DEVELOPER & OPERATOR MANUAL

FraudGuard Documentation

Welcome to the official technical manual for FraudGuard — the AI-powered autonomous fraud prevention engine engineered by TeamRootOps at Galgotias University.

1. Overview & Purpose

FraudGuard is a real-time, low-latency transaction processing engine designed to autonomously detect and intercept fraudulent financial activity. Operating with an evaluation latency under 25 milliseconds, FraudGuard inspects transactions through stateful heuristic pipelines, behavioral anomaly detection, and composite scoring algorithms before committing balance mutations to persistent ACID storage.

Core Philosophy: Deterministic security, transparent risk scoring, strict isolation of sensitive personal identifiers (PII), and frictionless user experience for legitimate transactions.

Core System Capabilities

  • Stateful Velocity Tracking: Micro-burst monitoring preventing carding attacks and account takeover attempts.
  • Dynamic Risk Tiering: Automatic division into LOW, MEDIUM, HIGH, and CRITICAL risk tiers with adaptive enforcement.
  • Autonomous Triage & Alerting: Real-time incident dispatching notifying security analysts with full rule audit trails.
  • Enterprise RBAC: Role-based access control protecting executive dashboards, transaction telemetry, and account management.

2. Quickstart & Setup Guide

Follow these steps to deploy and run FraudGuard on your local development or staging environment.

Prerequisites

ComponentRequired VersionPurpose
Java Development Kit (JDK)17 LTS or 21 LTSCompiler & runtime environment
Apache Tomcat10.1.xJakarta EE 10 Servlet Container
MySQL Database8.0+Relational transactional storage (InnoDB)
Apache Maven3.8+Build automation & dependency management

Step 1: Database Initialization

Create the database schema and seed default administrative and test customer accounts:

# Connect to MySQL 8.0 CLI
mysql -u root -p

# Execute initialization scripts from repository root
mysql> source database/schema.sql;
mysql> source database/seed.sql;

Step 2: Compile & Package via Maven

# Clean and compile war package (skips unit tests for quick packaging)
mvn clean package -DskipTests

Step 3: Deploy to Apache Tomcat

# Copy generated WAR to Tomcat webapps directory
cp target/fraudguard.war $CATALINA_HOME/webapps/

# Start Tomcat server
$CATALINA_HOME/bin/startup.sh   # Linux/macOS
$CATALINA_HOME\bin\catalina.bat run   # Windows

Navigate to http://localhost:8080/fraudguard/ to access the system.

3. Portal User Guides

FraudGuard features dedicated, role-tailored interfaces:

Customer Portal

Designed for end-users to send funds, monitor real-time wallet balances, review transaction status, and acknowledge security alerts.

Executive & Analyst Portal

Designed for fraud analysts and security officers to inspect global transaction streams, evaluate rule trigger breakdowns, and resolve alerts.

Default System Credentials (Testing)

RoleUsernamePasswordPrivileges
ADMIN admin Admin@123 Full Executive Dashboard, User Accounts, Rule Configuration
ANALYST analyst Analyst@123 Transaction Monitor, Fraud Alerts Triage, Incident Notes
CUSTOMER user User@123 Send Funds, Wallet Balance, Personal History, Alert Feedback

4. Fraud Rules Specification

The detection engine orchestrates 7 autonomous heuristic rules implementing the Strategy Pattern. Each rule evaluates the transaction independently:

Rule Name Trigger Heuristic Weight Risk Impact Automated Action
BlacklistAccountRule Target account exists in sanctions/fraud ring registry +100 CRITICAL Immediate Transaction Block & Incident Alert
HighAmountRule Amount > ₹50,000 or exceeds 300% historical baseline +35 HIGH Flagged for Analyst Triage / Secondary Review
VelocityRule > 3 transactions from same account in sliding 5-min window +40 HIGH Velocity Throttle & Notification Dispatch
GeographicAnomalyRule Distance between subsequent locations implies speed > 800 km/h +50 HIGH Session Freeze & Out-of-Band Verification
UnusualHourRule Transfer executed between 01:00 AM and 05:00 AM local time +20 MEDIUM Telemetry Tag & Elevated Scrutiny
NewDeviceRule Hardware hash / user-agent not recorded in account history +25 MEDIUM Device Confirmation Challenge
RapidBalanceDrainRule Single transfer withdraws > 80% of current available balance +45 CRITICAL Hold on Funds & Critical Alert Generation

Composite Risk Scoring Formula

The total risk score is calculated via the formula:

Score = Min(100, Sum(Evaluations[i].Weight * Evaluations[i].SeverityFactor))

If any rule triggers a critical hard-block condition (such as BlacklistAccountRule), the score instantly saturates at 100.

5. REST API & Payload Specification

FraudGuard provides REST-compatible servlet endpoints for automated transaction intake and scoring.

Endpoint: Initiate Transaction

POST /transaction

Headers

Content-Type: application/x-www-form-urlencoded
Cookie: JSESSIONID=...

Form Parameters

ParameterTypeRequiredDescription
amountDecimalYesTransaction amount (e.g., 1500.00)
recipientAccountStringYesTarget IBAN or account identifier
locationStringNoOriginating city or geo-coordinates
deviceFingerprintStringNoClient hardware / browser canvas hash

Sample JSON Response (Result Object)

{
  "status": "FLAGGED",
  "transactionRef": "TXN-8F92A14D",
  "amount": 7500.00,
  "riskScore": 75,
  "riskLevel": "HIGH",
  "triggeredRules": [
    "HighAmountRule (+35)",
    "VelocityRule (+40)"
  ],
  "requiresAnalystReview": true,
  "timestamp": "2026-10-05T18:30:00Z"
}

6. Security & Privacy Model

Data Privacy Guarantee: Zero personal email addresses, student IDs, or sensitive customer PII are ever exposed in client-facing HTML views, network responses, or client payloads.
  • Cryptographic Password Salting: Passwords hashed with PBKDF2 / SHA-256 with cryptographically secure salts.
  • SQL Injection Immunity: 100% of database queries use JDBC PreparedStatement with strict parameter binding.
  • Session & Cookie Protection: HttpOnly cookies preventing cross-site scripting token theft, session rotation upon login.
  • HTTP Defense Headers: X-Content-Type-Options: nosniff, X-Frame-Options: DENY, and X-XSS-Protection injected on all responses.

7. Troubleshooting & FAQ

Q: Why does my transaction score 100 immediately?

The recipient account matches a blacklisted entity or sanction list in BlacklistAccountRule. Switch to a standard test recipient account to test lower risk tiers.

Q: How do I switch themes?

Use the celestial theme toggle switch in the top-right navigation bar to switch seamlessly between Obsidian Dark Mode and Refined Ivory Light Mode.

8. TeamRootOps Engineering Credits

FraudGuard was engineered as a core security research initiative by TeamRootOps at the School of Computing Science and Engineering (SCSE), Galgotias University.

Rohan Rastogi — Team Leader • Lead System Architect, Core Java Engine, Database & Frontend Engineer
Anant Kumar
Kumar Arya
Rohan Tevatia