IP Library Granted Patent US 12,367,494
Granted Patent B2
US 12,367,494 · App. 18/519,877 · Granted Jul 22, 2025

Systems and methods for incorporating breach velocities into fraud scoring models

Inventors: Joshua A. Allbright (Valley Park, MO); Amudhan Venkatesan (Vancouver, CA); Felix Johannes Flory (Wildwood, MO); Christopher John Merz (Wildwood, MO)
Assignee: MASTERCARD INTERNATIONAL INCORPORATED
G06Q20/4016G06Q20/4093H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,367,494
App. No.
18/519,877
Granted
Jul 22, 2025
Kind
B2
Abstract

A method and system for detecting fraudulent network events in a payment card network by incorporating breach velocities into fraud scoring models are provided. A potential compromise event is detected, and payment cards that transacted at a compromised entity associated with the potential compromise event are identified. Subsequent transaction activity for the payment cards is reviewed, and a data structure for the payment cards are generated. The data structure sorts subsequent transaction activity into fraud score range stripes. The data structure is parsed over a plurality of time periods, and at least one cumulative metric is calculated for each of the time periods in each fraud score range stripe. A plurality of ratio striping values are determined, and a set of feature inputs is generated using the ratio striping values. The feature inputs are applied to a scoring model used to score future real-time transactions initiated using the payment cards.

Claims (37)

1. A computing system for detecting and preventing fraudulent network events, said computing system comprising a memory communicatively coupled to a processor, the memory having computer-executable instructions stored thereon that when executed by the processor implement:

a compromise detection and prevention (CDP) engine configured to:

in response to detecting a potential compromise event associated with a compromised entity, review, for a plurality of payment cards associated with the potential compromise event, subsequent transaction activity that occurred after the potential compromise event, the respective subsequent transaction activity for each payment card including one or more subsequent payment card transactions, each subsequent payment card transaction associated with a respective fraud score calculated using a fraud scoring model executing one or more machine learning algorithms;

generate a data structure that classifies each subsequent payment card transaction over a plurality of fraud score range stripes based on the respective fraud score;

determine, from the generated data structure, a plurality of ratio striping values;

detect a potential fraud wave associated with one or more of the plurality of payment cards based on the plurality of ratio striping values; and

transmit, to a fraud detection module, a set of feature inputs generated using the determined plurality of ratio striping values, the set of feature inputs indicative of the potential fraud wave, wherein transmitting the set of feature inputs to the fraud detection model causes the fraud detection model to i) apply the set of feature inputs to update the one or more machine learning algorithms executed by the fraud scoring model to generate an updated fraud scoring model, and ii) execute the updated fraud scoring model on a plurality of real-time payment card transactions by increasing, based on the updated one or more machine learning algorithms, the fraud score for any of the real-time payment card transactions associated with any one of the plurality of payment cards associated with the potential compromise event.

2. The computing system of claim 1 , wherein the CDP engine is further configured to generate a graphical user interface including a graph having an x-axis graduated in units of time and a y-axis graduated in units of fraud score, the graph showing the plurality of fraud score range stripes extending horizontally, each delineated by an upper fraud score threshold and a lower fraud score threshold, the graph showing vertically extending time period boundaries intersecting the x-axis, the graphical user interface displayable on a display screen of a user computer device.

3. The computing system of claim 1 , wherein the CDP engine is further configured to output a potential fraud wave alert in response to the detection of the potential fraud wave.

4. The computing system of claim 1 , wherein the CDP engine is configured to determine the ratio striping values based on a tally of each subsequent payment card transaction scored within each fraud score range stripe.

5. The computing system of claim 1 , wherein the CDP engine is configured to determine the ratio striping values based on a cumulative total of transaction amounts of subsequent payment card transactions scored within each fraud score range stripe.

6. The computing system of claim 1 , wherein the CDP engine is configured to determine the ratio striping values based on a count of declined subsequent payment card transactions scored within each fraud score range stripe.

7. The computing system of claim 1 , wherein the CDP engine is further configured to generate the set of feature inputs as being equal to the determined plurality of ratio striping values.

8. The computing system of claim 1 , wherein the CDP engine is further configured to:

detect the potential fraud wave by comparing one or more of the plurality of ratio striping values to a threshold ratio value indicating a likelihood of the potential fraud wave.

9. A computer-implemented method for detecting fraudulent network events, said method implemented using at least one computing device having at least one processor, said method comprising:

in response to detecting a potential compromise event associated with a compromised entity, reviewing, for a plurality of payment cards associated with the potential compromise event, subsequent transaction activity that occurred after the potential compromise event, the respective subsequent transaction activity for each payment card including one or more subsequent payment card transactions, each subsequent payment card transaction associated with a respective fraud score calculated using a fraud scoring model executing one or more machine learning algorithms;

generating a data structure that classifies each subsequent payment card transaction over a plurality of fraud score range stripes based on the respective fraud score;

determining, from the generated data structure, a plurality of ratio striping values;

detecting a potential fraud wave associated with one or more of the plurality of payment cards based on the plurality of ratio striping values; and

transmitting, to a fraud detection module, a set of feature inputs generated using the determined plurality of ratio striping values, the set of feature inputs indicative of the potential fraud wave, wherein transmitting the set of feature inputs to the fraud detection model causes the fraud detection model to i) apply the set of feature inputs to update the one or more machine learning algorithms executed by the fraud scoring model to generate an updated fraud scoring model, and ii) execute the updated fraud scoring model on a plurality of real-time payment card transactions by increasing, based on the updated one or more machine learning algorithms, the fraud score for any of the real-time payment card transactions associated with any one of the plurality of payment cards associated with the potential compromise event.

10. The computer-implemented method of claim 9 , further comprising generating a graphical user interface including a graph having an x-axis graduated in units of time and a y-axis graduated in units of fraud score, the graph showing the plurality of fraud score range stripes extending horizontally, each delineated by an upper fraud score threshold and a lower fraud score threshold, the graph showing vertically extending time period boundaries intersecting the x-axis, the graphical user interface displayable on a display screen of a user computer device.

11. The computer-implemented method of claim 9 , further comprising the steps of outputting a potential fraud attack alert in response to the detection of the potential fraud wave.

12. The computer-implemented method of claim 9 , wherein determining the ratio striping values comprises determining the ratio striping values based on at least one of i) a tally of each subsequent payment card transaction scored within each fraud score range stripe, ii) a cumulative total of transaction amounts of subsequent payment card transactions scored within each fraud score range stripe, and iii) a count of declined subsequent payment card transactions scored within each fraud score range stripe.

13. The computer-implemented method of claim 9 , wherein detecting the potential fraud wave further comprises:

comparing, by the at least one processor, one or more of the plurality of ratio striping values to a threshold ratio value indicating a likelihood of the potential fraud wave.

14. At least one non-transitory computer-readable storage media having computer-executable instructions embodied thereon wherein, when executed by at least one processor, the computer-executable instructions cause the at least one processor to:

in response to detecting a potential compromise event associated with a compromised entity, review, for a plurality of payment cards associated with the potential compromise event, subsequent transaction activity that occurred after the potential compromise event, the respective subsequent transaction activity for each payment card including one or more subsequent payment card transactions, each subsequent payment card transaction associated with a respective fraud score calculated using a fraud scoring model executing one or more machine learning algorithms;

generate a data structure that classifies each subsequent payment card transaction over a plurality of fraud score range stripes based on the respective fraud score;

determine, from the generated data structure, a plurality of ratio striping values;

detect a potential fraud wave associated with one or more of the plurality of payment cards based on the plurality of ratio striping values; and

transmit, to a fraud detection module, a set of feature inputs generated using the determined plurality of ratio striping values, the set of feature inputs indicative of the potential fraud wave, wherein transmitting the set of feature inputs to the fraud detection model causes the fraud detection model to i) apply the set of feature inputs to update the one or more machine learning algorithms executed by the fraud scoring model to generate an updated fraud scoring model, and ii) execute the updated fraud scoring model on a plurality of real-time payment card transactions by increasing, based on the updated one or more machine learning algorithms, the fraud score for any of the real-time payment card transactions associated with any one of the plurality of payment cards associated with the potential compromise event.

15. The computer-readable storage media of claim 14 , wherein the computer-executable instructions cause the processor to determine the plurality of ratio striping values based on a tally of each subsequent payment card transaction scored within each fraud score range stripe.

16. The computer-readable storage media of claim 14 , wherein the computer-executable instructions cause the processor to determine the plurality of ratio striping values based on a cumulative total of transaction amounts of subsequent payment card transactions scored within each fraud score range stripe.

17. The computer-readable storage media of claim 14 , wherein the computer-executable instructions cause the processor to determine the plurality of ratio striping values based on a count of declined subsequent payment card transactions scored within each fraud score range stripe.

18. The computer-readable storage media of claim 14 , wherein the computer-executable instructions further cause the processor to:

detect the potential fraud wave by comparing one or more of the plurality of ratio striping values to a threshold ratio value indicating a likelihood of the potential fraud wave.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2023
From: ALLBRIGHT, JOSHUA A.; VENKATESAN, AMUDHAN; FLORY, FELIX JOHANNES; MERZ, CHRISTOPHER JOHN
To: MASTERCARD INTERNATIONAL INCORPORATED
Reel/Frame 065678/0201 →
Continuity (3)
Continuation 18061813 · Dec 5, 2022
Continuation 16235529 · Dec 28, 2018
Related Publication 20240095745A1 · Mar 21, 2024
References Cited (148)
US 6254000B1 · Degen et al. · 2001 [cited by applicant]
US 6658393B1 · Basch et al. · 2003 [cited by applicant]
US 7580891B2 · Klebanoff · 2009 [cited by applicant]
US 7788195B1 · Subramanian et al. · 2010 [cited by applicant]
US 7814008B2 · Choudhuri et al. · 2010 [cited by applicant]
US 8266059B2 · Horvath et al. · 2012 [cited by applicant]
US 8423467B1 · Johansson et al. · 2013 [cited by applicant]
US 8489476B1 · Lester et al. · 2013 [cited by applicant]
US 8600872B1 · Yan · 2013 [cited by applicant]
US 8606700B2 · Carlson et al. · 2013 [cited by applicant]
US 8612340B1 · Yan · 2013 [cited by applicant]
US 8620801B2 · Choudhuri et al. · 2013 [cited by applicant]
US 8694429B1 · Ballaro et al. · 2014 [cited by applicant]
US 8706641B2 · Bruesewitz et al. · 2014 [cited by applicant]
US 8744941B2 · Chisholm · 2014 [cited by applicant]
US 8744958B2 · Carlson et al. · 2014 [cited by applicant]
US 9230280B1 · Maag et al. · 2016 [cited by applicant]
US 9256780B1 · DeBattista · 2016 [cited by applicant]
US 9256810B2 · Wu et al. · 2016 [cited by applicant]
US 9256870B1 · Howe · 2016 [cited by applicant]
US 9331994B2 · Grigg et al. · 2016 [cited by applicant]
US 9392008B1 · Michel et al. · 2016 [cited by applicant]
US 9412108B2 · Wang et al. · 2016 [cited by applicant]
US 9477960B2 · Grigg et al. · 2016 [cited by applicant]
US 9483766B2 · Grigg et al. · 2016 [cited by applicant]
US 9547864B2 · Howe · 2017 [cited by applicant]
US 9601000B1 · Gruss et al. · 2017 [cited by applicant]
US 9619801B2 · Sikljovan et al. · 2017 [cited by applicant]
US 9661012B2 · Michel et al. · 2017 [cited by applicant]
US 9721080B2 · Moran et al. · 2017 [cited by applicant]
US 9898741B2 · Siegel et al. · 2018 [cited by applicant]
US 10308033B2 · Sato et al. · 2019 [cited by applicant]
US 10339606B2 · Gupta et al. · 2019 [cited by applicant]
US 10380333B1 · Moran et al. · 2019 [cited by applicant]
US 10395243B1 · Johansson et al. · 2019 [cited by applicant]
US 10586235B2 · Wang et al. · 2020 [cited by applicant]
US 10778681B1 · Douglas et al. · 2020 [cited by applicant]
US 10867303B1 · Manapat et al. · 2020 [cited by applicant]
US 10937030B2 · Allbright et al. · 2021 [cited by applicant]
US 11151569B2 · Allbright et al. · 2021 [cited by applicant]
US 11157913B2 · Allbright et al. · 2021 [cited by applicant]
US 11366884B2 · Liu et al. · 2022 [cited by applicant]
US 20020099649A1 · Lee et al. · 2002 [cited by applicant]
US 20030217094A1 · Andrews et al. · 2003 [cited by applicant]
US 20040034604A1 · Klebanoff · 2004 [cited by applicant]
US 20040162773A1 · Del Rey et al. · 2004 [cited by applicant]
US 20050055373A1 · Forman · 2005 [cited by applicant]
US 20070094067A1 · Kumar et al. · 2007 [cited by applicant]
US 20070185782A1 · Shooks et al. · 2007 [cited by applicant]
US 20070203732A1 · Griegel et al. · 2007 [cited by applicant]
US 20090132347A1 · Anderson et al. · 2009 [cited by applicant]
US 20090132404A1 · King et al. · 2009 [cited by applicant]
US 20090276269A1 · Yee et al. · 2009 [cited by applicant]
US 20090307049A1 · Elliott, Jr. et al. · 2009 [cited by applicant]
US 20100228580A1 · Zoldi et al. · 2010 [cited by applicant]
US 20100280882A1 · Faith et al. · 2010 [cited by applicant]
US 20110055074A1 · Chen et al. · 2011 [cited by applicant]
US 20110078034A1 · Hayhow · 2011 [cited by applicant]
US 20110238510A1 · Rowen et al. · 2011 [cited by applicant]
US 20120084207A1 · Horvath et al. · 2012 [cited by applicant]
US 20120239557A1 · Weinflash et al. · 2012 [cited by applicant]
US 20120296824A1 · Rosano · 2012 [cited by applicant]
US 20130036036A1 · Zoldi · 2013 [cited by applicant]
US 20130159077A1 · Stringfellow et al. · 2013 [cited by applicant]
US 20130231976A1 · Tavares et al. · 2013 [cited by applicant]
US 20130297473A1 · Wolfe · 2013 [cited by applicant]
US 20140032409A1 · Rosano · 2014 [cited by applicant]
US 20140249934A1 · Subramanian et al. · 2014 [cited by applicant]
US 20140258099A1 · Rosano · 2014 [cited by applicant]
US 20140279185A1 · Merz et al. · 2014 [cited by applicant]
US 20140279331A1 · Gimby et al. · 2014 [cited by applicant]
US 20140324522A1 · Wilkins et al. · 2014 [cited by applicant]
US 20140337215A1 · Howe · 2014 [cited by applicant]
US 20150012430A1 · Chisholm et al. · 2015 [cited by applicant]
US 20150046338A1 · Laxminarayanan et al. · 2015 [cited by applicant]
US 20150073981A1 · Adjaoute · 2015 [cited by applicant]
US 20150127547A1 · Powell et al. · 2015 [cited by applicant]
US 20150220999A1 · Thornton et al. · 2015 [cited by applicant]
US 20150339667A1 · Dua · 2015 [cited by applicant]
US 20150339673A1 · Adjaoute · 2015 [cited by applicant]
US 20150348023A1 · Fisher et al. · 2015 [cited by applicant]
US 20150371207A1 · Cummins et al. · 2015 [cited by applicant]
US 20160125317A1 · Benjamin · 2016 [cited by applicant]
US 20160125405A1 · Alterman et al. · 2016 [cited by applicant]
US 20160140561A1 · Cowan · 2016 [cited by applicant]
US 20160155124A1 · Howe · 2016 [cited by applicant]
US 20160162759A1 · Yun et al. · 2016 [cited by applicant]
US 20160171498A1 · Wang et al. · 2016 [cited by applicant]
US 20160180333A1 · Leyva · 2016 [cited by applicant]
US 20160196615A1 · Yen et al. · 2016 [cited by applicant]
US 20160217470A1 · Gerard et al. · 2016 [cited by applicant]
US 20160321634A1 · George et al. · 2016 [cited by applicant]
US 20160335641A1 · White et al. · 2016 [cited by applicant]
US 20160352766A1 · Flacher et al. · 2016 [cited by applicant]
US 20160364727A1 · DeLawter et al. · 2016 [cited by applicant]
US 20160364728A1 · DeLawter et al. · 2016 [cited by applicant]
US 20170053294A1 · Yang et al. · 2017 [cited by applicant]
US 20170116585A1 · Rosano · 2017 [cited by applicant]
US 20170140262A1 · Wilson et al. · 2017 [cited by applicant]
US 20170169500A1 · Merz et al. · 2017 [cited by applicant]
US 20170193515A1 · Sharan et al. · 2017 [cited by applicant]
US 20170293906A1 · Komarov · 2017 [cited by applicant]
US 20170352026A1 · Musil et al. · 2017 [cited by applicant]
US 20180018670A1 · Ju et al. · 2018 [cited by applicant]
US 20180047024A1 · Niehaus · 2018 [cited by applicant]
US 20180053188A1 · Zoldi et al. · 2018 [cited by applicant]
US 20180114203A1 · Senci et al. · 2018 [cited by applicant]
US 20180182029A1 · Vinay · 2018 [cited by applicant]
US 20180218369A1 · Xiao et al. · 2018 [cited by applicant]
US 20190066109A1 · Jia et al. · 2019 [cited by applicant]
US 20190073647A1 · Zoldi et al. · 2019 [cited by applicant]
US 20190130403A1 · Merz et al. · 2019 [cited by applicant]
US 20190220864A1 · Avegliano et al. · 2019 [cited by applicant]
US 20190220865A1 · Weber · 2019 [cited by applicant]
US 20190279309A1 · Gupta et al. · 2019 [cited by applicant]
US 20190385170A1 · Arrabothu et al. · 2019 [cited by applicant]
US 20200211022A1 · Allbright et al. · 2020 [cited by applicant]
US 20200311285A1 · Jochems et al. · 2020 [cited by applicant]
US 20210084065A1 · Irimie et al. · 2021 [cited by applicant]
US 20210304207A1 · Lo Faro et al. · 2021 [cited by applicant]
US 20210357940A1 · Abdelkader · 2021 [cited by applicant]
US 20220012742A1 · Kielak et al. · 2022 [cited by applicant]
US 20220108331A1 · Thomson et al. · 2022 [cited by applicant]
US 20230316285A1 · Kramme et al. · 2023 [cited by applicant]
CN 1348566A · 2002 [cited by applicant]
CN 105913243A · 2016 [cited by applicant]
EP 2420966A1 · 2012 [cited by applicant]
WO 2001077959A1 · 2001 [cited by applicant]
WO 2002025495A1 · 2002 [cited by applicant]
WO 2004070293A1 · 2004 [cited by applicant]
WO 2009067346A2 · 2009 [cited by applicant]
WO 2011025689A1 · 2011 [cited by applicant]
WO 2011077959A1 · 2011 [cited by applicant]
WO 2012135115A2 · 2012 [cited by applicant]
WO 2017031039A1 · 2017 [cited by applicant]
“Technology Briefs”, Publication Info: Card News; Potomac vol. 14, Iss. 4, March (Year: 1999). [cited by applicant]
Abhimanyu Roy et al., “Deep Learning Detecting Fraud in Credit Card Transactions,” 2018 Systems and Information Engineering Design Symposium (SIEDS), Charlottesville, VA, USA, 2018, pp. 129-134 (Year: 2018). [cited by applicant]
Baboo et al. “Analysis of Spending Pattern on Credit Card Fraud Detection,” IOSR Journal of Computer Engineering, Mar.-Apr. 2017 (Year: 2017). [cited by applicant]
Ghosh et al., “Credit card fraud detection with a neural network,” 1994 Proceedings of the Twenty-Seventh Hawaii International Conference on System Sciences, Wailea, HI, USA, 1994, pp. 621-630, doi: 10.1109/HICSS.1994.3… [cited by applicant]
J.T.S. Quah et al., Real Time Credit Card Fraud Detection using Computational Intelligence, 2007 International Joint Conference on Neural Networks, Orlando, FL, USA, 2007, pp. 863-868, doi: 10.1109/IJCNN.2007.4371071. [cited by applicant]
PCT International Search Report and Written Opinion, Application No. PCT/US2018/031980, dated Jul. 26, 2018, 11 pps. [cited by applicant]
PCT International Search Report and Written Opinion, Application No. PCT/US2018/052143, dated Dec. 7, 2018, 12 pps. [cited by applicant]
PCT International Search Report and Written Opinion, Application No. PCT/US2018/052145, dated Feb. 12, 2019, 12 pps. [cited by applicant]
PCT International Search Report and Written Opinion, Application No. PCT/US2018/059326, dated Mar. 7, 2019, 11 pps. [cited by applicant]
Sanchez-Aguayo et al., “Fraud Detection Using the Fraud Triangle Theory and Data Mining Techniques: A literature review”, Computers 10, 10:121, MDPI AG., (Year: 2021). [cited by applicant]
Sudjianto et al., “Statistical Methods for Fighting Financial Crimes”, Technometrics 52:1:5-19, American Society for Quality, Feb. 2010. [cited by applicant]
T. K. Behera and S. Panigrahi, “Credit Card Fraud Detection: A Hybrid Approach Using Fuzzy Clustering Neural Network,” 2015 Second International Conference on Advances in Computing and Communication Engineering, Dehradu… [cited by applicant]
Wikipedia, “Collaborative Filtering,” https://web.archive.org (Year: 2017). [cited by applicant]