COMPOSITE EVENT SIGNATURE ANALYSIS
In one example, this disclosure describes a method that includes determining a first transaction category identifier based on data for a first financial transaction initiated by a customer. A demographic category identifier is determined based on a set of demographic data associated with the customer. A first composite event signature is established for the customer by combining the transaction category identifier with the demographic category identifier. The customer is assigned to a first profile group of customers having the first composite event signature. A first risk associated with the first profile group is determined, based on zero or more historical fraud events associated with the first profile group. When the first risk exceeds a first threshold, a first fraud report is generated, a first fraud alert is generated, and/or a first mitigation action is performed to mitigate the first risk.
1 . A method comprising:
determining a first transaction category identifier based on data for a first financial transaction initiated by a customer;
determining a demographic category identifier based on a set of demographic data associated with the customer;
establishing a first composite event signature for the customer by combining the transaction category identifier with the demographic category identifier;
assigning the customer to a first profile group of customers having the first composite event signature;
determining a first risk associated with the first profile group, based on zero or more historical fraud events associated with the first profile group; and
when the first risk exceeds a first threshold, at least one of generating a first fraud report, generating a first fraud alert, or performing a first mitigation action to mitigate the first risk.
2 . The method of claim 1 , further comprising:
determining a second transaction category identifier based on data for a second financial transaction initiated by the customer;
establishing a second composite event signature for the customer by combining the second transaction category identifier with the demographic category identifier;
assigning the customer to a second profile group of customers having the second composite event signature;
determining a second risk associated with the second profile group, based on zero or more historical fraud events associated with the second profile group; and
when the second risk exceeds the first risk by at least a second threshold, at least one of generating a second fraud report, generating a second fraud alert, or performing the mitigation action to mitigate the second risk.
3 . The method of claim 1 , further comprising sending the first fraud alert to one or more of: a mobile device associated with the customer or a computing device associated with a financial institution.
4 . The method of claim 1 , wherein the first fraud report comprises at least one of a textual report, a graphical report, or a displayed report forwarded to one or more of: a mobile device associated with the customer or a computing device associated with a financial institution.
5 . The method of claim 1 , wherein the first mitigation action comprises one or more of: not completing the first financial transaction, reversing the first financial transaction, or providing a message, to a mobile device associated with the customer, asking the customer to confirm the transaction.
6 . The method of claim 1 , wherein the second financial transaction occurs after the first financial transaction.
7 . The method of claim 1 , further comprising determining the transaction category identifier by determining a channel used to perform the transaction.
8 . The method of claim 7 , wherein the channel comprises one or more of an online portal, a store, a phone, or an automated teller machine (ATM).
9 . The method of claim 1 , further comprising determining a false positive probability for the first risk.
10 . A system comprising: a memory and one or more processors in communication with the memory, t, the one or more processors configured to:
determine a first transaction category identifier based on data for a first financial transaction initiated by a customer;
determine a demographic category identifier based on a set of demographic data associated with the customer;
establish a first composite event signature for the customer by combining the transaction category identifier with the demographic category identifier;
assign the customer to a first profile group of customers having the first composite event signature;
determine a first risk associated with the first profile group, based on zero or more historical fraud events associated with the first profile group; and
when the first risk exceeds a first threshold, at least one of generate a first fraud report, generate a first fraud alert, or perform a first mitigation action to mitigate the first risk.
11 . The system of claim 10 , wherein the one or more processors are further configured to:
determine a second transaction category identifier based on data for a second financial transaction initiated by the customer;
combine the second transaction category identifier with the demographic category identifier to establish a second composite event signature for the customer;
assign the customer to a second profile group of customers having the second composite event signature;
determine a second risk associated with the second profile group, based on zero or more historical fraud events associated with the second profile group; and
when the second risk exceeds the first risk by at least a second threshold, at least one of generate a second fraud report, generate a second fraud alert, or perform the mitigation action to mitigate the second risk.
12 . The system of claim 10 , further comprising an interface to a network; wherein the one or more processors are further configured to send the first fraud alert over the network to one or more of: a mobile device associated with the customer or a computing device associated with a financial institution.
13 . The system of claim 10 , wherein the first fraud report comprises at least one of a textual report or a displayed report forwarded to one or more of: a mobile device associated with the customer or a computing device associated with a financial institution.
14 . The system of claim 10 , wherein the first mitigation action comprises one or more of: not completing the first financial transaction, reversing the first financial transaction, or providing a message, to a mobile device associated with the customer, asking the customer to confirm the transaction.
15 . The system of claim 10 , wherein the one or more processors are further configured to determine the transaction category identifier based on a channel used to perform the transaction.
16 . The system of claim 15 , wherein the channel comprises one or more of an online portal, a store, a phone, or an automated teller machine (ATM).
17 . The system of claim 10 , wherein the one or more processors are further configured to determine a false positive probability for the first risk.
18 . A non-transitory computer-readable media having computer-executable instructions embodied therein that, when executed by one or more processors of a computing system, cause the computing system to perform operations comprising:
determining a first transaction category identifier based on data for a first financial transaction initiated by a customer;
determining a demographic category identifier based on a set of demographic data associated with the customer;
establishing a first composite event signature for the customer by combining the transaction category identifier with the demographic category identifier;
assigning the customer to a first profile group of customers having the first composite event signature;
determining a first risk associated with the first profile group, based on zero or more historical fraud events associated with the first profile group; and
when the first risk exceeds a first threshold, at least one of generating a first fraud report, generating a first fraud alert, or performing a first mitigation action to mitigate the first risk.
19 . The non-transitory computer-readable medium of claim 18 , further comprising instructions for:
determining a second transaction category identifier based on data for a second financial transaction initiated by the customer;
establishing a second composite event signature for the customer by combining the second transaction category identifier with the demographic category identifier;
assigning the customer to a second profile group of customers having the second composite event signature;
determining a second risk associated with the second profile group, based on zero or more historical fraud events associated with the second profile group; and
when the second risk exceeds the first risk by at least a second threshold, at least one of generating a second fraud report, generating a second fraud alert, or performing the mitigation action to mitigate the second risk.
20 . The non-transitory computer-readable medium of claim 18 , further comprising instructions for sending the first fraud alert to one or more of: a mobile device associated with the customer or a computing device associated with a financial institution.