US2017221063A1PendingUtilityA1

Automated database analysis to detect malfeasance

Assignee: PALANTIR TECHNOLOGIES INCPriority: Dec 20, 2013Filed: Jan 23, 2017Published: Aug 3, 2017
Est. expiryDec 20, 2033(~7.4 yrs left)· nominal 20-yr term from priority
G06F 21/554G06Q 20/4016G06Q 40/12H04L 63/1425G06F 2221/2101G06Q 10/0635G06Q 20/4014G06Q 40/00G06Q 50/26
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In various embodiments, systems, methods, and techniques are disclosed for analyzing various entity data items including users, computing devices, and IP addresses, to detect malfeasance. The data and/or database items may be automatically analyzed to detect malfeasance, such as criminal activity to disguise the origins of illegal activities. Various money laundering indicators or rules may be applied to the entity data items to determine a likelihood that money laundering is occurring. Further, the system may determine one or more scores (and/or metascores) for each entity data item that may be indicative of a likelihood that it is involved in money laundering. Scores/metascores may be determined based on, for example, various money laundering scoring criteria and/or strategies. Account entities may be ranked based on their associated scores/metascores. Various embodiments may enable an analyst to discover various insights related to money laundering.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A method comprising:
 by a computer system comprising one or more computer hardware processors and one or more storage devices,   identifying, from a plurality of entity data items, a first entity data item that corresponds to at least one of:
 an entity from a predetermined list of entities that have been identified as being associated with potential money laundering activities, 
 an entity associated with a high-risk area for money laundering, or 
 an entity associated with a transaction indicative of a potential money laundering fee; 
   determining, from a plurality of Internet Protocol address data items, a first Internet Protocol address associated with the first entity data item, wherein a computing device associated with the first entity data item was assigned the first Internet Protocol address;   determining a first account that was accessed by the first Internet Protocol address, the first account different than the first entity data item;   designating the first account as a seed;   identifying one or more related data items associated with the seed;   generating a cluster based at least on the seed, wherein generating the cluster comprises:
 adding the seed to the cluster; and 
 adding the one or more related data items to the cluster; and 
   causing presentation, in a user interface, of at least some data from the cluster.   
     
     
         3 . The method of  claim 2 , further comprising:
 determining a number of occurrences where the first account was accessed by the first Internet Protocol address.   
     
     
         4 . The method of  claim 3 , wherein designating the first account as the seed further comprises determining that the number of occurrences where the first account was accessed by the first Internet Protocol address exceeds a threshold. 
     
     
         5 . The method of  claim 3 , wherein generating the cluster further comprises:
 adding corresponding one or more data items to the cluster for each occurrence where the first account was accessed by the first Internet Protocol address.   
     
     
         6 . The method of  claim 5 , further comprising:
 causing presentation, in the user interface, of the cluster as a visual graph comprising a representation of the seed as linked to the one or more related data items and linked to the corresponding one or more data items for each occurrence where the first account was accessed by the first Internet Protocol address.   
     
     
         7 . The method of  claim 5 , further comprising:
 accessing, from log data, a log record comprising a first account identifier for the first account and a computing device identifier; and   generating a device data item corresponding to the computer device identifier, wherein identifying the one or more related data items associated with the seed further comprises:
 determining that the device data item is related to the first account based at least in part on the log record comprising the first account identifier and the computing device identifier. 
   
     
     
         8 . A non-transitory computer storage medium storing computer executable instructions that when executed by a computer hardware processor perform operations comprising:
 identifying, from a plurality of entity data items, a first entity data item that corresponds to at least one of:
 an entity from a predetermined list of entities that have been identified as being associated with potential money laundering activities, 
 an entity associated with a high-risk area for money laundering, or 
 an entity associated with a transaction indicative of a potential money laundering fee; 
   determining a first Internet Protocol address associated with the first entity data item, wherein a computing device associated with the first entity data item was assigned the first Internet Protocol address;   determining a first account that was accessed by the first Internet Protocol address, the first account different than the first entity data item;   designating the first account as a seed;   identifying one or more related data items associated with the seed;   generating a cluster based at least on the seed, wherein generating the cluster comprises:
 adding the seed to the cluster; and 
 adding the one or more related data items to the cluster; and 
   causing presentation, in a user interface, of at least some data from the cluster.   
     
     
         9 . The non-transitory computer storage medium of  claim 8 , wherein the operations further comprise:
 determining a number of occurrences where the first account was accessed by the first Internet Protocol address.   
     
     
         10 . The non-transitory computer storage medium of  claim 9 , wherein designating the first account as the seed further comprises determining that the number of occurrences where the first account was accessed by the first Internet Protocol address exceeds a threshold. 
     
     
         11 . The non-transitory computer storage medium of  claim 9 , wherein generating the cluster further comprises:
 adding corresponding one or more data items to the cluster for each occurrence where the first account was accessed by the first Internet Protocol address.   
     
     
         12 . The non-transitory computer storage medium of  claim 11 , wherein the operations further comprise:
 causing presentation, in the user interface, of the cluster as a visual graph comprising a representation of the seed as linked to the corresponding one or more data items for each occurrence where the first account was accessed by the first Internet Protocol address.   
     
     
         13 . The non-transitory computer storage medium of  claim 8 , wherein the operations further comprise:
 accessing, from log data, a log record comprising a first account identifier for the first account and an additional identifier; and   generating an additional data item corresponding to the additional identifier, wherein identifying the one or more related data items associated with the seed further comprises:
 determining that the additional data item is related to the first account based at least in part on the log record comprising the first account identifier and the additional identifier. 
   
     
     
         14 . The non-transitory computer storage medium of  claim 8 , wherein the additional identifier corresponds to at least one of: a user identifier, a computing device identifier, a cookie identifier, a hash identifier. 
     
     
         15 . A system comprising:
 a non-transitory computer-readable storage medium configured to store:
 a plurality of entity data items; and 
 a plurality of Internet Protocol address data items; and 
   a computer hardware processor in communication with the non-transitory computer-readable storage medium that executes computer executable instructions to:
 identify, from the plurality of entity data items, a first entity data item that corresponds to at least one of:
 an entity from a predetermined list of entities that have been identified as being associated with potential money laundering activities, 
 an entity associated with a high-risk area for money laundering, or 
 an entity associated with a transaction indicative of a potential money laundering fee; 
 
 determine, from the plurality of Internet Protocol address data items, a first Internet Protocol address associated with the first entity data item, wherein a computing device associated with the first entity data item was assigned the first Internet Protocol address; 
 determine a first account that was accessed by the first Internet Protocol address, the first account different than the first entity data item; 
 designate the first account as a seed; 
 identify one or more related data items associated with the seed; and 
 generate a cluster based at least on the seed, wherein generating the cluster comprises:
 adding the seed to the cluster; and 
 adding the one or more related data items to the cluster. 
 
   
     
     
         16 . The system of  claim 15 , wherein the entity data item comprises at least one of: an account data item, a user data item, or an organization data item. 
     
     
         17 . The system of  claim 15 , wherein the computer hardware processor further executes the computer executable instructions to:
 determine a number of occurrences where the first account was accessed by the first Internet Protocol address.   
     
     
         18 . The system of  claim 17 , wherein designating the first account as the seed further comprises determining that the number of occurrences where the first account was accessed by the first Internet Protocol address exceeds a threshold. 
     
     
         19 . The system of  claim 17 , wherein generating the cluster further comprises:
 adding corresponding one or more data items to the cluster for each occurrence where the first account was accessed by the first Internet Protocol address.   
     
     
         20 . The system of  claim 19 , wherein the computer hardware processor further executes the computer executable instructions to:
 causing presentation, in a user interface, of the cluster as a visual graph comprising a representation of the seed as linked to the corresponding one or more data items for each occurrence where the first account was accessed by the first Internet Protocol address.   
     
     
         21 . The system of  claim 15 , wherein the computer hardware processor further executes the computer executable instructions to:
 access, from log data, a log record comprising a first account identifier for the first account and an additional identifier; and   generate an additional data item corresponding to the additional identifier, wherein identifying the one or more related data items associated with the seed further comprises:
 determine that the additional data item is related to the first account based at least in part on the log record comprising the first account identifier and the additional identifier.

Join the waitlist — get patent alerts

Track US2017221063A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.