IP Library › Granted Patent US 11,843,617
Granted Patent B2
US 11,843,617 · App. 17/726,827 · Granted Dec 12, 2023

Fraud detection using graph databases

Inventors: Jonathan Shek Wing Lee (Kitchener, CA); Vidhyasagar Mahadevan Harihara (North York, CA); Michelle Indyarta (Scarborough, CA); Tian Zou (Surrey, CA); Steve Frensch (Kitchener, CA)
Assignee: Capital One Services, LLC
H04L63/1416G06F16/245G06F16/9024H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,843,617
App. No.
17/726,827
Granted
Dec 12, 2023
Kind
B2
Abstract

Aspects discussed herein relate to the storage of data in graph databases and detecting fraudulent behavior in the stored data. Fraud detection systems may use graph databases to store data, allowing for querying the graph database to obtain data using a variety of graph semantics such as nodes, edges, and properties. Graph databases in accordance with embodiments of the invention may include account nodes and attribute nodes, where nodes of the same type are not directly linked to each other. When a particular node is updated, an updated node may be created with a higher version number than the existing node. Each node may include an indication of the node being associated with fraudulent activity. Fraud indicators may be calculated based on the relationships between the nodes and fraud indicators for the nodes.

Claims (53)

1. A computer-implemented method for detecting fraud using a whitelist, the computer-implemented method comprising:

generating, by a computing device, the whitelist indicating one or more values to be filtered from a fraud detection database when calculating a fraud proximity score, wherein each of the one or more values are associated with an attribute node of the fraud detection database, and wherein the one or more values comprise one or more default values;

determining whether a fraud rate for the one or more values occurs at a frequency greater than a threshold fraud rate;

updating, based on the whitelist, an edge weight of each edge linking an account node to the attribute node;

obtaining account data comprising an account number;

determining a corresponding account node having an account number corresponding to the account number, the corresponding account node being stored in the fraud detection database;

calculating a fraud score for the corresponding account node, the fraud score being calculated based on the updated edge weight; and

setting, based on the fraud score, a suspicious account indicator for the corresponding account node such that the corresponding account node is indicated as a suspicious account.

2. The computer-implemented method of claim 1 , wherein generating the whitelist is based on a determination that a first value is associated with fraud at a rate less than a threshold fraud rate.

3. The computer-implemented method of claim 2 , wherein generating the whitelist is further based on a frequency with which the first value occurs within the one or more values.

4. The computer-implemented method of claim 1 , wherein the updating the edge weight of each edge linking the account node to the attribute node further comprises:

setting the edge weight of each edge linking the attribute node to the account node to zero.

5. The computer-implemented method of claim 1 , further comprising:

removing, from the whitelist, a set of values, of the one or more values, that occur at a frequency greater than the threshold fraud rate.

6. The computer-implemented method of claim 1 , wherein the one or more default values further comprise at least one of a default phone number, a default mailing address, a default social security number, or a default email address.

7. The computer-implemented method of claim 1 , further comprising:

determining one or more classes of the account data; and

normalizing the account data such that the account data in each of the one or more classes has a common format.

8. The computer-implemented method of claim 1 , wherein the account data comprises sensitive data comprising personally identifiable information, and the method further comprises:

encrypting the sensitive data using a hash function.

9. A non-transitory machine-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform steps comprising:

generating, by a computing device, a whitelist indicating one or more values to be filtered from a fraud detection database when calculating a fraud proximity score, wherein each of the one or more values are associated with an attribute node of the fraud detection database, and wherein the one or more values comprise one or more default values;

determining whether a fraud rate for the one or more values occurs at a frequency greater than a threshold fraud rate;

updating, based on the whitelist, an edge weight of each edge linking an account node to the attribute node;

obtaining account data comprising an account number;

determining a corresponding account node having an account number corresponding to the account number, the corresponding account node being stored in the fraud detection database;

calculating a fraud score for the corresponding account node, the fraud score being calculated based on the updated edge weight; and

setting, based on the fraud score, a suspicious account indicator for the corresponding account node such that the corresponding account node is indicated as a suspicious account.

10. The non-transitory machine-readable medium of claim 9 , wherein the instructions, when executed by one or more processors, further cause the one or more processors to perform steps comprising:

removing, from the whitelist, a set of values of the one or more values that occur at a frequency greater than the threshold fraud rate.

11. The non-transitory machine-readable medium of claim 9 , wherein the one or more default values further comprise at least one of a default phone number, a default mailing address, a default social security number, or a default email address.

12. The non-transitory machine-readable medium of claim 9 , wherein the instructions, when executed by one or more processors, further cause the one or more processors to perform steps comprising:

determining one or more classes of the account data; and

normalizing the account data such that the account data in each of the one or more classes has a common format.

13. The non-transitory machine-readable medium of claim 9 , wherein the account data comprises sensitive data comprising personally identifiable information, and wherein the instructions, when executed by one or more processors, further cause the one or more processors to perform steps comprising:

encrypting the sensitive data using a hash function.

14. The non-transitory machine-readable medium of claim 9 , wherein generating the whitelist is based on a determination that a first value is associated with fraud at a rate less than a threshold fraud rate.

15. A computing device, comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the computing device to:

generate a whitelist indicating one or more values to be filtered from a fraud detection database when calculating a fraud proximity score, wherein each of the one or more values are associated with an attribute node of the fraud detection database, and wherein the one or more values comprise one or more default values;

determine whether a fraud rate for the one or more values occurs at a frequency greater than a threshold fraud rate;

update, based on the whitelist, an edge weight of each edge linking an account node to the attribute node;

calculate a fraud score for the corresponding account node, the fraud score being calculated based on the updated edge weight; and

set, based on the fraud score, a suspicious account indicator for the corresponding account node such that the corresponding account node is indicated as a suspicious account.

16. The computing device of claim 15 , wherein the instructions, when executed by the one or more processors, further cause the computing device to:

remove, from the whitelist, set of values of the one or more values that occur at a frequency greater than the threshold fraud rate.

17. The computing device of claim 15 , wherein the one or more default values further comprise at least one of a default phone number, a default mailing address, a default social security number, or a default email address.

18. The computing device of claim 15 , wherein the instructions, when executed by the one or more processors, further cause the computing device to:

determine one or more classes of the account data; and

normalize the account data such that the account data in each of the one or more classes has a common format.

19. The computing device of claim 15 , wherein generating the whitelist is based on a determination that a first value is associated with fraud at a rate less than a threshold fraud rate.

20. The computing device of claim 19 , wherein generating the whitelist is further based on a frequency with which the first value occurs within the one or more values.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2023
From: LEE, JONATHAN SHEK WING; HARIHARA, VIDHYASAGAR MAHADEVAN; INDYARTA, MICHELLE; ZOU, TIAN; FRENSCH, STEVE
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 063387/0807 →
Continuity (3)
Continuation 16944932 · Jul 31, 2020
Continuation 16739519 · Jan 10, 2020
Related Publication 20220247765A1 · Aug 4, 2022
Cited By (2)
US 12,267,311 US 12,267,312