{"id":1164,"date":"2014-12-22T15:58:06","date_gmt":"2014-12-22T10:13:06","guid":{"rendered":"https:\/\/www.subex.com\/blog\/?p=1164"},"modified":"2014-12-22T15:58:06","modified_gmt":"2014-12-22T10:13:06","slug":"intelligent-alarm-qualifier","status":"publish","type":"post","link":"https:\/\/dev.enki.studio\/test\/?p=1164","title":{"rendered":"Intelligent Alarm Qualification in a Fraud Management System"},"content":{"rendered":"<p>Most leading rule-based Fraud Management Systems are based on a relatively simple process\u2026. When an event (or series of events) occurs, the record associated with the event is processed in the FMS.\u00a0 If the event breaks a rule in the FMS &#8211; perhaps because it is unusual for the customer, unusually long duration, unusually expensive or is one of a very high number of calls &#8211; an alarm is fired and that alarm is sent to the alarm page so that the fraud analyst can see it in their workstack and hopefully take prompt action to deal with the case.<\/p>\n<p>The reality of course is that, in many instances, the alarm is competing with perhaps hundreds or thousands of other alarms for the attention of the analyst.\u00a0 So, which is the most important alarm in the stack? \u00a0Well, as we know, most FMS systems will have a scoring system so that the alarms with the highest score will appear at the top of the stack.<\/p>\n<p>Typically, when rules are built, they are given a score which reflects their \u201c<strong>potential<\/strong>\u201d severity, relative to other alarms.\u00a0 Weird and wonderful algorithms are then used in the background to build a consolidated score for an alarm based on a combination of these various scores for each rule breach, bearing in mind that alarms usually comprise a combination of several rule breaches.<\/p>\n<p>So a $50 call to an Adult entertainment line may have breached all of the following rules, each having a score associated with that breach:-<\/p>\n<ul>\n<li>High Value Call to a Premium Rate Service<\/li>\n<li>Long Duration Call to a Premium Rate Service<\/li>\n<li>High Value Call to ANY number<\/li>\n<li>Out of Hours Call<\/li>\n<\/ul>\n<p>On the face of it, this seems a sensible solution.\u00a0 However, there are three flaws with this methodology:-<\/p>\n<ol>\n<li>The scoring provided for a rule breach (alert) is arbitrarily\/subjectively assigned at the time the rule is written<\/li>\n<li>Once the score is associated with the rule, it is unlikely it will be changed until a thorough rules review is conducted, which could be months\/years later<\/li>\n<li>No consideration is given to the \u201cactual\u201d ruling that was subsequently assigned to the alarm.<\/li>\n<\/ol>\n<p>But what if the score could change dynamically based on the history of <strong>ACTUAL<\/strong> rulings made by analysts, rather than remaining static, based on the <strong>POTENTIAL<\/strong> severity of the situation.<\/p>\n<p>So, for example, if a particular set of rule breaches appear to be high risk but actually rarely result in a fraud, then surely over time, the score associated with that \u201cevent\u201d should reduce.\u00a0 Likewise, if a low score alarm always results in a fraud ruling, the score should automatically be enhanced the next time the system sees the same, or similar, behaviours.<\/p>\n<p>In other words, the system learns from experience over time.\u00a0 The more alarms that analysts rule correctly, the more accurately the score reflects the likelihood of that alarm being fraudulent or not.\u00a0 It won\u2019t reduce the number of false alarms, but it will ensure that the alarms most likely to be fraudulent will appear at the top of the list and be dealt with quicker than those that are known to be less risky\u2026. And that means losses due to fraud are reduced.<\/p>\n<p>Subex has been running this system for several years now.\u00a0 It is known as Intelligent Alarm Qualification (IAQ) and \u2013 wherever it is deployed \u2013 the results have been excellent.\u00a0 We have a benchmark which follows the Pareto Principle (the 80:20 Rule).\u00a0 This means that customers who let IAQ score the alarms should find 80% of their fraud in the top 20% of their alarm stack.\u00a0 The results in 95% of cases achieve this benchmark \u2013 and in the vast majority of cases, exceed it.<\/p>\n<p>Of course, it relies on the fact that analysts do rule alarms as FRAUD or NOT FRAUD regularly, and it also assumes that such rulings are usually correct.\u00a0 But as long as that is happening, as it is in most operations, then it is Happy Days!<\/p>\n<p>To get more information about IAQ or to find out more about Subex Fraud products please <a href=\"https:\/\/dev.enki.studio\/test\/roc-fraud-management\/\">click here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most leading rule-based Fraud Management Systems are based on a relatively simple process\u2026. When an event (or series of events) occurs, the record associated with the event is processed in the FMS.\u00a0 If the event breaks a rule in the FMS &#8211; perhaps because it is unusual for the customer, unusually long duration, unusually expensive [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":1165,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[28],"tags":[],"class_list":["post-1164","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fraud-management"],"acf":[],"_links":{"self":[{"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=\/wp\/v2\/posts\/1164","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1164"}],"version-history":[{"count":0,"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=\/wp\/v2\/posts\/1164\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=\/wp\/v2\/media\/1165"}],"wp:attachment":[{"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1164"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1164"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1164"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}