Monday, September 16, 2019
African Americans and Medicine: from Slavery to Modern Times
African Americans and Medicine: From Slavery to Modern Times Imagine being sick, but never going to a doctor because you knew they would do bad things to you, make you sicker, or even kill you. When we see doctors, we are trusting them to make the best decisions to help us. However, there was a time when doctors committed the most heinous acts against those who needed them. African Americanââ¬â¢s have been used for unethical studies and cases since the time of slavery.Some were used against their will, while others were taken advantage of by the people who were supposed to take care of them. The earlier cases of this inhumane treatment were scarcely documented, but through tales and word of mouth were passed from generation to generation. African Americans never forgot what happened to their ancestors or what could still possibly happen to them and as a result lead to the mentality that they should stay away from hospitals and doctors, furthermore creating a culture of fear surrou nding institutional medicine.Unfair treatment of African Americans started during the time of slavery. In Slavery and Medicine: Enslavement and Medical Practices in Antebellum Louisiana, author Katherine Bankole describes the mentality of whites and white slave owners which dictated the treatment of slaves medically. Bankole says, ââ¬Å"The three main areas of enslavement and medicine in the antebellum period are: theory, management, and experimentationâ⬠(Bankole 8), doctors theorized that the biology of Africans was innately inferior to that of the white race.The second area, management, involved ââ¬Å"general health, disease, diet/nutrition, clothing, mortality, and the medical costs incurred by slaveowners. â⬠(Bankole 8) Medical management was the most important factor that determined the success of a slave owners land. The healthier a slave was, the more he could work and produce a profit for the slave owner. This meant health care was provided at a lower cost to t hose who owned slaves. Through this management came the development of medical and scientific journals as well as pamphlets and almanacs.The last area discussed was experimentation. Records show documented cases of surgeries and experimental treatment and procedures. The cases show how doctors built their careers using slaves as their subjects. Slaves were used in painful surgeries against their will. Consent only needed to be given by the slave owner. A slave could receive treatment if the slave owner found it cost effective to the value of the slave. Bankole also notes, ââ¬Å"Often slave owners equate the care they provided to enslaved Africans to the care provided to horses or other farm/plantation animalsâ⬠(Bankole 28).Although it is not completely certain how slaves felt about their medical treatment, due to the fact no documentation was taken from them on this subject, through stories and folklore there is an indication that ââ¬Å"some Africans expressed a significant f ear of doctors and hospitalsâ⬠(Bankole 20) . The legends indicate stories of Night Doctors, who were said to have paid slaves to dig up newly buried bodies. African Americans played the largest role in medical advancements.In The Use of Blacks for Medical Experimentation and Demonstration in the Old South, Todd Savitt explains how ââ¬Å"southern white medical educators and researchers relied greatly on the availability of Negro patients for various purposes. Black bodies often found their way to dissecting tables, operating amphitheatres, classroom or beside demonstrations, and experimental facilities. â⬠(Savitt 331). Though poor whites as well as European immigrants were plentiful in the northern cities of the south, blacks were easier targets because they were a voiceless people in a racially divided society.During this time bodies were greatly needed for teaching purposes. ââ¬Å"Students had to learn anatomy, recognize and diagnose diseases, and treat conditions req uiring surgery; researchers had to try out their ideas and new techniques; and practitioners had to perform autopsies to confirm their diagnoses to understand the effects of diseases on the human body. â⬠(Savitt 332). When the French school of hospital medicine reached America in the early 19th century, the need for human specimens became more necessary, so medical schools wanted to meet these demands for their studentââ¬â¢s education.Colleges opened clinics as well as infirmaries to further assist students. Since most patients did not want to participate in studies, these institutions became reliant on poor and enslaved citizens. Savitt goes on to say, ââ¬Å"Neither whites nor blacks held hospitals in high esteem during the antebellum period. Not only did patients object to having medical students and doctors touching and poking them and discussing their illnesses and the merits or problems of particular modes of treatment in their presence, but they also feared that expe riments might be performed on them and that they would be permitted to so autopsies could be undertaken. (Savitt 336). References of night doctors are again seen here where Savitt notes, ââ¬Å"Black fear of medical schools and dissection inevitably carried over into the postbellum period, when whites, as a mean of maintaining control over freedmen, reinforced the idea of ââ¬Ënight doctorsââ¬â¢ who stole, killed, and then dissected blacksâ⬠(Savitt 340). My final thought from Savitt comes from Southern medical schools boasting about their large supplies of blacks for study material. Even after their schooling, white physicians maintained the idea of the usefulness of African Americans.African Americans continued to be used for new techniques or treatments, and doctors did not fear consequences as long as death or permanent injury did not result. ââ¬Å"Blacks, therefore, did have reason for fearing misuse at the hands of southern white physicians. â⬠(Savitt 341). Mu ch advancement was made in medicine as a result of experimentation. Certain doctors received their fame off the unethical treatments of slaves and African American patients. Dr. J. Marion Sims was an American surgeon who became credited with developing the area of gynecology, and has even been called, ââ¬Å"The Father of Gynecology. Sims used enslaved women to try to discover a cure for the disease vesico-vaginal fistula. During Sims time, the practice of gynecology did not exist and obstetrics as well as child delivery were taught with dummies. Because enslaved women were poor, and lacked proper nutrition as well as prenatal care, they were at higher risk for developing VVF. After Sims graduated he became interested in surgery and began conducting experiments on enslaved women which resulted in the perfection of a certain surgical technique to repair the fistula.This was not Sims initial objective, but after looking after a patient one day who had fallen from a horse and had pain her pelvic area he discovered a way to better see inside the vagina which made him feel more confident in his ability to perform surgery on women with VVF. Sims used 7 enslaved women as his subjects so their consent was not necessary. His first patient was a woman named Lucy, and Sims was so sure he had discovered the proper technique for surgery he invited local doctors to come watch the surgery. Lucy had to stay in a position where she was on her knees and elbows with everyone watching, and she was not given anesthetics.Lucy was in horrible pain during and after the surgery and nearly lost her life from a blood infection she developed as a result of Simsââ¬â¢ experimentation. It took Sims four years to finally perfect his surgery and cure women of this disease. His first success was on a woman named Anarcha who had already received thirteen operations, all without the use of anesthetics. White women began coming to Sims after they heard of his success, but none of them could en dure the pain of surgery. Among the list of unethical experiments done to African Americans, one of the most famous was the Tuskegee Study.Syphilis was a huge concern during the 1930ââ¬â¢s in America, but not much was known at the time of the effects of advanced syphilis. The study was conducted by investigators from the United States Public Health Service on 400 African American men from Macon County, Alabama. The study was meant to last from six months to a year, but the investigators knew that the most important information would come only after the men were dead. In Experimentation on Human Beings, Susan Lederer describes the men used for the study: ââ¬Å"The men recruited into this study were impoverished individuals; many had never seen a doctor in their entire livesâ⬠(Lederer 21).The investigators would deceive the men by offering free treatment and perform spinal punctures collecting fluid, telling them this was a treatment for the condition. The investigators want ed to make sure the men would go on not receiving treatment so they would keep them from being enlisted in military service, during World War II, because once in the military they would receive mandatory syphilis treatment. The Center for Disease control held a meeting in 1969 to discuss whether the study should continue or not. Only one professor protested the study saying the men should be receiving treatment.It was only three years later when reports of the study flooded through American media, and Americans were shocked and disgusted in the governments treatment of these vulnerable subjects that the study was closed in 1972. In light of the study as well as other unethical studies at that time, Congress adopted the National Research Act in 1974. This act required that the people must give a written consent before partaking in studies. Given the history of medical experimentation of African Americans, one is left to wonder if it has had an effect on the modern day perspective of the African American and medicine.A study conducted in 2006 by doctors, Elizabeth Jacobs, Italia Rolle, Carol Estwing Ferrans, Eric Whitaker, and Richard Warnecke, to see what trust or distrust of physicians means to African Americans. They found that the African Americans they tested had more trust based on the ââ¬Å"interpersonal and technical competence of physicians. â⬠While distrust stemmed from ââ¬Å"lack of interpersonal and technical competence, perceived quest for profit and expectations of racism and experimentation during routine provision of health care. If patients felt their physician was untrustworthy they would either keep information to themselves or lie about their medical history, change doctors, or even refuse to seek medical care. Multiple studies have shown that African Americans are more likely to distrust physicians than Caucasian Americans. One of the female patients in the study was quoted saying, ââ¬Å"Over my period of time dealing with the medic al field, I know that you do need a hell of a lot of trust in the physicians or the medical field and the institutions. The patient goes on to say, ââ¬Å"But I don't know how most people are, but it reminds me of the Tuskegee Institute where they messed around and they made the brothers have the disease instead of treating them they just wanted to see how it was going to affect them. So maybe sometimes you go instead of getting treated they just want to see what itââ¬â¢s going to do to you and they'll try this and try that and they may give you a sugar pill. Because itââ¬â¢s not like they haven't seen anyone dead before so the only time they get affected [by dead people] is when itââ¬â¢s personal. So that's why a lot of people have mistrust. (Jacobs et al) Although there have been great medical discoveries made over the last two centuries in American medicine, the cost of these discoveries has been paid by the lives of individuals who were or deceived into partaking in the se experiments. As a result, centuries later, there is still concern as to whether or not physicians are to be trusted to ethically perform their duties on patients. We owe so much of what has been established in the field of medicine to the slaves in America. Their pain and suffering paved the road to medical advancements, and their sacrifices need to be recognized as well as praised.
Sunday, September 15, 2019
Real-Time Fraud Detection: How Stream Computing Can Help the Retail Banking Industry
Para os meus pais, porque ââ¬Å"o valor das coisas nao esta no tempo que elas duram, mas na intensidade com que acontecem. Por isso existem momentos inesqueciveis, coisas inexplicaveis e pessoas incomparaveisâ⬠como voces! Obrigado por tudo, Filipe Abstract The Retail Banking Industry has been severely affected by fraud over the past few years. Indeed, despite all the research and systems available, fraudsters have been able to outsmart and deceive the banks and their customers. With this in mind, we intend to introduce a novel and multi-purpose technology known as Stream Computing, as the basis for a Fraud Detection solution.Indeed, we believe that this architecture will stimulate research, and more importantly organizations, to invest in Analytics and Statistical Fraud-Scoring to be used in conjunction with the already in-place preventive techniques. Therefore, in this research we explore different strategies to build a Streambased Fraud Detection solution, using advanced Dat a Mining Algorithms and Statistical Analysis, and show how they lead to increased accuracy in the detection of fraud by at least 78% in our reference dataset. We also discuss how a combination of these strategies can be embedded in a Stream-based application to detect fraud in real-time.From this perspective, our experiments lead to an average processing time of 111,702ms per transaction, while strategies to further improve the performance are discussed. Keywords: Fraud Detection, Stream Computing, Real-Time Analysis, Fraud, Data Mining, Retail Banking Industry, Data Preprocessing, Data Classi? cation, Behavior-based Models, Supervised Analysis, Semi-supervised Analysis Sammanfattning Privatbankerna har drabbats hart av bedragerier de senaste aren. Bedragare har lyckats kringga forskning och tillgangliga system och lura bankerna och deras kunder.Darfor vill vi infora en ny, polyvalent strommande datorteknik (Stream Computing) for att upptacka bedragerier. Vi tror att denna struktur kommer att stimulera forskningen, och framfor allt fa organisationerna att investera i analytisk och statistisk bedragerisparning som kan anvandas tillsammans med be? ntlig forebyggande teknik. Vi undersoker i var forskning olika strategier for att skapa en strommande losning som utnyttjar avancerade algoritmer for datautvinning och statistisk analys for att upptacka bedragerier, och visar att dessa okar traffsakerheten for att upptacka bedragerier med minst 78% i var referensbas.Vi diskuterar aven hur en kombination av dessa strategier kan baddas in i en strommande applikation for att upptacka bedragerier i realtid. Vara forsok ger en genomsnittlig bearbetningstid pa 111,702ms per transaktion, samtidigt som olika strategier for att fortsatta forbattra resultaten diskuteras. Acknowledgments ââ¬Å"Silent gratitude isnââ¬â¢t much use to anyoneâ⬠Gladys Bronwyn Stern When I wrote the ? rst words in this report I think I had no idea what a Master Thesis is about!I canââ¬â¢t blame myself though since I never wrote one before, but if you ask me now to describe this experience I would say that itââ¬â¢s like a road trip: you set yourself a destination, you have a loyal crew that is always there for you, a roadmap, supporters on the side and then the journey begins. Within the latter, you face setbacks with the help of others, you share knowledge, you meet new people and most importantly you get to know themâ⬠¦ This journey would not have been possible without the support, camaraderie and guidance of many friends, colleagues and my family.For all these reasons, I couldnââ¬â¢t let the journey end without expressing my gratitude to each and everyone of them. First and foremost, I would like to express my sincere gratitude to my supervisor, Philippe Spaas, who made it possible for me to work in this project under his supervision and in collaboration with IBM. It was a privilege to work alongside with him and a unique learning opportunity for me! I am indebted for his precious guidance and for the time dedicated not only in helping me understand how a research paper should be formulated, but also in reviewing the latter.Thank you! I am very thankful as well to Tybra Arthur, who graciously accepted me in her team and supported my internship, Jean de Canniere who accepted to be my Manager and without whom I wouldnââ¬â¢t have had this opportunity. In this line of thought, I am also grateful to Hans Van Mingroot who helped me secure this project in its negotiation phase. All three were key elements, and their support and guidance throughout the research were important to me and very much appreciated.I would also like to express my gratitude to Professor Mihhail Matskin at KTH ââ¬â the Royal Institute of Technology ââ¬â for having accepted this Master Thesis and for being my examiner. His insights and help were invaluable to achieve more sound end results and put together this ? nal report! In addition, I would like to ext end my personal thanks to my Erasmus Coordinator, Anna Hellberg Gustafsson, for her support, kindness and dedication for the duration of the research which was key to the organization of the latter.She is, for me, the best coordinator I have met and heard about! I would probably not have taken the appropriate steps to have this opportunity within IBM if it werenââ¬â¢t for the initial support and guidance of Karl De Backer, Anika Hallier, Anton Wilsens and last but not least Parmjeet Kaur Gurmeet. I truly value their follow-up both on the research and on my experience! On a special note I would like to thank Parmjeet for having been always a good mentor to me and for her support and trust ever since the Extreme Blue internship.I want to thank each IBMer with whom I came in contact with in the Financial Services Sector Department for welcoming me into their working environment and for making my stay very enjoyable. In addition to the aforementioned IBMers, among many others and in no speci? c order I would like to thank Daniel Pauwels, Patrick Taymans, Hedwige Meunier, Gauthier de Villenfagne, Michel Van Der Poorten, Kjell Fastre, Annie Magnus, Wouter Denayer, Patrick Antonis, Sara Ramakers, Marc Ledeganck, Joel Van Rossem and Stephane Massonet. It was a real pleasure to share the open space and, more importantly, to meet them!Dan Gutfreund at IBM Haifa was a key element in the development of this thesis. I am very thankful for the discussions we had about Fraud Detection and for his advice in the different phases that compose this research. In addition, I would like to extend my thanks to Jean-Luc Collet at IBM La Gaude for his valuable help in obtaining a stable virtual machine with InfoSphere Streams. I am thankful to Professor Gianluca Bontempi and Liran Lerman at Universite Libre de Bruxelles for ? nding the time to discuss about Fraud Detection and Data Mining techniques.Their insights were vital for the development of the prototype and the overall rese arch. On the same vein, I would like to thank Chris Howard at IBM Dublin for his help in understanding Stream Computing and InfoSphere Streams. His guidance was crucial for a timely comprehension of the ? eld without which I wouldnââ¬â¢t have been able to develop the prototype. I want to thank Mike Koranda and John Thorson at IBM Rochester for their help in understanding the integration of Data Mining and Stream Computing and how to achieve the latter in a more ef? cient manner.I really appreciated their help with the prototype, especially when atypical errors occurred to more quickly detect the source of the problem. I am also thankful to IBM, as a company, for providing me the opportunity and necessary facilities to conduct my thesis project, as well as to KTH, as university, for having allowed me to take on this experience. I want to take this opportunity to thank my friend, Thomas Heselmans, for having been there ever since the beginning of the research despite my busy agenda . His support and concern were vital in times of great stress and trouble, thank you for your friendship!The same applies to Stephane Fernandes Medeiros, a great friend of mine who was always there for me and followed my work very closely. In addition, I am thankful to two of my greatest friends, Nicola Martins and Alberto Cecilio, for their friendship, for always supporting me and always having my back. Margarida Cesar is a very important person in my life, and I would like to express my gratitude for all the discussions and advice we shared, as well as for the support demonstrated ever since we met. I always take her advice very seriously and she has helped me cope with dif? ulties in more than one occasion, namely during the thesis, and for that Iââ¬â¢m very thankful! I am also very grateful to my friend, Arminda Barata, for all the help she provided me in moving and adapting myself to Stockholm. Without her help and concern I wouldnââ¬â¢t have felt at home so easily, and I wouldnââ¬â¢t have liked Stockholm from the very ? rst day. I would like to take advantage of this opportunity to thank all my colleagues and friends in Stockholm for making these two years of study unforgettable, and for shaping the person I am today.Among so many others, I would like to thank in particular Sanja Jankolovska, Boshko Zerajik, Pedram Mobedi, Adrien Dulac, Filipe Rebello De Andrade, Pavel Podkopajev, Cuneyt Caliskan, Sina Molazem, Arezoo Ghannadian and Hooman Peiro. I couldnââ¬â¢t have made it through without all of them! Last but de? nitely not least, because I didnââ¬â¢t have the chance to formally thank my friends in my previous studies, I would like to take this opportunity to extend my thanks to them for all the good moments we spent together throughout our bachelor degree as well as today.In particular I would like to thank Miruna Valcu, Rukiye Akgun, Vladimir Svoboda, Antonio Paolillo, Tony Dusenge, Olivier Sputael, Aurelien Gillet, Mathieu Duchene, Br uno Cats, Nicolas Degroot and Juraj Grivna. I reserve a special thank you note to Mathieu Stennier, for both his friendship and support throughout my academic life, and for having shared with me what were the best moments I had in Brussels while at University!I would very much like to express myself in Portuguese to my family so that they can all more easily understand what I have to say, thank you for your understanding: Nao podia deixar de agradecer a toda a minha familia o apoio que demonstraram ao longo deste percurso academico que conhece hoje um novo capitulo. Gostaria de agradecer a todos sem excepcao por acreditarem em mim e nunca duvidarem das minhas capacidades. Obrigado por estarem sempre presentes apesar da distancia, obrigado por se preocuparem comigo e por fazerem com que eu saiba que poderei sempre contar com voces!Sou verdadeiramente um ser afortunado por poder escrever estas palavrasâ⬠¦ Um obrigado especial a minha grande avo Olga por estar sempre disposta a sac ri? car-se por nos e por telefonar quase diariamente a perguntar se estou bem e se preciso de alguma coisa. Agradeco-lhe do fundo do coracao esse amor que tem pelos netos e que tanta forca transmite! Queria agradecer tambem aos meus primos Rui e Hugo, que sao para mim como os irmaos que eu nunca tive, a forca que me transmitem para seguir em frente face as adversidades da vida. Ambos ensinaram-me imenso durante toda a vida e sao uma fonte de inspiracao constante para mim!A admiracao que tenho por eles foi como um guia que me levou onde estou hojeâ⬠¦ Obrigado por acreditarem em mim para levar a bom porto este projecto e por terem estado sempre presentes a apoiar-me! Gostaria de deixar uma mensagem de apreco ao David, que e mais do que um primo para mim, e um melhor amigo, que sempre esteve presente e sempre se preocupou comigo durante a tese. Foram momentos, frases e situacoes da vida que ? zeram com que o David se tornasse na pessoa importante que e para mim e ao longo da tese a s suas mensagens de apoio foram sempre bem recebidas porque deram-me um alento enorme.Aproveito tambem para agradecer a minha querida tia Aida e ao meu estimado primo Xico pela preocupacao que tem sempre comigo e por serem uma fonte de inspiracao para mim. Desejo tambem aproveitar esta oportunidade para agradecer a Nandinha e Jorginho todo o apoio que me deram nao so durante estes 6 longos meses mas desde os meus primeiros passos. Sao como uns segundos pais para mim cujo apoio ao longo deste curso e capitulo da minha vida foi primordial. Agradeco, do fundo do coracao, o facto de me tratarem como se fosse um ? lho, por me guiarem e sempre ajudarem! Tenho ainda um lugar especial reservado para o meu tio Antonio.Um tio que admiro muito, que sempre me quis bem e cujo dom da palavra move montanhas! O seu conselho e para mim uma maisvalia, e agradeco todo o seu apoio e ajuda durante esta investigacao e sobretudo por me guiar quando nao ha estrelas no ceu. Aproveito para vos deixar a todos um pedido de desculpa por nao estar presente como gostaria, e agradeco o facto de que apesar de tudo voces estejam todos de pe ? rme atras de mim! Sem o vosso apoio nunca teria feito metade do que ? z! Costuma-se guardar o melhor para o ? m, e por isso nao podia deixar de agradecer aos meus pais tudo o que ? eram e fazem por mim! A lingua de Camoes e escassa para que eu consiga descrever o quao grato estouâ⬠¦ Dedico-vos esta tese, por sempre me terem dado todo o amor, carinho, e ajuda necessaria para ter uma vida feliz e de sucesso. Deixo aqui um grande e sentido obrigado por terem estado sempre presentes quando mais precisava, por me terem sempre apoiado a alcancar os meus objectivos, por me terem ensinado a viver, a amar, a partilhar e a ser a pessoa que sou hoje. Obrigado! Em particular gostaria de agradecer ao meu pai a compreensao que teve comigo durante este periodo mais ocupado.Agradecer-lhe a ajuda em conseguir por um meio termo as coisas e a olhar para elas de outro pr isma. Agradeco tambem a calma que me transmitiu e transmite, e o apaziguamento que me ensinou a ter face as adversidades da vida. Sem estas licoes de vida, que guardarei sempre comigo, sinto que a tese nao teria sido bem sucedida e eu nunca teria alcancado tudo o que alcancei! A minha mae, agradecoâ⬠¦ por onde hei-de comecar? Pela ajuda diaria durante a tese para que os meus esforcos se concentrassem no trabalho? Pela inspiracao diaria de um espirito lutador que nao desmorona face as di? culdades e injusticas da vida?Agradeco por tudo isto e muito mais pois sem a sua ajuda diaria nao teria conseguido acabar a tese. A admiracao que tenho pela sua forca e coragem ? zeram com que eu tentasse seguir os mesmos passos e levaram-me a alcancar patamares que considerava inalcancaveis! A paciencia que teve durante todo o projecto, mas sobretudo no ? m, e de louvar, e sem o seu ombro amigo teria sido tudo muito mais complicado. Obrigado a todos por tudo! Thank you all for everything! Filip e Miguel Goncalves de Almeida Table of Contents 1 Introduction Part I: Setting the Scene 2 Retail Banking and The State of the Art in Detection and Prevention of Fraud 2. The Retail Banking Industry . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2. 1. 1 A Short Walk Down Memory Lane . . . . . . . . . . . . . . . . . . . . 2. 1. 2 The Retail Banking IT Systemsââ¬â¢ Architecture . . . . . . . . . . . . . . 2. 2 Fraud . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2. 2. 1 Internet and E-Commerce Fraud . . . . . . . . . . . . . . . . . . . . . 2. 2. 2 Other Consumer Fraud . . . . . . . . . . . . . . . . . . . . . . . . . . 2. 3 Current Solutions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2. 3. 1 Technology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2. 3. 2 Analytics and Statistical Fraud-Scoring . . . . . . . . . . . . . . . . . 3 Problem De? nition 3. 1 Weak Links in Currently Available Solutio ns . 3. 1. 1 Bank Card and Pin Code . . . . . . . . . 3. 1. 2 One-Time-Password or Card Reader . . 3. 1. 3 Biometrics . . . . . . . . . . . . . . . . . 3. 1. 4 Analytics and Statistical Fraud-Scoring 3. 2 Facts and Figures . . . . . . . . . . . . . . . . . 3. 2. 1 France . . . . . . . . . . . . . . . . . . . 3. 2. 2 United Kingdom . . . . . . . . . . . . . 3. 3 E-Commerce and Internet Banking . . . . . . . 3. 4 Mobile Banking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 2 3 3 3 4 6 6 12 12 13 14 15 15 16 17 18 18 19 19 19 20 21 22 22 23 23 23 24 24 25 25 28 28 29 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30 31 31 31 32 32 33 34 Research Methodology 4. 1 Objective of the Research . . . . . . . . . . . . . . . 4. 2 Data Collection . . . . . . . . . . . . . . . . . . . . 4. 2. 1 FICOââ¬â¢s E-Commerce Transactions Dataset . 4. 2. 2 Personal Retail Bank Transacti ons . . . . . 4. 3 Data Analysis Plan . . . . . . . . . . . . . . . . . . 4. 3. 1 Partitioning of the Data . . . . . . . . . . . 4. 4 Instruments and Implementation Strategy . . . . . 4. 4. 1 InfoSphere Streams . . . . . . . . . . . . . . 4. 4. 2 SPSS Modeler . . . . . . . . . . . . . . . . . 4. 4. 3 MySQL Database . . . . . . . . . . . . . . . Part II: Behind the Curtains 5 Phase 0: Data Preprocessing 5. Getting to Know the Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5. 1. 1 Attributes and their Types . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5. 1. 2 Attributes in the Retail Banking Industry and in FICOââ¬â¢s Dataset . . . . . . 5. 1. 3 Statistical Description . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5. 2 Data Reduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5. 2. 1 Dimensionality Reduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5. 2. 2 Supervised Merge and Transformat ion of Nominal and Categorical Data . 5. 3 5. 4 5. 5 5. 6 . 7 5. 8 Cleaning Process . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5. 3. 1 Missing Values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5. 3. 2 Noisy Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Data Transformation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5. 4. 1 Transformation of Times and Dates . . . . . . . . . . . . . . . . . 5. 4. 2 Transformation by Normalization . . . . . . . . . . . . . . . . . . Sampling Strategies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5. 5. 1 Clustering using K-Means Algorithm . . . . . . . . . . . . . . . 5. 5. 2 Under-Sampling Based on Clustering . . . . . . . . . . . . . . . . Preprocessing Data with Stream Computing . . . . . . . . . . . . . . . . 5. 6. 1 Receiving and Sending Streams of Transactions . . . . . . . . . . 5. 6. 2 Retrieving and Storing Data to a Database . . . . . . . . . . . . . 5. 6. 3 Data Preprocessing using SPSS Solution Publisher . . . . . . . . . 5. 6. 4 Data Preprocessing using a Non-Generic C++ Primitive Operator Rule-Based Engine . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5. 7. 1 Streams with a Business Rules Management System . . . . . . . . Final Thoughts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36 36 36 37 37 37 39 40 41 42 42 43 45 45 46 48 49 50 51 51 52 53 53 54 55 56 57 57 58 60 60 61 62 62 63 63 66 71 71 73 76 77 6 Phase I: Data Classi? cation 6. 1 Supervised Learning . . . . . . . . . . . . . . . . . . . 6. 1. 1 Ensemble-Based Classi? er . . . . . . . . . . . . 6. 2 Classi? cation Algorithms . . . . . . . . . . . . . . . . 6. 2. 1 Support V ector Machines . . . . . . . . . . . . 6. 2. 2 Bayesian Networks . . . . . . . . . . . . . . . . 6. 2. 3 K-Nearest Neighbors (KNN) . . . . . . . . . . 6. 2. 4 C5. 0 Decision Tree . . . . . . . . . . . . . . . . 6. 3 Classi? cation using the Data Mining Toolkit . . . . 6. 3. 1 Weaknesses of the Approach . . . . . . . . . . 6. 4 Classi? cation using SPSS Modeler Solution Publisher 6. 4. 1 Implementation Details . . . . . . . . . . . . . 6. 5 Model Retraining Architecture: High Level Overview 6. 6 Final Thoughts . . . . . . . . . . . . . . . . . . . . . . 7 Phase II: Anomaly Detection and Stream Analysis 7. 1 Data Aggregation . . . . . . . . . . . . . . . . . . . . 7. 2 Bank Customers Aggregation Strategy . . . . . . . . 7. 3 Anomaly Detection . . . . . . . . . . . . . . . . . . . 7. 3. 1 Techniques for Anomaly Detection . . . . . . 7. 3. 2 Mahalanobis Distance . . . . . . . . . . . . 7. 4 Stream Analysis . . . . . . . . . . . . . . . . . . . . . 7. 4. 1 Window-Based Operators . . . . . . . . . . . 7. 4. 2 Window-Based Anomaly Detection Strategy 7. 5 Final Thoughts . . . . . . . . . . . . . . . . . . . . . Part III: Critical Review 8 Overall Evaluation 8. 1 Performance Measurement Techniques . . . . . . . . . 8. 1. 1 Performance Metrics . . . . . . . . . . . . . . . 8. 1. 2 Accuracy Levels . . . . . . . . . . . . . . . . . 8. 2 Data Preprocessing and Business Rules Analysis . . . 8. 3 Data Classi? cation . . . . . . . . . . . . . . . . . . . . 8. 3. 1 Un-preprocessed Classi? er Analysis . . . . . . 8. . 2 Preprocessed Un-Sampled Classi? er Analysis 8. 3. 3 Preprocessed Sampled Classi? er Analysis . . . 8. 3. 4 Ensemble-Based Classi? er Analysis . . . . . . 8. 4 Anomaly Detection . . . . . . . . . . . . . . . . . . . . 8. 5 Overall Concept . . . . . . . . . . . . . . . . . . . . . . 8. 6 Future Work . . . . . . . . . . . . . . . . . . . . . . . . 8. 6. 1 Extend Services . . . . . . . . . . . . . . . . . . 8. 6. 2 eXtreme Scale . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 78 78 78 79 80 80 81 83 84 87 88 89 90 91 92 i 8. 7 8. 6. 3 Architecture and Data Mining Algorithms . . . . . . . . . . . . . . . . . . . . . . . Final Thoughts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 93 94 95 i vi 9 Conclusion Appendix A Supporing Figures Glossary List of Figures Figure 1. 1 Figure 2. 1 Figure 2. 2 Figure 2. 3 Figure 2. 4 Figure 2. 5 Figure 2. 6 Figure 2. 7 Figure 2. 8 Figure 2. 9 Figure 3. 1 Figure 3. 2 Figure 3. 3 Figure 3. 4 Figure 3. 5 Figure 3. 6 Figure 3. 7 Figure 3. 8 Figure 4. 1 Figure 4. 2 Figure 4. 3 Figure 4. 4 Figure 4. 5 Figure 4. 6 Figure 4. 7 Figure 5. 1 Figure 5. 2 Figure 5. 3 Figure 5. 4 Figure 5. 5 Figure 5. 6 Figure 5. 7 Figure 5. 8 Figure 5. 9 Figure 5. 10 Figure 5. 11 Figure 5. 12 Figure 5. 13 Figure 5. 14 Figure 5. 15 Figure 6. Figure 6. 2 Figure 6. 3 Figure 6. 4 Figure 6. 5 Lost in Translation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . As-Is Banking IT Architecture . . . . . . . . . . Hype Cycle for Application Architecture, 2009 To-Be Banking IT Reference Architecture . . . . MitB Operation . . . . . . . . . . . . . . . . . . Possible Paypal website (1) . . . . . . . . . . . Possible Paypal website (2) . . . . . . . . . . . Keyboard State Table method . . . . . . . . . . Windows Keyboard Hook method . . . . . . . Kernel-Based Keyboard Filter Driver met hod . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 5 5 5 8 10 10 11 11 11 16 16 17 20 20 20 21 21 24 25 26 26 27 28 29 30 32 32 33 34 35 35 36 37 40 40 42 45 46 48 50 51 52 53 54 Components of the Chip and Pin Attack . . . . . . . . . . . . Attack to Card Illustrated . . . . . . . . . . . . . . . . . . . . One-Time-Password Hacking Material and Architecture . Number of European Internet Users and Online Purchasers Forecast: US Online Retail Forecast, 2010 to 2015 . . . . . . . Web Growth has Outpaced Non-Web Growth for Years . . . US Mobile Bankers, 2008-2015 . . . . . . . . . . . . . . . . . US Mobile Banking Adoption . . . . . . . . . . . . . . . . . . CRoss-Industry Standard Process for Data Mining . . . . . . . . . Streams Programming Model . . . . . . . . . . . . . . . . . . . . . ââ¬Å"Straight-throughâ⬠processing of messages with optional storage. Backup and Fail-Over System for Streams . . . . . . . . . . . . . . Multiple-Machines Architecture . . . . . . . . . . . . . . . . . . Analytical and Business In telligent Platforms Compared . . . . . Global Flow of Events: Stream-Based Fraud Detection Solution . Overall SPSS Modeler Stream for the Of? ine Data Preprocessing Phase Frequency of Transactions per Hour . . . . . . . . . . . . . . . . . . . . Amount Transferred per Transaction . . . . . . . . . . . . . . . . . . . . Data Feature Selection in SPSS . . . . . . . . . . . . . . . . . . . . . . . Data Preparation Preprocessing Phase in SPSS . . . . . . . . . . . . . . SPSS Stream CHAID Tree Model . . . . . . . . . . . . . . . . . . . . . . CHAID Tree for Data Reduction . . . . . . . . . . . . . . . . . . . . . Filtering Null Values with SPSS . . . . . . . . . . . . . . . . . . . . . . . Cyclic Values of Attribute hour1 . . . . . . . . . . . . . . . . . . . . . . K-Means Modeling in SPSS . . . . . . . . . . . . . . . . . . . . . . . . . Clustering with K-Means in SPSS Modeler . . . . . . . . . . . . . . . . Stream-based Application: Data Preprocessing and Rule-Based Engine Stream-based Application: Data Preprocessing . . . . . . . . . . . . . . Stream-based Application: Rule-Based Engine . . . . . . . . . . . . . . Interaction Between a BRMS and a Stream-based Application . . . . . Classi? cation in Stream-Based Application .Ensemble-Based Classi? er . . . . . . . . . . . Classi? cation in SPSS . . . . . . . . . . . . . . Support Vector Machines (SVMs) Illustrated Example of a Bayesian Network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . i Figure 6. 6 Figure 6. 7 Figure 6. 8 Figure 7. 1 Figure 7. 2 Figure 7. 3 Figure 7. 4 Figure 7. 5 Figure 7. 6 Figure 7. 7 Figure 7. 8 Figure 7. 9 Figure 7. 10 Figure 7. 11 Figure 7. 12 Figure 7. 13 Figure 8. 1 Figure 8. 2 Figure 8. 3 Figure 8. 4 Figure 8. 5 Figure 8. 6 Figure 8. 7 Figure 8. 8 Figure 8. Figure A. 1 Figure A. 2 Figure A. 3 Figure A. 4 Figure A. 5 Figure A. 6 K-Nearest Neighbors Illustrated . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Section of C5. 0 Decision Tree . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . SPSS C&DS: Classi? er Retraining . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Anomaly Detection Stream-based Application . . . . . . . . . . . . Aggregate Bank Customers . . . . . . . . . . . . . . . . . . . . . . . Learning a classi? er model for the normal class of transactions . . Transaction not belonging to a cluster . . . . . . . . . . . . . . . . .Transactions far from the clustersââ¬â¢ center . . . . . . . . . . . . . . . Mahalanobis Distance Illustrated . . . . . . . . . . . . . . . . . . . . Mahalanobis Distance: Stream-based Application . . . . . . . . . . Window Types . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Tumbling Windows . . . . . . . . . . . . . . . . . . . . . . . . . . . Sliding Windows . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Partitioned Keyword . . . . . . . . . . . . . . . . . . . . . . . . . . . Account average expenses and frequency of transactions in 3 days Window-Based Analysis: Stream-based Application . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54 55 60 61 63 64 65 65 66 67 71 71 72 73 73 74 78 79 84 86 88 89 92 92 94 ii iii iii iv iv v Benchmarking Stream-based Application: Concept for Each Processing Step . . Confusion Matrix . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Comparison between Un-Preprocessed and Preprocessed Data: Accuracy Levels Comparison between Sampled Datasets: Accuracy Levels (TP/FP) . . . . . . . Stream Analysis: Debited Account . . . . . . . . . . . . . . . . . . . . . . . . . . . Overall View of the Solution: Accuracy Levels (TP/FP/FN) . . . . . . . . . . . . Overall St ructure of the Financial Services Toolkit . . . . . . . . . . . . . . . . . . In-Memory Database with InfoSphere Streams . . . . . . . . . . . . . . . . . . . . Stream-Based Application: a Flexible and Multifaceted Architecture . . . . . . . Stream-based Application: Overview . . . . . . . . . . . . . . . . . . . . . . . . . . Time per Transaction for each of the Data Preprocessing Approaches . . . . . . . Time per Transaction for Preprocessing the Data and Examine the Business Rules . Metrics Data Classi? cation Process . . . . . . . . . . . . . . . . . . . . . . . . . . . . Anomaly Detection Time per Transaction . . . . . . . . . . . . . . . . . . . . . . . . Fraud Detection: Time per Transaction . . . . . . . . . . . . . . . . . . . . . . . . . List of Tables Table 3. 1 Table 5. 1 Table 5. 2 Table 6. 1 Table 7. 1 Table 8. 1 Table 8. 2 Table 8. 3 Table 8. 4 Table 8. 5 Table 8. 6 Table 8. 7 Table 8. 8 National fraud in France categorized by transaction type . . . . . . . . . . . . . . . Communalities PCA/Factor Analysis . . . . . . . . . . . . . . . . . . . . . . . . . . Steps for Under-Sampling Based on Clustering (SBC) . . . . . . . . . . . . . . . . . . Supported Mining Algorithms: Data Mining Toolkit . . . . . . . . . . . . . . . . . . Hardware Speci? cation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Individual Classi? er Accuracy Levels ââ¬â Un-Preprocessed Training Set . . . . . Individual Classi? er Accuracy Levels ââ¬â Un-Sampled Preprocessed Training Set Multiple Sampling Ratios Analyzed . . . . . . . . . . . . . . . . . . . . . . . . . Multiple Sampling Ratios Analyzed . . . . . . . . . . . . . . . . . . . . . . . . . Ensemble-Based Classi? r: Balanced . . . . . . . . . . . . . . . . . . . . . . . . Ensemble-Based Classi? er: Maximum Fraud Detection . . . . . . . . . . . . . Ensemble-Based Classi? er with Mahalanobis: Balanced Model Combination . Ensemble-Based Classi? er with Mahalanobis: Maximizing Fraud Detectio n . . . . . . . . . . . . . . . . . . . . . . . . . 19 34 41 56 77 81 83 85 85 87 87 89 89 List of Algorithms Algorithm 1 Algorithm 2 Algorithm 3 Algorithm 4 Algorithm 5 Algorithm 6 Algorithm 7 Algorithm 8 Algorithm 9 Algorithm 10 Algorithm 11 Algorithm 12 Algorithm 13 Algorithm 14 InputSource: Receive Incomming Transactions . . . . . . . . . . . . . . . . ODBCEnrich: Enrich an Incomming Transaction . . . . . . . . . . . . . . . . Non-Generic C++ Primitive Operator: Manual Preprocessing . . . . . . . . . Preprocessing: Manual Preprocessing of Incoming Transactions . . . . . . . Functor: Split Stream for Preprocessing and Rule-Based Engine . . . . . . . . Join: Append Business Rules to Preprocessed Transaction . . . . . . . . . . . Join: Append Business Rules to Preprocessed Transaction . . . . . . . . . . . Data Mining Toolkit Operator: Decision Tree C5. 0 Classi? er . . . . . . . . . . Non-Generic C++ Primitive Operator: Supervised Analysis . . . . . . . . . . Classi? cationEnsembl e: Constructor() . . . . . . . . . . . . . . . . . . . . . . Classi? cation Ensemble: process(Tuple & tp, uint32_t port) . . . . . . . . . . Variance-Covariance Inverse Matrix used in the Mahalanobis Distance . . . Individual Account Anomaly Detection Approach . . . . . . . . . . . . . . . Voting Protocol: Mahalanobis Distance, Window-Based and Classi? er Score . . . . . . . . . . . . . . 43 44 45 46 47 47 47 56 58 58 59 68 75 75 Chapter 1 Introduction ââ¬Å"A journey of a thousand miles must begin with a single stepâ⬠Lao Tzu ââ¬Å"If you work on fraud detection, you have a job for lifeâ⬠. These were the words used by Professor David J.Hand1 in one of his talks to synthesize the vast research ? eld that is Fraud Detection. Indeed, this ? eld consists of multiple domains, and is continually evolving through time with new strategies and algorithms to counter the constantly changing tactics employed by fraudsters2 . In this line of thought, currently available solutions ha ve been unable to control or mitigate the everincreasing fraud-related losses. Although thorough research has been done, only a small number of studies have led to actual Fraud Detection systems [27], and the focus is typically on novel algorithms aiming at increasing the accuracy levels.To this end, we want to look at the problem from a different angle, and focus on the foundations for a real-time and multi-purpose solution, based on a technology known as Stream Computing, able to encompass these algorithms while creating the possibilities for further research. We subdivide our study in three main parts. We begin with an overall understanding of the topic being discussed by de? ning the research environment, its problems and presenting the solutions currently available. In addition, we conclude this ? rst part by both specifying the structure, and outlining the objective of the research.The second part explores the overall course of action to bring about a Stream-based Fraud Detect ion solution. From this perspective, we discuss different strategies previously researched in Data Preprocessing, Data Classi? cation and Behavior-based Analysis, and tackle their combination and integration in a Stream-based application. Last but not least, we review the overall solution proposed, and examine the possibilities offered by the latter for further research in the ? eld of Fraud Detection in the Retail Banking Industry. Senior Research Investigator and Emeritus Professor of Mathematics at the Imperial College of London, and one of the leading researchers in the ? eld of Fraud Detection ââ¬â http://www3. imperial. ac. uk/people/d. j. hand ââ¬â link to the presentation: http://videolectures. net/mmdss07_hand_stf/ 2 a person intended to deceive others (i. e. one who commits fraud) [de? ned in the Glossary] 1 Part I: Setting the Scene ââ¬Å"Great things are not done by impulse, but by a series of small things brought togetherâ⬠Vincent van Gogh Fraud Detection in itself is interlinked with numerous ? lds of study, and before the playââ¬â¢s main action, we want to set the stage. In order to avoid getting off track and allowing you to better understand the scope, contents, choices made, and requirements of the research, we divided this act in three scenes. In the ? rst, we introduce the main actors ââ¬â namely banks, bank customers and fraudsters. In addition, we also present the current situation in the Detection and Prevention of Fraud in banks, describing the techniques being used both to counter and to commit fraudulent transactions. The second scene introduces the overall problem of fraud in the Banking Sector.It identi? es the weaknesses of the latest solutions, and quanti? es fraud losses as accurately as possible in some European countries and this based on the most recent data. We then take a step further and comment on new trends, and predict possible risks banks might incur from them. Before the end of the act, we introdu ce the two main parts of the play, as well as how we intend to approach the problem. More precisely, we provide some speci? cs regarding the research conducted, the tools used and the plan followed to reach our conclusions. Figure 1. : Lost in Translation 2 Chapter 2 Retail Banking and The State of the Art in Detection and Prevention of Fraud ââ¬Å"There are things known and there are things unknown, and in between are the doors of perceptionâ⬠Aldous Huxley Businessmen and politicians, before sealing deals or taking political decisions, are known to go through a phase of reconnaissance ââ¬â the military term for exploring enemy or unknown territory. Just as it is important to them, so it is for you when you are about to dive into the speci? cs of a real-time fraud detection solution.In this line of thought, it is important to grasp the context of the research to better understand the concepts discussed. To do so, we start this chapter with an overall view of the Retail Ba nking Industry, to understand both its services and IT architecture (Section 2. 1); we continue with a de? nition of fraud together with a description of the different fraud types that affect banks and how they operate (Section 2. 2); lastly, we give an overview of some of the current solutions available (Section 2. 3). 2. 1 The Retail Banking Industry To describe the banking industryââ¬â¢s evolution that started earlier than 2000 B.C. [91], deserves almost a research paper on its own. For this reason, and because we donââ¬â¢t want to divert from the topic, we start by solely providing a simple and brief resume about the origins of the banking industry (Section 2. 1. 1). The latter is an interesting talking point that not only allows you to understand how it all started, but also to perceive the challenge of keeping a bank pro? table. Additionally, it is a good introduction to understand a more technical description of the IT architecture behind the banking services (Section 2 . 1. 2). 2. 1. 1 A Short Walk Down Memory LaneIt all started with barter back in the time of Dravidian India, passing through Doric Greece to preRoman Italy, when a cow or an ox was the standard medium of exchange. [91] However, given the dif? culty of trading fairly, evaluating different goods with the same standards, and ? nding suitable goods for both parties involved, the invention of ââ¬Å"moneyâ⬠inevitably developed. Indeed, the origin of the word money is pecunia in Latin, which comes from pecus, meaning cattle. Through time, money evolved in the different civilizations and became not only a symbol but also a key factor in trading.Together with the development of the art of casting, the different mediums of exchange evolved gradually from random precious metals to what we now know as currency. This developments made our forefathers the proponents of the ? rst banks for reasons that are still of applicability in todayââ¬â¢s banking system. The code of Hammurabi in th e early 2000 B. C. stated ââ¬Å"If a man gives to another silver, gold or anything else to safeguard, whatsoever he gives he shall show to witnesses, and he shall arrange the contracts before he makes the deposits. [91] It is therefore clear that the Babylonians already placed back in their time their valuable possessions in a safe place, guarded by a trusted man. 3 Nevertheless, the real inspiration for the banking system as we know it today came from the Greeks. Unlike the Babylonians, the Greeks didnââ¬â¢t have a government and therefore the country was divided into independent states that were constantly either at war or in a state of unrest. [91] In these turbulent times, they found Temples to be the only safe place able to survive the test of wartime.They were seen as safe deposit vaults, marking the beginning of the functions of our current banks. Indeed, records show that the Temples not only kept money safe but also lent the funds at a certain interest rate. In addition , even though safeguarding the money started as a service free of charge, it soon turned into a business where small commissions were applied. The banking industry continued to evolve through time, from the commercial development of the Jews; passing by the establishment of the Bank of St.George, the Bank of the Medici and the Bank of England, to the rise of the Rothschilds, and the development of banking in the land of the Vikings. [91] At this moment in time, a major bank is a combination of a dozen of businesses, such as corporate, investment and small business banking, wealth management, capital markets. One among these is the retail banking industry. [46] The retail banking industry is characterized by a particularly large number of customers and bank accounts in comparison to any other banking business, which results in a much higher number of transactions, services and products.In addition, it relies more and more on technology due to the levels of cooperation between banks, retailers, businesses, customers leading to an ever-increasing amount of information processing requirements. In a nutshell, todayââ¬â¢s banks follow the same principle described earlier by borrowing from clients in surplus and lending to those in de? cit. This triangulation is a win-win situation for the bank and its customers: the bank makes revenue from the net interest income, which is the difference between what it pays to the lending customer and what it receives from the borrower.Nevertheless, the bank canââ¬â¢t lend all the deposits and needs to guarantee that a certain percentage is kept aside to satisfy customer withdraws and requirements. [92] Even though the situation varies from bank to bank, it is noteworthy to mention that ââ¬Å"more than half of a retail bankââ¬â¢s revenue, perhaps three-quarters, comes from this intermediation role in the form of net interest incomeâ⬠. [46] To conclude, in todayââ¬â¢s world, and after years of evolution, retail ban ks provide you with a multitude of services for which they charge fees, mainly to cover the maintenance of the infrastructure and the bankââ¬â¢s structure.These added up together account between 15% to 35% of the net interest income. [46] Among the services you can ? nd payment services, phone banking, money transfer, ATMs1 , online banking, advisory services, investment and taxation services, mobile banking and many more. How does a bank ef? ciently govern, offer and maintain all these services? 2. 1. 2 The Retail Banking IT Systemsââ¬â¢ Architecture Just as banking services evolved through time so did the overall back-end architecture allowing a bank to provide all the aforementioned services. This evolution was especially prominent after the unveiling by Barclays Bank f the ? rst ATM machine in 19672 : from that moment on, banks started investing heavily in computerized systems with the goal of automating manual processes in an effort to improve its services, overall status in the market and cut costs. From this perspective, the IT systems of banks matured from the creation of payment systems together with the launch of the international SWIFT network3 in the 70s, to todayââ¬â¢s core banking system: a general architecture that supports all the channels and services of a bank and where each one of them is digitalized.An overview of such general architecture is illustrated in Figure 2. 1 [77]. 1 acronym for Automated Teller Machine, a machine that automatically provides cash and performs other banking services on insertion of a special card by the account holder [de? ned in the Glossary] 2 http://www. personal. barclays. co. uk/PFS/A/Content/Files/barclays_events. pdf 3 Society for Worldwide Interbank Financial Telecommunication (SWIFT) is a member-owned cooperative that operates a worldwide standardised ? nancial messaging network through which the ? nancial world conducts its business operations http://www. wift. com 4 This architecture was in plac e in many banks some years ago, and still is in some cases, but even though it provides the clients with all the necessary banking tools, it had certain drawbacks that became visible through the modernization and improvement of services. As it is described by both Microsoft [82] and IBM [77]: the as-is architecture has no true enterprise view of a customer because information is duplicated, which leads to inconsistent customer services and promotions across channels; when adding new or changing current products, it takes time to bring Figure 2. : As-Is Banking IT Architecture (source [77]) them to the market and a signi? cant amount of changes to the core system code. This leads to a dif? culty in responding quickly to new challenges and evolving regulatory pressures. Faced with the aforementioned problems, banks had the need to change towards a more ? exible and ef? cient architecture that would allow them to comply with the ever-changing needs of the clients and of the technology. With this n mind, the major players in core banking have switched to a Service-Oriented Architecture (SOA) with the intended goal of improving growth, reducing costs, reducing operational risks, and improving customer experience. [69] [94] [83] [77] [82] As reported by Forrester in a survey in 2007 [82], out of 50 European banks, 53 percent declared they were already replacing their core system while 27 percent were planning to do so and 9 percent had already completed a major transition. The same survey assessed that 56 percent of the banks already used SOA and 31 percent were planning to.Additionally, in Gartnerââ¬â¢s 2009 report (Figure 2. 2 [28]), supports this strategy and believed that SOA-based architectures was increasingly being adopted and would be widely accepted in a time frame of 2 to 5 years. In the latest update (2011th Edition [29]), SOA is entering the Plateau of Productivity, which indiFigure 2. 2: Hype Cycle for Application Architecture, 2009 cates that the ma instream adoption is starting to take off. (source [28]) With this transition to an agile banking platform with a more ? exible product de? ition built on SOA principles, banks expect to gradually simplify their business and become more ef? cient in the long term. Indeed, the aforementioned platform which is illustrated in Figure 2. 3, is meant to provide the banks with faster and easier ways to update the system and comply with changing industry regulations and conditions. Additionally, by having a holistic view of the customer-relevant data across systems, a bank is able to better focus and analyze it with the goal to improve its customers experience by investing in more ef? cient and ? xible customer-centric offerings. Lastly, the architecture allows for integrated customer analytics and insight capabilities. In this line of thought, a stream-based real-time fraud detection solution would be easy to integrate in such an architecture, allowing the bank, as we will see later on, to broaden its services, data analysis capabilities and detect fraud in realtime. Figure 2. 3: To-Be Banking IT Reference Architecture (source [77]) 5 2. 2 Fraud When one wants to get something from others illegally he can do it in two ways: force or trick them into doing so. The ? st is better known as robbery and is usually more violent and noticeable; the second is known as fraud, which is more discrete and therefore preferred by fraudsters. [76] From this we can understand that fraud includes a wide variety of acts characterized by the intent to deceive or to obtain an unearned bene? t. [30] Many audit-related agencies provide distinct insights into the de? nition of fraud that can be brie? y summarized in this way: De? nition 1. Fraud consists of an illegal act (the intentional wrongdoing), the concealment of this act (often only hidden via simple means), and the deriving of a bene? (converting the gains to cash or other valuable commodity) [30] Given this de? nition, we can furt her classify the known types of fraud by victim, perpetrator and scheme [76]: â⬠¢ Employee Embezzlement ââ¬â Employees deceive their employers by taking company assets either directly or indirectly. The ? rst occurs without the participation of a third party and is characterized by an employee who steals company assets directly (e. g. cash, inventory, tools, etc. ). In the second, the stolen assets ? ow from the company to the perpetrator through a third party.Indeed, indirect fraud happens usually when an employee accepts bribes to allow for lower sales or higher purchases prices, or any other dishonest action towards the company. â⬠¢ Vendor Fraud ââ¬â This type of fraud usually happens when a seller overcharges its products; ships lower quality goods; or doesnââ¬â¢t ship any products to the buyer even though it received the corresponding payment. Vendor fraud happens more frequently with government contracts and usually becomes public when discovered, being one of the most common in the United States. Customer Fraud ââ¬â Customer fraud takes place when a customer doesnââ¬â¢t pay for the products he purchased, pays too little, gets something for nothing or gets too much for the price. All these situations occur through deception. â⬠¢ Management Fraud ââ¬â Management fraud, also known as ? nancial statement fraud, is committed by top management who deceptively manipulate ? nancial statements. The interest behind these actions is usually to hide the real economic situation of a company by making it look healthier than it actually is.However, for the purpose of this research, and given the fact that we are focusing on fraud perpetrated in the retail banking industry, we will mainly focus on every possible bank transaction that a customer can perform. The research will be based in debit, online banking ââ¬â namely electronic bill payment and giro transfers ââ¬â and debit plastic card transactions. Fraud that can be perpet rated against these transactions falls within the category known as consumer fraud. Additionally, the latter can be sub-categorized in Internet and e-commerce fraud and other (non-)internet related fraud that we will now describe in more detail. . 2. 1 Internet and E-Commerce Fraud The Internetâ⬠¦ a technology that was unknown to many of us 25 years ago and is used now by billions of people either at home, work or on-the-go. We can ? nd webpages from business home pages, to informational wikis, passing through social networking sites; ? les that take the form of text, audio or video; and a multitude of services and web applications. It took just 3 years for the Internet to reach over 90 million people while the television and the radio took respectively 15 and 35 years to reach 60 million people! 76] This is how fast the medium through which e-commerce fraud takes place has evolved. This informational and technological revolution led to new ways for fraud to be perpetrated while techniques to avoid it have dif? culties to keep up with the pace. Today, businesses depend on the Internet to perform paperless transactions and exchange information between them: they mostly use e-business connections, virtual private networks (VPNs1 ), and other specialized connections. 76] This type of commerce is known as e-commerce, or electronic commerce, because it takes place over electronic systems. Therefore, even if you think you are not using the Internet, any operation you make at a local branch, any withdraw you do from an ATM or any purchase you make at a local store with your bank card, a Network transaction takes place. 1 itââ¬â¢s a method employing encryption to provide secure access to a remote computer over the Internet [de? ned in the Glossary] 6Since most businesses rely on Network-based transactions and, as we will describe later on, Internet users use the network more and more frequently to buy products or services, the North American Securities Administ rators Association (NASAA) considers that Internet fraud has become a booming business. [76] With this in mind, there are three standpoints that need to be taken into consideration when describing in more details the risks involved in this category that undermine banks and more importantly their customers: risks lying inside and/or outside the organization.Risks Inside Banks and Other Organizations The main risks come from within the bank. [76] Indeed, a perpetrator with inside access has knowledge regarding the environment, the security mechanisms and how to bypass them. Additionally, any employee with access to the organizationââ¬â¢s network has automatically bypassed ? rewalls and security checks making it easier to in? ltrate systems, steal information or data and cause damage to the bank. From this perspective, the most common example is the superuser access that most IT-related employees (e. g. rogrammers, technical support, network administrators or project managers) have within the companyââ¬â¢s infrastructure and database systems. [76] In one survey, ââ¬Å"more than a third of network administrators admitted to snooping into human resource records, layoff lists, and customer databasesâ⬠. [76] A related survey found that ââ¬Å"88 percent of administrators would take sensitive data if they were ? red, and 33 percent said they would take company password listsâ⬠. [76] Even if a perpetrator does not have personal access to the targeted system and information, there are techniques that he can use to get at them indirectly, i. . via a person of interest: ââ¬â Snif? ng, also known as Eavesdropping: Snif? ng is the logging, ? ltering, and viewing of information that passes along a network connection. Applications are easily and available for free on the Internet, Wireshark1 and tcpdump2 that allow network administrators to troubleshoot any possible problem in the network. Nevertheless, these applications can as easily be used by hackers to gather information from unencrypted communications. 76] A good example is the usage of unencrypted e-mail access protocols like Post Of? ce Protocol 3 (POP3) or the Internet Message Access Protocol (IMAP) instead of other more secured ones. Since e-mail clients check messages every couple of minutes, hackers have numerous opportunities to intercept personal information. [76] A user could in addition encrypt the body of the email by using Secure/Multipurpose Internet Mail Extensions (S/MIME) or OpenPGP in order to avoid that sensitive information passes through the network in plain text.Even though security experts have successfully managed to encrypt emails, the reason behind this lack of security is that they have failed to take into consideration the needs of the end-user ââ¬â namely, ââ¬Å"the ability to occasionally encrypt an email without much trouble at allâ⬠. [113] ââ¬â Wartrapping: Wartrapping happens when hackers set up free access points to the Internet t hrough their laptops in speci? c locations like airports or inside a companyââ¬â¢s headquarters. Users, unaware that the wi? passes through a hackerââ¬â¢s computer, connect to the latter and navigate the Internet as if they had a secured connection.When logging their internet banking services and performing transactions, or simply access their emails, the hacker can see the bits and bytes of every communication passing through any laptop in the clear. In this line of thought, hackers can get caught in their own web as companies are also using what they call honeypot traps. The latter is an information system resource, like a computer, data, or a network site (e. g. wireless entry), whose purpose is not only to divert attackers and hackers away from critical resources, but also to serve as a tool to study their methods. 1] These systems are placed strategically so to look like part of the companyââ¬â¢s internal infrastructure even though they are actually isolated and monito red by administrators of the organization. One of the most widely used tools is honeyd3 . [89] 1 2 3 http://www. wireshark. org/ http://www. tcpdump. org/ http://www. honeyd. org/ 7 Passwords are the Achilleââ¬â¢s heel of many systems since its creation is left to the end user who keeps them simple and within his or her preferences and life experiences (e. g. birthdays, family names, favorite locations or brands).In addition, users tend to re-use the same password for different purposes in order to avoid having to remember different ones, which leads perpetrators to gain access to different services and accounts with a single password from the person. In addition, another source of threats are the laptops and mobile devices that many employees take with them outside the companyââ¬â¢s protected environment. While in these unsecured contexts, the devices are exposed to viruses, spyware, and other threats that might compromise again the integrity of other organizationââ¬â¢s sy stem once these computers are plugged in the network.Viruses, trojans and worms are able to enter the protected environment without having to go through ? rewalls and security checks, making it easier to in? ltrate key information systems and bypass defense mechanism. Risks Outside Banks and Other Organizations The Internet not only became a source of services to users and companies but also a rich medium for hackers to gain access to personal systems. Indeed, when performing attacks, hackers are relatively protected because they cross international boundaries ââ¬â which puts them under a different jurisdiction than the victim of the attack ââ¬â and are mostly anonymous ââ¬â making tracking dif? ult. Therefore, the Internet became the defacto technological medium to perform attacks and there are numerous ways of doing so: ââ¬â Trojan Horses: A trojan horse is a program designed to breach the security of a computer system and that has both a desirable and a hidden, us ually malicious, outcome. [86] These programs can be embedded in a bank userââ¬â¢s computer when he views or opens an infected email, visits or downloads a ? le from an unsecured website or even when visiting a legitimate website that has been infected by a trojan. [85] From this perspective, a good example is the man-in-the-browser (MitB) attack, represented in Figure 2. , which uses trojan horses to install extensions or plugins in the browser that are used to deceive a bank customer: Whenever a speci? c webpage is loaded, the Trojan will ? lter it based on a target list (usually online banking pages). The trojan extension waits until the user logs into his bank and starts to transfer money. When a transaction is performed, the plug-in extracts data from all the ? elds and modi? es the amount and recipient according to the hackerââ¬â¢s preferences through the document object model (DOM1 ) interface, and resubmits the form to the server.The latter will not be able to identify whether the values were written by the customer or not and performs the Figure 2. 4: MitB Operation (source2 ) transaction as requested. [85] ââ¬â ATM Attack Techniques: An Automated Teller Machine (ATM), is a computerized device that allows customers of a ? nancial institution to perform most banking transactions and check their account status without the help of a clerk. The device identi? es the customers with the help of a plastic bank card, which contains a magnetic stripe with the customerââ¬â¢s information, together with a personal identi? ation number (PIN) code. [2] ATMs are attractive to fraudsters because they are a direct link to customers information and money, and there are security pitfalls with their current architecture [2]: the way data is encoded in the magnetic media makes it easily accessible if a hacker invests some money to buy the easyto-be-found equipment, and time to decode and duplicate the contents; in addition, with a four 1 An interface that let s software programs access and update the content, structure, and style of documents, including webpages [de? ed in the Glossary] 2 www. cronto. com, blog. cronto. com/index. php? title=2fa_is_dead 8 digit PIN, not only will one in every 10. 000 users have the same number but it also allows brute force attacks to discover the combination. Not to mention the possible physical attacks on ATMs which cannot be considered as fraud (see De? nition 1), there are a couple of ways fraudsters steal money from bank customers [2]: 1. Skimming Attack: skimming is the most popular approach in ATMs and consists in using devices named skimmers that capture the data from the magnetic strip.These devices can be plugged in an ATMââ¬â¢s factory-installed card reader and allows for download of all personal information stored on the card. In addition, to obtain the PIN code fraudsters use either shoulder-sur? ng and hidden video cameras, or distraction techniques while the customer uses the ATM. [2] S ometimes fraudsters take a step further and create their own fake teller machines to deceive bank customers; this is considered to be a spoo? ng attack that we will describe in more details below. [39] 2.Card Trapping: this tech
Saturday, September 14, 2019
Doctrine of Social Responsibility
Doctrine of Social ResponsibilityThe doctrine of social responsibility holds that individuals and organizations should advance the interests of society at large. They can do this by abstaining from harmful actions and by performing socially beneficial acts. Although the doctrine of social responsibility applies to people and organizations, much of the discussion focuses on business and the extent to which social responsibility should influence business decisions.Examples of Social Responsibility?AnswerWhen individuals and organizations say they are motivated by social responsibility, they are referring to a feeling of ethical obligation to act in ways that benefit society.In recent years, the mantra of social responsibility has been taken up by small businesses, non-profits, and corporations alike. Some notable examples of corporate efforts at social responsibility include: Ben & Jerry's, which started the Ben & Jerry's Foundation and donates 7.5% of profits to charitable causes Kenn eth Cole, which has supported AIDS awareness and research Pedigree, which distributes grants and food to animal shelters.Each of these companies has recognized that success in business alone falls short of contributing to the societies they share in, and have taken the extra step to address their ethical obligations.On an individual level, everyone can engage in acts of social responsibility, every day. Consider the consequences of your actions on society as whole. Turn off lights and electronics when they aren't needed to conserve energy. Donate money to trustworthy organizations that work to further causes that interest you.VolunteerRemember, the smallest act of individual social responsibility can have a powerful impact when multiplied by an entire community.Voluntary Hazard EliminationCompanies involved with social responsibility often take action to voluntarily eliminate production practices that could cause harm for the public, regardless of whether they are required by law. F or example, a business could institute a hazard control program that includes steps to protect the public from exposure to hazardous substances through education and awareness. A plant that uses chemicals could implement a safety inspection checklist to guide staff in best practices when handling potentially dangerous substances and materials. A business that makes excessive noise and vibration could analyze the effects its work has on the environment by surveying local residents. The information received could be used to adjust activities and develop soundproofing to lessen public exposure to noise pollution. Community DevelopmentCompanies, businesses and corporations concerned with social responsibility align with appropriate institutions to create a better environment to live and work. For example, a corporation or business may set up a foundation to assist in learning or education for the public. This action will be viewed as an asset to all of the communities that it serves, wh ile developing a positive public profile. Related Reading: Role of Social Responsibility in Marketing PhilanthropyBusinesses involved in philanthropy make monetary contributions that provide aid to local charitable, educational and health-related organizations to assist under-served or impoverished communities. This action can assist people in acquiring marketable skills to reduce poverty, provide education and help the environment. For example, the Bill and Melinda Gates Foundation focuses on global initiatives for education, agriculture and health issues, donating computers to schools and funding work on vaccines to prevent polio and HIV/AIDS. Creating Shared ValueCorporate responsibility interests are often referred to as creating shared value or CSV, which is based upon the connection between corporate success and social well-being. Since a business needs a productive workforce toà function, health and education are key components to that equation. Profitable and successful bu sinesses must thrive so that society may develop and survive. An example of how CSV works could be a company-sponsored contest involving a project to improve the management and access of water used by a farming community, to foster public health. Social Education and AwarenessCompanies that engage in socially responsible investing use positioning to exert pressure on businesses to adopt socially responsible behavior themselves. To do this, they use media and Internet distribution to expose the potentially harmful activities of organizations. This creates an educational dialogue for the public by developing social community awareness. This kind of collective activism can be affective in reaching social education and awareness goals. Integrating a social awareness strategy into the business model can also aid companies in monitoring active compliance with ethical business standards and applicable laws. For other types of responsibility, see Responsibility (disambiguation). Social responsibility is an ethical theory that an entity, be it an organization or individual, has an obligation to act to benefit society at large. Social responsibility is a duty every individual has to perform so as to maintain a balance between the economy and the ecosystem. A trade-off always[citation needed] exists between economic development, in the material sense, and the welfare of the society and environment. Social responsibility means sustaining the equilibrium between the two. It pertains not only to business organizations but also to everyone whose any action impacts the environment. [1] This responsibility can be passive, by avoiding engaging in socially harmful acts, or active, by performing activities that directly advance social goals. Businesses can use ethical decision making to secure their businesses by making decisions that allow for government agencies to minimize their involvement with the corporation. For instance if a company follows the United States Environmental Protection Agency (EPA) guidelines for emissions on dangerous pollutants and even goes an extra step to get involved in the community and address those concerns that the public might have; they would be less likely to have the EPA investigate them for environmental concerns. [3] ââ¬Å"A significant element of current thinking about privacy, however, stresses ââ¬Å"self-regulationâ⬠rather than market or government mechanisms for protecting personal informationâ⬠. According to some experts, most rules and regulations are formed due to public outcry, which threatens profit maximization and therefore the well-being of the shareholder, and that if there is not outcry there often will be limited regulation. [5] Critics argue that Corporate social responsibility (CSR) distracts from the fundamental economic role of businesses; others argue that it is nothing more than superficial window-dressing; others argue that it is an attempt to pre-empt the role of governments as a watchdog over powerful corporations though there is no systematic evidence to support these criticisms. A significant number of studies have shown no negative influence on shareholder results from CSR but rather a slightly negative correlation with improved shareholder returns. [clarification needed][6] The Social Responsibility of Business is to Increase its Profits by Milton Friedman The New York Times Magazine, September 13, 1970. Copyright @ 1970 by The New York Times Company. When I hear businessmen speak eloquently about the ââ¬Å"social responsibilities of business in a free-enterprise system,â⬠I am reminded of the wonderful line about the Frenchman who discovered at the age of 70 that he had been speaking prose all his life. The businessmen believe that they are defending free enterprise when they declaim that business is not concerned ââ¬Å"merelyâ⬠with profit but also with promoting desirable ââ¬Å"socialâ⬠ends; that business has a ââ¬Å"social conscienceâ⬠and takes seriously its responsibilities for providing employment, eliminating discrimination, avoiding pollution and whatever else may be the catchwords of the contemporary crop of reformers. In fact they areââ¬âor would be if they or anyone else took them seriouslyââ¬âpreaching pure and unadulterated socialism. Businessmen who talk this way are unwitting puppets of the intellectual forces that have been undermining the basis of a free society these past decades. The discussions of the ââ¬Å"social responsibilities of businessâ⬠are notable for their analytical looseness and lack of rigor. What does it mean to say that ââ¬Å"businessâ⬠has responsibilities? Only people can have responsibilities. A corporation is an artificial person and in this sense may have artificial responsibilities, but ââ¬Å"businessâ⬠as a whole cannot be said to have responsibilities, even in this vague sense. The first step toward clarity in examining the doctrine of the social responsibility of business is to ask precisely what it implies for whom. Presumably, the individuals who are to be responsible are businessmen, which means individual proprietors or corporate executives. Most of the discussion of social responsibility is directed at corporations, so in what follows I shall mostly neglect the individual proprietors and speak of corporate executives. In a free-enterprise, private-property system, a corporate executive is an employee of the owners of the business. He has direct responsibility to his employers. That responsibility is to conduct the business in accordance with their desires, which generally will be to make as much money as possible while conforming to the basic rules of the society, both those embodied in law and those embodied in ethical custom. Of course, in some cases his employers may have a different objective. A group of persons might establish a corporation for an eleemosynary purposeââ¬âfor example, a hospital or a school. The manager of such a corporation will not have money profit as his objective but the rendering of certain services. In either case, the key point is that, in his capacity as a corporate executive, the manager is the agent of the individuals who own the corporation or establish the eleemosynary institution, and his primary responsibility is to them. Needless to say, this does not mean that it is easy to judge how well he is performing his task. But at least the criterion of performance is straightforward, and the persons among whom a voluntary contractual arrangement exists are clearly defined. Of course, the corporate executive is also a person in his own right. As a person, he may have many other responsibilities that he recognizes or assumes voluntarilyââ¬âto his family, his conscience, his feelings of charity, his church, his clubs, his city, his country. He ma}. feel impelled by these responsibilities to devote part of his income to causes he regards as worthy, to refuse to work for particular corporations, even to leave his job, for example, to join his country's armed forces. Ifwe wish, we may refer to some of these responsibilities as ââ¬Å"social responsibilities. â⬠But in these respects he is acting as a principal, not an agent; he is spending his own money or time or energy, not the money of his employers or the time or energy he has contracted to devote to their purposes. If these are ââ¬Å"social responsibilities,â⬠they are the social responsibilities of individuals, not of business. What does it mean to say that the corporate executive has a ââ¬Å"social responsibilityâ⬠in his capacity as businessman? If this statement is not pure rhetoric, it must mean that he is to act in some way that is not in the interest of his employers. For example, that he is to refrain from increasing the price of the product in order to contribute to the social objective of preventing inflation, even though a price in crease would be in the best interests of the corporation. Or that he is to make expenditures on reducing pollution beyond the amount that is in the best interests of the corporation or that is required by law in order to contribute to the social objective of improving the environment. Or that, at the expense of corporate profits, he is to hire ââ¬Å"hardcoreâ⬠unemployed instead of better qualified available workmen to contribute to the social objective of reducing poverty. In each of these cases, the corporate executive would be spending someone else's money for a general social interest. Insofar as his actions in accord with his ââ¬Å"social responsibilityâ⬠reduce returns to stockholders, he is spending their money. Insofar as his actions raise the price to customers, he is spending the customers' money. Insofar as his actions lower the wages of some employees, he is spending their money. The stockholders or the customers or the employees could separately spend their own money on the particular action if they wished to do so. The executive is exercising a distinct ââ¬Å"social responsibility,â⬠rather than serving as an agent of the stockholders or the customers or the employees, only if he spends the money in a different way than they would have spent it. But if he does this, he is in effect imposing taxes, on the one hand, and deciding how the tax proceeds shall be spent, on the other. This process raises political questions on two levels: principle and consequences. On the level of political principle, the imposition of taxes and the expenditure of tax proceeds are governmental functions. We have established elaborate constitutional, parliamentary and judicial provisions to control these functions, to assure that taxes are imposed so far as possible in accordance with the preferences and desires of the publicââ¬âafter all, ââ¬Å"taxation without representationâ⬠was one of the battle cries of the American Revolution. We have a system of checks and balances to separate the legislative function of imposing taxes and enacting expenditures from the executive function of collecting taxes and administering expenditure programs and from the judicial function of mediating disputes and interpreting the law. Here the businessmanââ¬âself-selected or appointed directly or indirectly by stockholdersââ¬âis to be simultaneously legislator, executive and, jurist. He is to decide whom to tax by how much and for what purpose, and he is to spend the proceedsââ¬âall this guided only by general exhortations from on high to restrain inflation, improve the environment, fight poverty and so on and on. The whole justification for permitting the corporate executive to be selected by the stockholders is that the executive is an agent serving the interests of his principal. This justification disappears when the corporate executive imposes taxes and spends the proceeds for ââ¬Å"socialâ⬠purposes. He becomes in effect a public employee, a civil servant, even though he remains in name an employee of a private enterprise. On grounds of political principle, it is intolerable that such civil servantsââ¬âinsofar as their actions in the name of social responsibility are real and not just window-dressingââ¬âshould be selected as they are now. If they are to be civil servants, then they must be elected through a political process. If they are to impose taxes and make expenditures to foster ââ¬Å"socialâ⬠objectives, then political machinery must be set up to make the assessment of taxes and to determine through a political process the objectives to be served. This is the basic reason why the doctrine of ââ¬Å"social responsibilityâ⬠involves the acceptance of the socialist view that political mechanisms, not market mechanisms, are the appropriate way to determine the allocation of scarce resources to alternative uses. On the grounds of consequences, can the corporate executive in fact discharge his alleged ââ¬Å"social responsibilities? â⬠On the other hand, suppose he could get away with spending the stockholders' or customers' or employees' money. How is he to know how to spend it? He is told that he must contribute to fighting inflation. How is he to know what action of his will contribute to that end? He is presumably an expert in running his companyââ¬âin producing a product or selling it or financing it. But nothing about his selection makes him an expert on inflation. Will his hold ing down the price of his product reduce inflationary pressure? Or, by leaving more spending power in the hands of his customers, simply divert it elsewhere? Or, by forcing him to produce less because of the lower price, will it simply contribute to shortages? Even if he could answer these questions, how much cost is he justified in imposing on his stockholders, customers and employees for this social purpose? What is his appropriate share and what is the appropriate share of others? And, whether he wants to or not, can he get away with spending his stockholders', customers' or employees' money? Will not the stockholders fire him? (Either the present ones or those who take over when his actions in the name of social responsibility have reduced the corporation's profits and the price of its stock. ) His customers and his employees can desert him for other producers and employers less scrupulous in exercising their social responsibilities. This facet of ââ¬Å"social responsibilityâ⬠doc trine is brought into sharp relief when the doctrine is used to justify wage restraint by trade unions. The conflict of interest is naked and clear when union officials are asked to subordinate the interest of their members to some more general purpose. If the union officials try to enforce wage restraint, the consequence is likely to be wildcat strikes, rank-and-file revolts and the emergence of strong competitors for their jobs. We thus have the ironic phenomenon that union leadersââ¬âat least in the U. S. ââ¬âhave objected to Government interference with the market far more consistently and courageously than have business leaders. The difficulty of exercising ââ¬Å"social responsibilityâ⬠illustrates, of course, the great virtue of private competitive enterpriseââ¬âit forces people to be responsible for their own actions and makes it difficult for them to ââ¬Å"exploitâ⬠other people for either selfish or unselfish purposes. They can do goodââ¬âbut only at their own expense. Many a reader who has followed the argument this far may be tempted to remonstrate that it is all well and good to speak of Government's having the responsibility to impose taxes and determine expenditures for such ââ¬Å"socialâ⬠purposes as controlling pollution or training the hard-core unemployed, but that the problems are too urgent to wait on the slow course of political processes, that the exercise of social responsibility by businessmen is a quicker and surer way to solve pressing current problems. Aside from the question of factââ¬âI share Adam Smith's skepticism about the benefits that can be expected from ââ¬Å"those who affected to trade for the public goodâ⬠ââ¬âthis argument must be rejected on grounds of principle. What it amounts to is an assertion that those who favor the taxes and expenditures in question have failed to persuade a majority of their fellow citizens to be of like mind and that they are seeking to attain by undemocratic procedures what they cannot attain by democratic procedures. In a free society, it is hard for ââ¬Å"evilâ⬠people to do ââ¬Å"evil,â⬠especially since one man's good is another's evil. I have, for simplicity, concentrated on the special case of the corporate executive, except only for the brief digression on trade unions. But precisely the same argument applies to the newer phenomenon of calling upon stockholders to require corporations to exercise social responsibility (the recent G. M crusade for example). In most of these cases, what is in effect involved is some stockholders trying to get other stockholders (or customers or employees) to contribute against their will to ââ¬Å"socialâ⬠causes favored by the activists. Insofar as they succeed, they are again imposing taxes and spending the proceeds. The situation of the individual proprietor is somewhat different. If he acts to reduce the returns of his enterprise in order to exercise his ââ¬Å"social responsibility,â⬠he is spending his own money, not someone else's. If he wishes to spend his money on such purposes, that is his right, and I cannot see that there is any objection to his doing so. In the process, he, too, may impose costs on employees and customers. However, because he is far less likely than a large corporation or union to have monopolistic power, any such side effects will tend to be minor. Of course, in practice the doctrine of social responsibility is frequently a cloak for actions that are justified on other grounds rather than a reason for those actions. To illustrate, it may well be in the long run interest of a corporation that is a major employer in a small community to devote resources to providing amenities to that community or to improving its government. That may make it easier to attract desirable employees, it may reduce the wage bill or lessen losses from pilferage and sabotage or have other worthwhile effects. Or it may be that, given the laws about the deductibility of corporate charitable contributions, the stockholders can contribute more to charities they favor by having the corporation make the gift than by doing it themselves, since they can in that way contribute an amount that would otherwise have been paid as corporate taxes. In each of theseââ¬âand many similarââ¬âcases, there is a strong temptation to rationalize these actions as an exercise of ââ¬Å"social responsibility. â⬠In the present climate of opinion, with its wide spread aversion to ââ¬Å"capitalism,â⬠ââ¬Å"profits,â⬠the ââ¬Å"soulless corporationâ⬠and so on, this is one way for a corporation to generate goodwill as a by-product of expenditures that are entirely justified in its own self-interest. It would be inconsistent of me to call on corporate executives to refrain from this hypocritical window-dressing because it harms the foundations of a free society. That would be to call on them to exercise a ââ¬Å"social responsibilityâ⬠! If our institutions, and the attitudes of the public make it in their self-interest to cloak their actions in this way, I cannot summon much indignation to denounce them. At the same time, I can express admiration for those individual proprietors or owners of closely held corporations or stockholders of more broadly held corporations who disdain such tactics as approaching fraud. Whether blameworthy or not, the use of the cloak of social responsibility, and the nonsense spoken in its name by influential and prestigious businessmen, does clearly harm the foundations of a free society. I have been impressed time and again by the schizophrenic character of many businessmen. They are capable of being extremely farsighted and clearheaded in matters that are internal to their businesses. They are incredibly shortsighted and muddleheaded in matters that are outside their businesses but affect the possible survival of business in general. This shortsightedness is strikingly exemplified in the calls from many businessmen for wage and price guidelines or controls or income policies. There is nothing that could do more in a brief period to destroy a market system and replace it by a centrally controlled system than effective governmental control of prices and wages. The shortsightedness is also exemplified in speeches by businessmen on social responsibility. This may gain them kudos in the short run. But it helps to strengthen the already too prevalent view that the pursuit of profits is wicked and immoral and must be curbed and controlled by external forces. Once this view is adopted, the external forces that curb the market will not be the social consciences, however highly developed, of the pontificating executives; it will be the iron fist of Government bureaucrats. Here, as with price and wage controls, businessmen seem to me to reveal a suicidal impulse. The political principle that underlies the market mechanism is unanimity. In an ideal free market resting on private property, no individual can coerce any other, all cooperation is voluntary, all parties to such cooperation benefit or they need not participate. There are no values, no ââ¬Å"socialâ⬠responsibilities in any sense other than the shared values and responsibilities of individuals. Society is a collection of individuals and of the various groups they voluntarily form. The political principle that underlies the political mechanism is conformity. The individual must serve a more general social interestââ¬âwhether that be determined by a church or a dictator or a majority. The individual may have a vote and say in what is to be done, but if he is overruled, he must conform. It is appropriate for some to require others to contribute to a general social purpose whether they wish to or not. Unfortunately, unanimity is not always feasible. There are some respects in which conformity appears unavoidable, so I do not see how one can avoid the use of the political mechanism altogether. But the doctrine of ââ¬Å"social responsibilityâ⬠taken seriously would extend the scope of the political mechanism to every human activity. It does not differ in philosophy from the most explicitly collectivist doctrine. It differs only by professing to believe that collectivist ends can be attained without collectivist means. That is why, in my bookCapitalism and Freedom, I have called it a ââ¬Å"fundamentally subversive doctrineâ⬠in a free society, and have said that in such a society, ââ¬Å"there is one and only one social responsibility of businessââ¬âto use it resources and engage in activities designed to increase its profits so long as it stays within the rules of the game, which is to say, engages in open and free competition without deception or fraud. ââ¬Å"
Subscribe to:
Posts (Atom)