Techniques for handling card testing attacks
Embodiments may include receiving a request including transaction data to evaluate a transaction as part of a charge path that processes at least a portion of the transaction; processing, by a set of blocking machine learning models, a portion of the transaction data to generate a set of blocking scores for the transaction; retrieving, from a memory, a set of card testing attack (CTA) scores associated with the transaction, the set of CTA scores indicative of an occurrence of a card testing attack, and the set of CTA scores retrieved based on the transaction data; adjusting a set of default blocking score thresholds based on the set of CTA scores to generate a set of adjusted blocking score thresholds; and determining to allow the transaction based on comparison of the set of blocking scores with the set of adjusted blocking score thresholds.
1 . A computer-implemented method for handling card testing attacks, the method comprising:
receiving, by a server system, a request to evaluate an event as part of a path that processes at least a portion of the event, wherein the request includes event data associated with the event comprising an identifier of a second server system that generated the event;
invoking a set of blocking machine learning (ML) models to process a portion of the event data and to generate a set of blocking scores for the event;
detecting a cache hit for a set of card testing attack (CTA) scores generated asynchronously to the path and associated with the identifier of the second server system, the set of CTA scores being generated by a plurality of ML models operating in parallel; and
subsequent to detecting the cache hit, reconfiguring the server system to selectively block the event by:
retrieving, from a memory, the set of CTA scores based on the event data;
determining whether to adjust a set of default blocking score thresholds based on whether the set of CTA scores is indicative of an occurrence of a card testing attack at the second server system; and
in accordance with a determination to adjust the set of default blocking score thresholds,
generating a set of lowered blocking score thresholds by lowering the set of default blocking score thresholds for a threshold amount of time;
blocking the event in response to determining that at least one blocking score of the set of blocking scores exceeds a blocking score threshold from the set of lowered blocking score thresholds; and
resetting the set of default blocking score thresholds after the threshold amount of time.
2 . The computer-implemented method of claim 1 , wherein the set of CTA scores is generated by a set of CTA ML models outside of the path that processes at least the portion of the event.
3 . The computer-implemented method of claim 1 , wherein the set of blocking scores for the event is generated by the set of blocking ML models as part of the path that processes at least the portion of the event.
4 . The computer-implemented method of claim 1 , wherein the event comprises a current event and the set of CTA scores is generated by a set of CTA ML models based on data associated with a previous event.
5 . The computer-implemented method of claim 4 , wherein the current event and the previous event are associated with a common identifier.
6 . The computer-implemented method of claim 1 , wherein each CTA score in the set of CTA scores is generated by a different CTA model that is trained to detect a different attack pattern indicative of CTAs.
7 . The computer-implemented method of claim 1 , wherein the set of CTA scores include a first set of CTA scores, and the method further comprises:
receiving, by the server system, further event data associated with the event;
processing, by a set of CTA ML models of the server system, a feature set produced based on the further event data to generate a second set of CTA scores; and
storing the second set of CTA scores in the memory.
8 . The computer-implemented method of claim 7 , wherein the second set of CTA scores are generated and stored in the memory in response to a determination that the first set of CTA scores are older than a further threshold amount of time.
9 . A non-transitory computer readable storage medium including instructions that, when executed by a processor, cause the processor to perform operations for handling card testing attacks, the operations comprising:
receiving, by a server system, a request to evaluate an event as part of a path that processes at least a portion of the event, wherein the request includes event data associated with the event comprising an identifier of a second server system that generated the event;
invoking a set of blocking machine learning (ML) models, to process a portion of the event data and to generate a set of blocking scores for the event;
detecting a cache hit for a set of card testing attack (CTA) scores generated asynchronously to the path and associated with the identifier of the second server system, the set of CTA scores being generated by a plurality of ML models operating in parallel; and
subsequent to detecting the cache hit, reconfiguring the server system to selectively block the event by:
retrieving, from a memory, the set of CTA scores based on the event data;
determining whether to adjust a set of default blocking score thresholds based on whether the set of CTA scores is indicative of an occurrence of a card testing attack at the second server system; and
in accordance with a determination to adjust the set of default blocking score thresholds,
generating a set of lowered blocking score thresholds by lowering the set of default blocking score thresholds for a threshold amount of time;
blocking the event in response to determining that at least one blocking score of the set of blocking scores exceeds a blocking score threshold from the set of lowered blocking score thresholds; and
resetting the set of default blocking score thresholds after the threshold amount of time.
10 . The non-transitory computer readable storage medium of claim 9 , wherein the set of CTA scores is generated by a set of CTA ML models outside of the path that processes at least the portion of the event.
11 . The non-transitory computer readable storage medium of claim 9 , wherein the set of blocking scores for the event is generated by the set of blocking ML models as part of the path that processes at least the portion of the event.
12 . The non-transitory computer readable storage medium of claim 9 , wherein the event comprises a current event and the set of CTA scores is generated by a set of CTA ML models based on data associated with a previous event.
13 . The non-transitory computer readable storage medium of claim 9 , wherein the set of CTA scores include a first set of CTA scores, and the operations further comprise:
receiving, by the server system, further event data associated with the event;
processing, by a set of CTA ML models of the server system, a feature set produced based on the further event data to generate a second set of CTA scores; and
storing the second set of CTA scores in the memory.
14 . A server computer system for handling card testing attacks, comprising:
a memory; and
a processor coupled to the memory configured to:
receive a request to evaluate an event as part of a path that processes at least a portion of the event, wherein the request includes event data associated with the event comprising an identifier of a second server system that generated the event;
invoke a set of blocking machine learning (ML) models of the server computer system to process a portion of the event data and to generate a set of blocking scores for the event;
detect a cache hit for a set of card testing attack (CTA) scores generated asynchronously to the path and associated with the identifier of the second server system, the set of CTA scores being generated by a plurality of ML models operating in parallel; and
subsequent to detecting the cache hit, reconfigure the server computer system to selectively block the event by:
retrieving, from a memory, the set of CTA scores based on the event data;
determining whether to adjust a set of default blocking score thresholds based on whether the set of CTA scores is indicative of an occurrence of a card testing attack at the second server system; and
in accordance with a determination to adjust the set of default blocking score thresholds,
generating a set of lowered blocking score thresholds by lowering the set of default blocking score thresholds for a threshold amount of time to generate a set of lowered blocking score thresholds,
blocking the event in response to determining that at least one blocking score of the set of blocking scores exceeds a blocking score threshold from the set of lowered blocking score thresholds; and
resetting the set of default blocking score thresholds after the threshold amount of time.
15 . The server computer system of claim 14 , wherein the set of CTA scores is generated by a set of CTA ML models outside of the path that processes at least the portion of the event.
16 . The server computer system of claim 14 , wherein the set of blocking scores for the event is generated by the set of blocking ML models as part of the path that processes at least the portion of the event.
17 . The server computer system of claim 14 , wherein the event comprises a current event and the set of CTA scores is generated by a set of CTA ML models based on data associated with a previous event.
18 . The server computer system of claim 14 , wherein each CTA score in the set of CTA scores is generated by a different CTA model that is trained to detect a different attack pattern indicative of CTAs.
19 . The server computer system of claim 14 , wherein the set of CTA scores include a first set of CTA scores, and the processor coupled to the memory is further configured to:
receive further event data associated with the event;
process, by a set of CTA ML models, a feature set produced based on the further event data to generate a second set of CTA scores; and
store the second set of CTA scores in the memory.