud indication as fraudulent;

(E) passing a result of said classifying to the destination classification component upon request.

16. The system of claim 15 , wherein the first period of time is shorter than the second period of time.

17. The system of claim 15 , wherein the portion of the destination identifiers for which fraud metrics are received by the device classification component from the destination classification component consists of those destination identifiers associated with one or more specified area codes.

18. The system of claim 15 , wherein the portion of the destination identifiers for which fraud metrics are received by the device classification component from the destination classification component consists of those destination identifiers associated with one or more specified international country codes.

19. The system of claim 15 , wherein:

the portion of the destination identifiers for which fraud metrics are received by the device classification component from the destination classification component consists of those destination identifiers that have a prefix that is included in a list of prefixes associated with fraudulent activity; and

said list of prefixes associated with fraudulent activity is updated based at least in part on one or more destination identifiers associated with communications devices that are classified as fraudulent by the device classification component.

20. The system of claim 15 , wherein the confirmation component performing additional analysis comprises passing data related to said communication device to a human for review and receiving a classification as fraudulent or non-fraudulent in reply.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT INTERNATIONAL INCORPORATED; IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2021
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 055604/0001 →
TERMINATION AND RELEASE OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2020
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 052969/0475 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
GRANT OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 6, 2017
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 041895/0210 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2010
From: ZANG, HUI; DAWSON, TRAVIS E.
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 024350/0848 →