Detection and Mitigation of Suspicious Voucher Changes
By automatically detecting the pattern of voucher changes and triggering mitigation measures, we solve the security threats of front-line employees when managing vouchers, and achieve effective monitoring and protection of voucher changes.
Patent Information
- Application Number
- CN201980054625.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2018-08-21
- Filing Date
- 2019-06-28
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2039-06-28
AI Technical Summary
Frontline employees are vulnerable to threats from malicious managers or attackers when managing credentials due to non-technical and lack of supervision, resulting in illegal access or tampering with the credentials.
The detection component automatically analyzes the data of the credentials, compares it with known suspicious credentials change patterns, marks suspicious credentials changes, and triggers mitigation actions such as notifying, pausing administrative privileges, or monitoring credential administrator activities.
Effectively detect and mitigate suspicious credential changes, reduce the risk of illegal access and tampering, and protect the security of user data.
Smart Images

Figure CN112585632B_ABST
Abstract
Description
Background Art
[0001] Frontline employees are the first point of contact between a company and the outside world. These are the people who typically do not sit behind a computer all day, but rather work, for example, on the store floor, in a clinic, or on the phone. In this role, such employees typically engage customers first and represent the company and its brand. Although not sitting behind a computer all day, frontline employees may also need access to certain productivity applications. However, frontline employees are typically non-technical and cannot contact an on-site information technology administrator. Instead of a dedicated information technology administrator, the manager of the frontline employee, or some other authority figure, may be given additional credential responsibilities. For example, a frontline employee contacts the store manager to obtain credentials such as a username and password or a smart card. Summary of the Invention
[0002] The following presents a simplified summary of the invention to provide a basic understanding of some aspects of the disclosed technical solution. This summary is not an extensive overview. It is not intended to identify the main / critical elements or to delineate the scope of the claimed technical solution. Its sole purpose is to present some concepts in a simplified form as a prelude to the more detailed description that will be presented later.
[0003] Briefly described, the present disclosure relates to the detection and mitigation of suspicious credential changes. Data surrounding a credential change on a user account can be collected and automatically compared to a set of suspicious credential change patterns. If the data surrounding the credential change matches one of the suspicious credential change patterns in the set of suspicious credential change patterns, the credential change can be flagged as suspicious. In response to the credential change being flagged as suspicious, one or more mitigation actions can be triggered to mitigate the adverse effects of the suspicious credential change. The mitigation actions can include, in particular, notification, suspension of suspicious administrative privileges, and initiation of monitoring of credential administrator activities.
[0004] To achieve the foregoing and related purposes, certain illustrative aspects of the claimed technical solution are described herein in connection with the following description and the accompanying drawings. These aspects indicate various ways in which the technical solution can be practiced, all of which are intended to be within the scope of the disclosed technical solution. Other advantages and novel features may become apparent from the following detailed description when considered in conjunction with the drawings. Brief Description of the Drawings
[0005] Figure 1 is a schematic block diagram of a credential change management system.
[0006] Figure 2 is a schematic block diagram of a detection component.
[0007] Figure 3 is a schematic block diagram of a mitigation component.
[0008] Figure 4 It is a flowchart of a method for voucher change management.
[0009] Figure 5 It is a flowchart of a method for detecting suspicious voucher changes.
[0010] Figure 6 It is a flowchart of a method for detecting suspicious voucher changes.
[0011] Figure 7 It is a flowchart of a method for detecting suspicious voucher changes.
[0012] Figure 8 It is a flowchart of a method for detecting suspicious voucher changes.
[0013] Figure 9 It is a flowchart of a method for detecting suspicious voucher changes.
[0014] Figure 10 It is a schematic block diagram illustrating a suitable operating environment for aspects of the present disclosure. Detailed Description
[0015] For decades, threats associated with voucher setup and reset have been analyzed relative to information technology administrators. In the case of information technology administrators, a significant level of scrutiny is performed, they are central, and are supervised. In the scenario of frontline employees, the individuals responsible for voucher management are non-technical, numerous, and receive minimal supervision. Thus, delegating voucher management to store managers or other authority figures exposes new threats. These threats can come from malicious managers or attackers who have gained control of the manager's vouchers.
[0016] By way of example, assume that Bob is a manager and voucher administrator at a retail store, and Alice is an employee. If Bob has malicious intent, Bob can reset and record Alice's username and password, and use these to check her emails and log into Alice's shift information. If instead of username and password, a phone number and text code are used, Bob can set his own phone number on Alice's account to access her data. Bob can then change the phone number back to Alice's number, in which case, Alice may never know that Bob was temporarily able to access her data.
[0017] Conventional solutions are to limit the number of people with voucher roles, and not give this role to untrusted individuals. However, such solutions defeat the purpose of the model that authorizes authority figures to perform such actions on behalf of employees.
[0018] This description relates to the detection and mitigation of suspect credential changes. Credential changes and the data surrounding the credential changes can be captured and compared against patterns of suspect credential changes. If a match is detected, the credential change can be flagged as suspect. In response to the detected suspect credential change, one or more mitigation countermeasures can be triggered. In a simple response, the suspect change can be reported to an authority / supervisor. The credential management role of the user account associated with the change can also be suspended or a significant amount of logging can be initiated, in particular.
[0019] Aspects of the present disclosure are now described in more detail with reference to the accompanying drawings, in which like reference numerals generally refer to like or corresponding elements throughout. It should be understood, however, that the drawings and the detailed description thereof are not intended to limit the claimed technology to the disclosed form. On the contrary, the intention is to cover all modifications, equivalents, and alternatives falling within the spirit and scope of the claimed technology.
[0020] Referring first to Figure 1 , a credential change management system 100 is illustrated. A credential is a piece of data used to prove a user's identity. Generally, a credential can be something the user knows, something the user has, or something the user is. For example, a credential can correspond to a username, password, phone number, smart card, hardware token, or fingerprint, among others. The system 100 receives data surrounding a credential change. For example, a user's password or phone number can be changed. The credential change can be made by a credential administrator or by an attacker who has control of the credential of the credential administrator. A credential administrator is not an information technology administrator, but a non-technical authority among frontline employees. By way of example and not limitation, a credential administrator can be a retail store manager with several employees to whom the manager assigns credentials. The system 100 analyzes the received data or information surrounding the credential change and outputs a response. The response can be a category, recommendation, report, or triggered action. Additionally, the system 100 can operate in substantially real-time or subsequently offline (e.g., post-event).
[0021] The system 100 includes a detection component 110 and a mitigation component 120. The detection component 110 provides means for detecting suspect credential changes. The detection component 110 analyzes credential change information and detects suspect credential changes based on known patterns of suspect credential changes. The mitigation component 120 provides means for mitigating the adverse effects associated with suspect credential changes. For example, the mitigation component 120 can report the detection, initiate further logging of actions against the credential administrator, or suspend the capabilities or privileges of the credential administrator.
[0022] Turning attention to Figure 2, the detection component 110 is depicted in more detail. The detection component 110 includes a matching component 210, a change pattern 220, a configuration component 230, and a learning component 240. The matching component 220 uses known suspicious change patterns 220 to seek the detection of suspicious credential changes. More specifically, the matching component 210 can seek to match the received data surrounding the credential change with known suspicious change patterns. The change pattern 220 can be manually input using the configuration component 230 or automatically specified by the learning component 240. The configuration component 230 provides means for a user to specify suspicious change patterns and control when a match exists under a given change pattern 220. For example, the user can specify the degree of pattern matching (e.g., a given percentage, features...). Additionally, the configuration component 230 can enable the setting of change pattern parameters such as the threshold number or the number of identical credentials. The learning component 240 can acquire known suspicious patterns and seek to learn new patterns or variants of existing patterns that can be used in the matching. Various known and novel statistical analysis and artificial intelligence techniques can be adopted by the learning component 240 to infer suspicious change patterns.
[0023] Following are some exemplary suspicious change patterns that can be encoded and exploited by the matching component 210. Of course, other suspicious change patterns indicating statistically abnormal or suspicious actions are possible. First, the change pattern can be cyclic on a given user merchant. For example, credential "A" is changed to credential "B", and then changed back to credential "A". This round-trip exposes the user account to malicious activities and may be difficult for the user to detect. The second change pattern is frequent credential changes on the same account at a predetermined time. For example, if the password, username, etc. are changed more than once on the same user account within two months, this pattern can be matched. The third pattern can involve an attempt to set credentials on an account where the credentials cannot be enabled. For example, a rogue credential administrator may attempt to configure their own phone number on an executive user's account to log into the account, but the executive has not enabled that login method. The fourth pattern can be an attempt to set the same credentials on more than one account within the same organization. For example, if the same phone number or the same password is configured on a predetermined number of accounts, this pattern is met. The fifth pattern can be an attempt to set the same credentials on more than one account in different organizations. It is common to hold two jobs, and thus a user may have the same credentials. However, it is highly unlikely to hold five or more jobs, and it is a sign of potential abuse. This pattern enables abuse or malware at the platform level to be captured compared to abuse by rogue agents within an organization. The sixth pattern involves an attempt to update credentials that have not been confirmed or enabled by the end user. For example, a rogue administrator may set their own login number on a victim account and then reset the login number back to the original login number to hide their actions. If the user does not verify the change of the number, this may be considered suspicious according to the sixth pattern.
[0024] Reference Figure 3, further details the mitigation component 120. As mentioned above, the mitigation component 120 mitigates the adverse effects associated with a suspected credential change. The mitigation component 120 includes a notification component 310, a suspension component 320, a logging component 330, and a policy component 340. The notification component 310 is configured to provide notifications to end users as well as information technology administrators or other persons related to the suspected credential change. The notifications can be provided in various media, especially including emails and text messages. The suspension component 320 enables the credential administrator role to be suspended without suspending the user account. In other words, if the credential administrator is associated with a suspected credential change, the user account can still operate, but the management of credentials is suspended. The logging component 330 can be activated to perform additional logging associated with activities or the credential administrator to support a detailed analysis of the credential administrator's actions. The policy component 340 enables the specification of mitigation policies or a set of policies. For example, the policy can indicate that notifications will be provided and detailed logging will be enabled when a suspected credential change is detected. Alternatively, the policy can indicate that the credential role will be immediately suspended.
[0025] The notification component can provide notifications to end users, who can be potential victims. In one instance, when a user's credentials are changed, the user can be notified. According to one implementation, the end user is a frontline employee with passwordless credentials. More specifically, the end user can log in using his / her phone number or email and receive a one-time code to their email or phone number. In this case, the notification can be sent to the old / previous phone number or email. For example, when the login phone number for an employee is changed, a text message can be sent to the new number and the employee is required to take action to enable that number to be used as a login for their account. Additionally, a text message can be sent to the old number to notify the employee that the number can no longer be used as a login for his / her account.
[0026] In addition to end users, the notification component 310 can enable notifications to be provided to information technology administrators, managers, fraud prevention service centers, or other authorities. When a credential change is detected as suspected, the user account used to make the change (presumably owned by the credential administrator), the authentication method used by this person, device information, network, location, and timestamp can be logged. The logged information, or a subset thereof, can be presented to the authorities. In one implementation, a report can be generated and a notification can be provided to the authorities.
[0027] According to one embodiment, the notification may include a trigger for further action. In other words, instead of merely receiving a message indicating that there has been a suspicious credential change, the ability to take action is provided. For example, a text message or an email may include a link or a button to suspend the ability of the credential authority to manage credentials, or to initiate monitoring of the user account from which the suspicious credential change was performed.
[0028] The above-described systems, architectures, environments, etc. have been described with reference to the interactions between several components. It should be understood that such systems and components may include those components or sub-components specified therein, some of the specified components or sub-components, and / or additional components. A sub-component may also be implemented as a component communicatively coupled to other components rather than being included within a parent component. Additionally, one or more components and / or sub-components may be combined into a single component to provide aggregated functionality. Communication between systems, components, and / or sub-components may be implemented according to a push model and / or a pull model. Components may also interact with one or more components that are not described in detail herein for the sake of brevity but are known to those skilled in the art.
[0029] Furthermore, various parts of the systems disclosed above and the methods below may include or employ statistical analysis, artificial intelligence, machine learning, or knowledge- or rule-based components, sub-components, processes, devices, methods, or mechanisms (e.g., support vector machines, neural networks, expert systems, Bayesian belief networks, fuzzy logic, data fusion engines, classifiers...). Such components can in particular automate certain mechanisms or processes being performed to make parts of the systems and methods more adaptable as well as efficient and intelligent. By way of example and not limitation, the foregoing techniques may be employed by one or both of the detection component 110 and the mitigation component 120 to infer suspicious credential change patterns and recommend responses based on detected suspicious credential changes. More specifically, the detection component 110 may employ supervised learning or unsupervised learning regarding the classification of a credential change as suspicious or not suspicious. Additionally, patterns may be learned based on the type of user, organization, or industry making the change. In this way, a profile of what is expected can be created, and anomaly detection can be performed based on what is expected.
[0030] In view of the exemplary systems described above, methods that may be implemented according to the disclosed technical solutions will be described with reference to Figures 4 - 9The flowchart can be better understood. Although, for the purpose of simplifying the explanation, the method is shown and described as a series of boxes, it should be understood and appreciated that the described technical solution is not limited by the order of the boxes, as some boxes may occur in a different order and / or concurrently with other boxes depicted and described herein. In addition, not all of the illustrated boxes may be required to implement the method described below. Further, each box or combination of boxes can be implemented by computer program instructions, which can be provided to a processor to generate a machine, such that the instructions executed on the processor create means for implementing the functions specified by the flowchart boxes.
[0031] Figure 4 A method 400 for voucher change management is illustrated. At reference numeral 410, a suspicious voucher is automatically detected, inferred, or otherwise identified. After a voucher change, such as made by a voucher administrator, information about the change can be analyzed to determine whether the change should be classified as suspicious. According to one embodiment, the information about the change can be compared with known patterns such that a match or similarity can be considered a suspicious change. At reference numeral 410, mitigation is initiated to reduce the potential negative impact of the suspicious voucher change. According to one embodiment, a notification can be sent to end users whose accounts may have been compromised, a superior of the voucher administrator (e.g., an information technology administrator, a fraud prevention department, a manager...), or both. In another embodiment, extensive monitoring of the actions of the voucher administrator associated with the suspicious change can be triggered. In yet another embodiment, the voucher management capabilities or roles can be suspended such that user accounts with such privileges can no longer manage vouchers. Further, the notification can include a mechanism for triggering mitigation actions, or user policies can be specified and adopted to automatically initiate mitigation actions.
[0032] Figure 5 A method 500 for detecting suspicious voucher changes is depicted. At reference numeral 510, a change from a first voucher to a second voucher is identified. For example, in a passwordless system, a change in password or a change in phone number can be detected. At reference numeral 520, a change from the second voucher to the first voucher is identified. For example, the password may have changed from "1234" to "5678" and then changed back to "1234". At reference numeral 530, the voucher change is labeled or flagged as suspicious. This cyclic pattern is highly suspicious and difficult for potential victims to detect.
[0033] Figure 6It is a flowchart of method 600 for detecting suspicious credential changes. At reference label 610, a first credential change is identified. At reference label 620, a second credential change is identified. In other words, the same credential has been changed twice. At label 630, a determination is made as to whether the change from the first credential to the second credential occurred within a threshold time. The threshold time is configurable. For example, the threshold time can be set to two months or two days. If the first credential change and the second credential change did not occur within the threshold time ("No"), the method can simply terminate. If the first credential change and the second credential change occurred within the threshold time ("Yes"), the method continues at 640, where the credential change is marked as suspicious. A rather rapid change of the credential may be suspicious. According to one embodiment, method 600 may also require a successful login with the first credential and then a change to the second credential to classify the change as suspicious.
[0034] Figure 7 It illustrates a flowchart of method 700 for detecting suspicious credential changes. The method 700 described below can be applied at the organizational level or across different organizations. At reference label 710, a change from a first credential to a second credential is identified. For example, the password can be changed from "1234" to "5678". At label 720, a determination is made as to whether there are any other credentials that match the second credential. In other words, is there any other password that is "5678"? If there are no matching credentials ("No"), the method terminates. If there are matching credentials ("Yes"), the method continues at 730. At reference label 730, the number of matching credentials is determined. Next, at 740, a determination is made as to whether the number of matching credentials is greater than a predetermined threshold. If the number of matching credentials is less than or equal to the threshold ("No"), the method terminates. If the number of matching credentials is greater than the threshold ("Yes"), the method continues at 750, where the credential change is marked or flagged as suspicious. It is possible that a user has two jobs and uses the same username and / or password. Therefore, if the threshold number is two or less, it may not be suspicious. However, if five accounts are set up with the same username and / or password, this is likely to be a potential abuse or malicious flag.
[0035] Figure 8is a flowchart depicting a method 800 for detecting suspicious credential changes. At reference numeral 810, a first credential change is identified. At label 820, the credential for the credential administrator making the credential change is determined. At label 830, a determination is made as to whether the changed credential matches the credential of the credential administrator. If the changed credential does not match the administrator's credential ("no"), the method terminates. If the changed credential matches the administrator's credential ("yes"), the method continues at 840, where the credential change is flagged as suspicious. In this way, an administrator setting their own credential on another account can be considered suspicious.
[0036] Figure 9 is a flowchart illustrating a method for detecting suspicious credential changes. At reference numeral 910, an attempt to set a credential is detected. For example, an attempt to set a phone number as a credential on a user account may be made. At label 920, a determination is made as to whether the type of credential being attempted to be set is enabled on the target user account. In other words, the determination relates to whether the user account has been configured to accept a particular type of credential for authentication purposes. If the credential is enabled ("yes"), the method terminates. On the other hand, if the credential is not enabled for the user account ("no"), the method continues at 930. At reference numeral 930, the potential credential change is flagged as suspicious. By way of example, a rogue credential administrator may attempt to configure their own phone number on an executive's user account to log into the account. However, the executive's account may not be enabled for that login method, which would be suspicious.
[0037] Aspects of the present disclosure relate to technical issues of credential security. Technical mechanisms are utilized to detect and mitigate suspicious credential changes. Credential changes can be compared to known or learned patterns of suspicious changes to automatically detect or infer suspicious credential changes. Once detected, one or more mitigation countermeasures can be triggered based on the suspicious change. For example, a notification can be sent, monitoring of the user account can be initiated, or the credential management capabilities of the user account can be suspended.
[0038] The present disclosure supports various products and processes that perform or are configured to perform various actions regarding suspicious credential changes and mitigation. Following are one or more exemplary systems and methods.
[0039] A system includes: a processor coupled to a memory, the processor being configured to execute computer-executable instructions stored in the memory, the computer-executable instructions, when executed, causing the processor to perform the following actions: receive data regarding a change in user credentials; detect a suspicious credentials change based on the data and a set of one or more suspicious change patterns; and initiate mitigation of the suspicious credentials change. In a first instance, the suspicious change pattern includes a cyclic pattern in which a first credential is changed to a second credential and changed back to the first credential. In a second instance, the suspicious change pattern includes multiple changes within a predetermined time. In a third instance, the suspicious change pattern includes setting the same credentials on more than one account. In a fourth instance, the suspicious change pattern includes an attempt to set credentials on an account where the account is disabled for the credentials being attempted to be set. In a fifth instance, the suspicious change pattern includes an attempt to update credentials not verified by an end user. The mitigation also includes only suspending the ability of a credentials administrator to manage credentials. The mitigation may also include generating a notification of the suspicious credentials change with a trigger that, when activated, performs an action regarding the credentials administrator. The system also includes performing automatic mitigation based on a configurable policy.
[0040] A method includes: employing at least one processor configured to execute computer-executable instructions stored in a memory, the computer-executable instructions, when executed, causing the at least one processor to perform the following actions: receive data regarding a change in user credentials; automatically detect a suspicious credentials change based on the data and a set of one or more suspicious change patterns; and initiate mitigation of the suspicious credentials change. The method also includes detecting a suspicious credentials change based on a suspicious change pattern specifying a cyclic pattern in which a first credential is changed to a second credential and changed back to the first credential. The method also includes detecting a suspicious credentials change based on a suspicious change pattern specifying multiple changes within a predetermined time. The method also includes detecting a suspicious credentials change based on a suspicious change pattern specifying that the same credentials are set on multiple accounts. Initiating the mitigation also includes only suspending the credentials management ability of a credentials administrator account to make user credentials changes. In another instance, initiating the mitigation also includes generating a notification with a mechanism configured to trigger a specific mitigation activity. The method also includes automatically initiating mitigation in response to a configurable mitigation policy.
[0041] A credential management method includes: using at least one processor configured to execute computer-executable instructions stored in a memory, the computer-executable instructions when executed causing the at least one processor to perform the following actions: automatically detecting a suspicious credential change by comparing data associated with a credential change for a user account with a set of one or more suspicious change patterns, wherein a match between the data and one of the set of one or more suspicious change patterns indicates a suspicious credential change; and after detecting a suspicious credential change, initiating an automatic mitigation of the suspicious credential change. The method further includes matching data associated with the credential change with a suspicious change pattern that includes a cyclic pattern in which a first credential is changed to a second credential and then changed back to the first credential. The method further includes matching data associated with the credential change with a suspicious change pattern that includes multiple changes within a predetermined time. The automatic mitigation further includes generating a notification with a mechanism to trigger one of the following: suspending the credential management privileges of a credential administrator responsible for making the credential change, or enabling extensive logging of the activities of the credential administrator.
[0042] As used herein, the terms "component" and "system" and their various forms (e.g., multiple components, multiple systems, subsystems...) are intended to refer to a computer-related entity, or hardware, a combination of hardware and software, software, or software in execution. For example, a component can be, but is not limited to, a process running on a processor, a processor, an object, an instance, an executable, a thread of execution, a program, and / or a computer. By way of illustration, both an application running on a computer and the computer can be components. One or more components can reside within a process and / or a thread of execution, and a component can be located on one computer and / or distributed between two or more computers.
[0043] Unless otherwise specified or clear from the context, as used in this specification and the appended claims, the conjunction "or" is intended to mean an inclusive "or" rather than an exclusive "or". In other words, "‘X’ or ‘Y’" is intended to mean any inclusive arrangement of "X" and "Y". For example, if "‘A’ employs ‘X’", "‘A’ employs ‘Y’", or "‘A’ employs both ‘X’ and ‘Y’", then in any of the foregoing instances, "‘A’ employs ‘X’ or ‘Y’" is satisfied.
[0044] In addition, to the extent that the terms "comprising", "including", "having", "has" or variations of such forms are used in the detailed description or claims, such terms are intended to be inclusive in a manner similar to the term "comprising" as it is interpreted when used as a transitional word in a claim.
[0045] To provide context for the disclosed technology, Figure 10 and the following discussion is intended to provide a brief, general description of a suitable environment in which aspects of the disclosed technology may be implemented. However, the suitable environment is only an example and is not intended to imply any limitation as to the scope of use or functionality.
[0046] While the systems and methods disclosed above may be described in the general context of computer-executable instructions of a program running on one or more computers, those skilled in the art will recognize that aspects may also be implemented in conjunction with other program modules and the like. Generally, program modules include routines, programs, components, data structures, etc. that perform particular tasks and / or implement particular abstract data types. In addition, those skilled in the art will understand that the above systems and methods may be practiced in a variety of computer system configurations, including: single-processor, multi-processor or multi-core processor computing systems, microcomputing devices, mainframe computers, and personal computers, handheld computing devices (e.g., personal digital assistants (PDAs), smart phones, tablet computers, watches...), microprocessor-based or programmable consumer or industrial electronics, etc. Aspects may also be practiced in a distributed computing environment where tasks are performed by remote processing devices linked through a communication network. However, some (if not all) aspects of the disclosed technology may be practiced on a stand-alone computer. In a distributed computing environment, program modules may be located in one or both of local and remote memory devices.
[0047] Referring Figure 10 , illustrated is an example general-purpose computer or computing device 1002 (e.g., desktop computer, laptop computer, tablet computer, watch, server, handheld, programmable consumer or industrial electronics, set-top box, gaming system, computing node...). Computer 1002 includes one or more processors 1020, a memory 1030, a system bus 1040, (one or more) mass storage devices 1050, and one or more interface components 1070. The system bus 1040 communicatively couples at least one of the above system components. However, it should be understood that in its most simplified form, computer 1002 may include one or more processors 1020 coupled to a memory 1030 that execute various computer-executable actions, instructions, and / or components stored in the memory 1030.
[0048] (A) processor(s) 1020 can be implemented with the following items designed to perform the functions described herein: general-purpose processor, digital signal processor (DSP), application specific integrated circuit (ASIC), field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware component, or any combination thereof. A general-purpose processor may be a microprocessor, but in the alternative, the processor may be any processor, controller, microprocessor, or state machine. (A) processor(s) 1020 can also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, multi-core processors, one or more microprocessors in conjunction with DSP cores, or any other such configuration. In one embodiment, (A) processor(s) 1020 can be a graphics processor.
[0049] Computer 1002 can include various computer-readable media, or otherwise interact with various computer-readable media to support the control of computer 1002 to implement one or more aspects of the disclosed technical solutions. Computer-readable media can be any available media that can be accessed by computer 1002, and includes volatile and non-volatile media, as well as removable and non-removable media. Computer-readable media can include two distinct and mutually exclusive types, namely computer storage media and communication media.
[0050] Computer storage media includes volatile and non-volatile, removable and non-removable media implemented with any method or technology for information storage, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes storage devices, such as memory devices (e.g., random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM) …), magnetic storage devices (e.g., hard disk, floppy disk, cassette tape, magnetic tape …), optical disks (e.g., compact disk (CD), digital versatile disk (DVD) …), and solid state devices (e.g., solid state drive (SSD), flash drive (e.g., card, stick, key drive …) …), or any other similar media, which stores the desired information accessible by computer 1002 as opposed to being transmitted or conveyed. Thus, computer storage media does not include modulated data signals, as described with reference to communication media.
[0051] A communication medium implements computer-readable instructions, data structures, program modules, or other data in a modulated data signal, such as a carrier wave or other transmission mechanism, and includes any information delivery medium. The term "modulated data signal" means a signal in which one or more of the characteristics of the signal are set or changed in such a way as to encode information in the signal. By way of example and not limitation, communication media include wired media such as a wired network or direct-wired connection, and wireless media such as acoustic, RF, infrared, and other wireless media.
[0052] Memory 1030 and mass storage device(s) 1050 are examples of computer-readable storage media. Depending on the exact configuration and type of computing device, memory 1030 can be volatile (e.g., RAM), non-volatile (e.g., ROM, flash memory...), or some combination of the two. By way of example, a basic input / output system (BIOS), which includes basic routines to transfer information between elements within computer 1002, such as during start-up, can be stored in non-volatile memory, and volatile memory can be used as an external cache memory to support processing by processor(s) 1020, etc.
[0053] Mass storage device(s) 1050 include removable / non-removable, volatile / non-volatile computer storage media for the storage of large amounts of data relative to memory 1030. For example, mass storage device(s) 1050 include, but are not limited to, one or more devices such as a magnetic or optical disk drive, a floppy disk drive, a flash memory, a solid state drive, or a memory stick.
[0054] Memory 1030 and mass storage device(s) 1050 may include or have stored therein an operating system 1060, one or more applications 1062, one or more program modules 1064, and data 1066. The operating system 1060 acts to control and allocate the resources of computer 1002. The applications 1062 include one or both of system and application software, and can utilize the management of resources by the operating system 1060 through program modules 1064 stored in memory 1030 and / or mass storage device(s) 1050 to perform one or more actions. Thus, the applications 1062 can transform the general-purpose computer 1002 into a specialized machine according to the logic they provide.
[0055] All or part of the disclosed technology solutions can be implemented using standard programming and / or engineering techniques to produce software, firmware, hardware, or any combination thereof to control a computer to implement the disclosed functions. By way of example and not limitation, the credential change management system 100, or other parts thereof, can be an application 1062, or form part of the application 1062, and include one or more modules 1064 and data 1066 stored in the memory and / or (multiple) mass storage devices 1050, the functions of which can be implemented when executed by one or more (multiple) processors 1020.
[0056] According to a particular embodiment, the (multiple) processors 1020 can correspond to a system-on-chip (SOC) or a similar architecture that includes, or in other words integrates, both hardware and software on a single integrated circuit substrate. Here, the (multiple) processors 1020 can include at least one or more processors and memories, etc., similar to the (multiple) processors 1020 and the memory 1030. Conventional processors include a minimal amount of hardware and software and rely heavily on external hardware and software. In contrast, the SOC implementation of a processor is more powerful because it embeds hardware and software therein, enabling specific functions with minimal or no dependence on external hardware and software. For example, the credential change management system 100 and / or the functions associated therewith can be embedded in the hardware within the SOC architecture.
[0057] The computer 1002 also includes one or more interface components 1070 that are communicatively coupled to the system bus 1040 and support interaction with the computer 1002. By way of example, the interface components 1070 can be ports (e.g., serial, parallel, PCMCIA, USB, FireWire...) or interface cards (e.g., sound, video...), etc. In one example implementation, the interface components 1070 can be implemented as a user input / output interface to enable a user to input commands and information into the computer 1002, for example, by way of one or more gesture or voice inputs, through one or more input devices (e.g., a pointing device such as a mouse, a trackball, a stylus, a touchpad, a keyboard, a microphone, a joystick, a gamepad, a satellite dish, a scanner, a camera, other computers...). In another example implementation, the interface components 1070 can be implemented as an output peripheral interface to supply output to a display (e.g., LCD, LED, plasma, organic light-emitting diode display (OLED)...), a speaker, a printer, and / or other computers, etc. Further, the interface components 1070 can be implemented as a network interface to enable communication with other computing devices (not shown), such as via a wired or wireless communication link.
[0058] The foregoing description includes examples of aspects of the claimed technology. Of course, for purposes of describing the claimed technology, it is not possible to describe every conceivable combination of components or methods, but one of ordinary skill in the art will recognize that many additional combinations and permutations of the disclosed technology are possible. Accordingly, the disclosed technology is intended to embrace all such alternatives, modifications, and variations that fall within the spirit and scope of the appended claims.
Claims
1. A system, comprising: one or more processors; and one or more computer-readable hardware storage devices storing instructions that can be executed by the one or more processors to cause the system to at least: receive data regarding a change in user credentials; automatically detect a suspicious credential change by seeking to match the received data regarding the change in user credentials with a known suspicious change pattern among the one or more known suspicious change patterns based on a user-specified pattern matching degree; and initiate mitigation of the suspicious credential change, wherein mitigation of the suspicious credential change includes: in response to determining that a credential administrator account is associated with the suspicious credential change, only suspending the ability of the credential administrator account to manage credentials while allowing the user account functions associated with the credential administrator account to continue uninterrupted, the credential administrator account initially being provided with the ability to manage the credentials including changing the credentials.
2. The system according to claim 1, wherein the suspicious credential change pattern includes a cyclic pattern in which a first credential is changed to a second credential and then changed back to the first credential.
3. The system according to claim 1, wherein the suspicious change pattern includes multiple credential changes to the same account within a predetermined time.
4. The system according to claim 1, wherein the suspicious change pattern includes setting the same credentials on more than one account.
5. The system according to claim 1, wherein the suspicious change pattern includes an attempt to set credentials on an account, where the credentials attempted to be set are prohibited on the account.
6. The system according to claim 1, wherein the suspicious change pattern includes an attempt to update credentials not verified by an end user.
7. The system according to claim 1, wherein the mitigation further includes generating a triggered notification of the suspicious credential change, which when activated, performs an action regarding the credential administrator.
8. The system according to claim 1, further comprising performing automatic mitigation based on a configurable policy.
9. A method, comprising: employing at least one processor configured to execute computer-executable instructions stored in a memory, the instructions when executed by the at least one processor causing the at least one processor to perform the following actions: receive data regarding a change in user credentials; automatically detect a suspicious credential change by seeking to match the received data regarding the change in user credentials with a known suspicious change pattern among the one or more known suspicious change patterns based on a user-specified pattern matching degree; and initiate mitigation of the suspicious credential change, wherein mitigation of the suspicious credential change includes: In response to determining that a credential administrator account is associated with the suspicious credential change, only suspend the ability of the credential administrator account to manage credentials, while allowing the user account functions associated with the credential administrator account to continue uninterrupted, where the credential administrator account is initially provided with the ability to manage the credentials including changing the credentials.
10. The method according to claim 9, further comprising detecting the suspicious credential change based on a suspicious change pattern specifying a cyclic pattern in which a first credential is changed to a second credential and then changed back to the first credential.
11. The method according to claim 9, further comprising detecting the suspicious credential change based on a suspicious change pattern specifying multiple changes within a predetermined time.
12. The method according to claim 9, further comprising detecting the suspicious credential change based on a suspicious change pattern specifying that the same credential is set on multiple accounts.
13. Initiating mitigation according to claim 9 further comprises generating a notification with a mechanism configured to trigger a specific mitigation activity.
14. The method according to claim 9, further comprising automatically initiating mitigation in response to a configurable mitigation policy.
15. A method for credential management, comprising: employing at least one processor configured to execute computer-executable instructions stored in a memory, which when executed cause the at least one processor to perform the following actions: automatically detecting a suspicious credential change by seeking to compare data associated with a credential change for a user account with a known suspicious change pattern among a set of one or more known suspicious change patterns based on a user-specified pattern matching degree, where a match between the data and one of the known suspicious change patterns in the set of one or more known suspicious change patterns indicates the suspicious credential change; and after detecting the suspicious credential change, initiating automatic mitigation of the suspicious credential change, where the automatic mitigation of the suspicious credential change includes: In response to determining that a credential administrator account is associated with the suspicious credential change, only suspend the ability of the credential administrator account to manage credentials, while allowing the user account functions associated with the credential administrator account to continue uninterrupted, where the credential administrator account is initially provided with the ability to manage the credentials including changing the credentials.
16. The method according to claim 15, further comprising matching the data associated with the credential change with a suspicious change pattern, the suspicious credential change pattern including a cyclic pattern in which a first credential is changed to a second credential and then changed back to the first credential.
17. The method according to claim 15, further comprising matching the data associated with the credential change with a suspicious change pattern, the suspicious change pattern including multiple credential changes to the same account within a predetermined time.
18. The method according to claim 15, wherein the automatic mitigation includes generating a notification with a mechanism to trigger one of the following: suspending the credential management privileges of the credential administrator responsible for making the credential change, or enabling extensive logging of the activities of the credential administrator.
Citation Information
Patent Citations
Storage medium and password locking control method, device and equipment
CN107659568A
Credential modification notifications
US20180083986A1