Method and system for adaptively responding to security risks
The system addresses the challenge of adapting to security risks by acquiring and evaluating user authentication risk information and determining a security policy, resulting in enhanced login system security and reduced unauthorized access in a cost-effective manner.
Patent Information
- Application Number
- PCT/KR2024/017021
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-02
- Filing Date
- 2024-11-01
- Publication Date
- 2025-05-08
AI Technical Summary
Existing security systems face challenges in effectively adapting to security risks while maintaining cost-effectiveness, particularly in managing unauthorized access and protecting user accounts and data.
A method and system that acquire risk information related to user authentication, evaluate security risks using a risk detection model, and determine a security policy to be applied based on the evaluation results, thereby enhancing the security of the login system and minimizing unauthorized access in a cost-effective manner.
The system effectively strengthens the security of the login system, reduces the risk of unauthorized access, and protects user accounts and data by adaptively responding to security risks in a cost-effective way.
Smart Images

Figure KR2024017021_08052025_PF_FP_ABST
Abstract
Description
Methods and systems for adaptively responding to security risks
[0001] The present invention relates to a method and system for adaptively responding to security risks.
[0002] As the risk of security breaches due to unauthorized access increases, it is increasingly important for businesses to implement robust security measures to protect users' accounts and sensitive data.
[0003] While it may be best to maintain the highest level of security against all security risks that could cause security breaches in the system, it is difficult to achieve this due to practical issues such as maintenance costs.
[0004] Accordingly, the inventor(s) of the present invention propose a technology that supports adaptive response to security risks in a cost-effective manner.
[0005] <Prior Art Literature>
[0006] Patent Document
[0007] (Patent Document 1) Patent Registration No. 10-0785715 (December 7, 2007)
[0008] The purpose of the present invention is to solve all of the problems of the above-mentioned prior art.
[0009] In addition, another purpose of the present invention is to obtain risk information associated with user authentication in a service providing server that operates a target service, to perform an evaluation on whether there is a security risk related to user authentication using a risk detection model, and to determine a security policy to be applied to user authentication based on the evaluation result.
[0010] In addition, another purpose of the present invention is to strengthen the security of the login system, minimize the risk of unauthorized access, and protect the user's account and data.
[0011] In addition, another object of the present invention is to support adaptive response to security risks in a cost-effective manner.
[0012] A representative configuration of the present invention to achieve the above purpose is as follows.
[0013] According to one aspect of the present invention, a method is provided, comprising: a step of obtaining risk information associated with user authentication in a service providing server operating a target service; a step of performing an evaluation as to whether there is a security risk with respect to the user authentication using a risk detection model; and a step of determining a security policy to be applied to the user authentication based on the evaluation result.
[0014] According to another aspect of the present invention, a system is provided, including a risk information acquisition unit that acquires risk information associated with user authentication in a service providing server that operates a target service, a security risk management unit that performs an evaluation as to whether there is a security risk regarding the user authentication using a risk detection model, and a security policy management unit that determines a security policy to be applied to the user authentication based on the evaluation result.
[0015] In addition, a non-transitory computer-readable recording medium recording another method for implementing the present invention, another system, and a computer program for executing the method are further provided.
[0016] According to the present invention, it is possible to obtain risk information associated with user authentication in a service providing server that operates a target service, perform an evaluation on whether there is a security risk related to user authentication using a risk detection model, and determine a security policy to be applied to user authentication based on the evaluation result.
[0017] In addition, according to the present invention, it is possible to strengthen the security of the login system, minimize the risk of unauthorized access, and protect the user's account and data.
[0018] In addition, according to the present invention, it is possible to support adaptive response to security risks in a cost-effective manner.
[0019] FIG. 1 is a diagram schematically illustrating the configuration of an entire system for adaptively responding to security risks according to one embodiment of the present invention.
[0020] FIG. 2 is a drawing showing in detail the internal configuration of a security risk response system according to one embodiment of the present invention.
[0021] <Explanation of symbols>
[0022] 100: Communications network
[0023] 200: Service Provider Server
[0024] 300: Device
[0025] 200: Security Risk Response System
[0026] 410: Hazard Information Acquisition Unit
[0027] 420: Security Risk Management Department
[0028] 430: Security Policy Management Department
[0029] 440: Communications Department
[0030] 450: Control Unit
[0031] The following detailed description of the present invention refers to the accompanying drawings, which illustrate specific embodiments in which the present invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the present invention. It should be understood that the various embodiments of the present invention, while different from each other, are not necessarily mutually exclusive. For example, specific shapes, structures, and characteristics described herein may be modified and implemented from one embodiment to another without departing from the spirit and scope of the present invention. Furthermore, it should be understood that the positions or arrangements of individual components within each embodiment may also be modified without departing from the spirit and scope of the present invention. Accordingly, the following detailed description is not to be taken in a limiting sense, and the scope of the present invention is to be construed to encompass the scope of the claims and all equivalents thereof. Like reference numerals in the drawings represent the same or similar elements throughout the several aspects.
[0032] Hereinafter, various preferred embodiments of the present invention will be described in detail with reference to the attached drawings so that a person having ordinary skill in the art to which the present invention pertains can easily practice the present invention.
[0033] Composition of the entire system
[0034] FIG. 1 is a diagram schematically illustrating the configuration of an entire system for adaptively responding to security risks according to one embodiment of the present invention.
[0035] As illustrated in FIG. 1, the entire system according to one embodiment of the present invention may include a communication network (100), a service provision server (200), a device (300), and a security risk response system (400).
[0036] First, the communication network (100) according to one embodiment of the present invention can be configured regardless of the communication mode such as wired communication or wireless communication, and can be configured with various communication networks such as a local area network (LAN), a metropolitan area network (MAN), and a wide area network (WAN). Preferably, the communication network (100) referred to herein may be the well-known Internet or the World Wide Web (WWW). However, the communication network (100) is not necessarily limited thereto, and may include at least a portion of a well-known wired or wireless data communication network, a well-known telephone network, or a well-known wired or wireless television communication network.
[0037] For example, the communication network (100) may be a wireless data communication network that implements conventional communication methods such as WiFi communication, WiFi-Direct communication, Long Term Evolution (LTE) communication, 5G communication, Bluetooth communication (including Bluetooth Low Energy (BLE) communication), infrared communication, ultrasonic communication, etc., at least in part. As another example, the communication network (100) may be an optical communication network that implements conventional communication methods such as LiFi (Light Fidelity), etc., at least in part.
[0038] Next, the service providing server (200) according to one embodiment of the present invention may be a server including a function capable of communicating after connecting to a device (300) or a security risk response system (400).
[0039] Next, a device (300) according to one embodiment of the present invention is a digital device that includes a function to communicate after connecting to a service provision server (200) or a security risk response system (400), and any digital device that has a memory means, a microprocessor, and a computing capability, such as a smart phone, a tablet, a smart watch, a smart band, smart glasses, a desktop computer, a notebook computer, a workstation, a PDA, a web pad, a mobile phone, etc., can be adopted as the device (300) according to the present invention.
[0040] In particular, the device (300) may include an application (not shown) that supports a user to receive services from a service providing server (200) or a security risk response system (400). Such an application may be downloaded from the service providing server (200), the security risk response system (400), or an external application distribution server (not shown). Meanwhile, the nature of such an application may be generally similar to the risk information acquisition unit (410), the security risk management unit (420), the security policy management unit (430), the communication unit (440), and the control unit (450) of the security risk response system (400), which will be described later. Here, at least a part of the application may be replaced with a hardware device or firmware device that can perform functions substantially identical to or equivalent thereto, as necessary.
[0041] Next, a security risk response system (400) according to one embodiment of the present invention may perform a function of obtaining risk information associated with user authentication in a service providing server operating a target service, evaluating whether there is a security risk regarding user authentication using a risk detection model, and determining a security policy to be applied to user authentication based on the evaluation result.
[0042] The configuration and function of the security risk response system (400) according to the present invention will be described in detail below.
[0043] Composition of a security risk response system
[0044] Below, the internal configuration and functions of each component of the security risk response system (400) that performs important functions for implementing the present invention will be examined.
[0045] FIG. 2 is a drawing showing in detail the internal configuration of a security risk response system (400) according to one embodiment of the present invention.
[0046] As illustrated in FIG. 2, a security risk response system (400) according to one embodiment of the present invention may be configured to include a risk information acquisition unit (410), a security risk management unit (420), a security policy management unit (430), a communication unit (440), and a control unit (450). According to one embodiment of the present invention, at least some of the risk information acquisition unit (410), the security risk management unit (420), the security policy management unit (430), the communication unit (440), and the control unit (450) may be program modules that communicate with a service provision server (200) or an external system (not shown). These program modules may be included in the security risk response system (400) in the form of an operating system, an application program module, or other program modules, and may be physically stored in various known memory devices. In addition, these program modules may also be stored in a remote memory device capable of communicating with the security risk response system (400). Meanwhile, these program modules include, but are not limited to, routines, subroutines, programs, objects, components, data structures, etc. that perform specific tasks or execute specific abstract data types, as described later in accordance with the present invention.
[0047] Meanwhile, although the security risk response system (400) has been described as above, this description is exemplary, and it is obvious to those skilled in the art that at least some of the components or functions of the security risk response system (400) may be realized within the service providing server (200), device (300), or external server (not shown) or included within an external system (not shown) as needed.
[0048] First, the risk information acquisition unit (410) according to one embodiment of the present invention can perform a function of acquiring risk information associated with user authentication in a service providing server (200) that operates a target service.
[0049] Specifically, according to one embodiment of the present invention, a user who wishes to use a target service, such as a financial service, an SNS service, an e-commerce platform service, etc., through a service providing server (200) may be required to undergo user authentication. The risk information acquisition unit (410) according to one embodiment of the present invention may acquire risk information related to such user authentication and process and / or store the same as necessary. The risk information according to one embodiment of the present invention may include information regarding various events, such as an action that raises suspicion as to whether user authentication is attempted by a genuine (or legitimate) user, a security vulnerability being discovered in user authentication, or an increased risk of password leakage.
[0050] According to one embodiment of the present invention, risk information associated with user authentication on the service providing server (200) operating the target service may be attack information associated with user authentication for a third-party service. Here, according to one embodiment of the present invention, user authentication for a third-party service may refer to user authentication for using a third-party service other than the target service.
[0051] For example, if the target service is a specific e-commerce platform service, it may be assumed that an abnormal increase in failed login attempts is detected in an e-commerce platform service other than the specific e-commerce platform (i.e., a third-party service), i.e., the other e-commerce platform is under attack. In this case, there is a risk that a similar attack may also be applied to the target service, and therefore, the risk information acquisition unit (410) according to one embodiment of the present invention may acquire the detected attack information as risk information associated with user authentication on the service provision server (200).
[0052] For another example, suppose the target service is a financial service in a first country (e.g., domestically), and an anomaly is detected in the login location or pattern for multiple accounts in a banking service (i.e., a third-party service) in a second country (e.g., foreign). In this case, there is a risk that a similar attack may also be applied to the financial service in the first country, i.e., the target service. Therefore, the risk information acquisition unit (410) according to one embodiment of the present invention can acquire the detected attack information as risk information associated with user authentication in the service provision server (200).
[0053] Meanwhile, while the risk information associated with user authentication on the service provision server (200) operating the target service has been described above, the attributes of the third-party service and the target service do not necessarily need to match. For example, the target service may be a financial service that emphasizes security, while the third-party service may be an SNS service that encourages free user participation.
[0054] Meanwhile, the risk information acquisition unit (410) according to one embodiment of the present invention can acquire risk information associated with user authentication in a service provision server (200) that operates a target service for each of a plurality of parameters.
[0055] Specifically, according to one embodiment of the present invention, a parameter may refer to a specific risk type or attack type that is classified or clustered according to predetermined criteria. According to one embodiment of the present invention, these parameters may have values such as a value assigned to at least one account (e.g., a value between 0 and 1), a flag (e.g., 0 or 1), a count number, etc., but are not limited to this format.
[0056] For example, parameters according to one embodiment of the present invention may include:
[0057]
[0058] 1. Abnormal login times: When a user attempts to log in at a time when they do not normally log in.
[0059] 2. Sudden increase in login attempts: Repeated login attempts occur within a short period of time.
[0060] 3. Failed login attempts: If login attempts fail repeatedly.
[0061] 4. Unusual login location: If the user attempts to log in from a location that is significantly different from the usual login area.
[0062] 5. Simultaneous login attempts from multiple locations: If login attempts occur at an unusually high rate from multiple locations.
[0063] 6. Unusual device, browser, or OS changes: If the user attempts to log in from a device that he or she does not normally use.
[0064] 7. Use a VPN or proxy: If you are trying to hide your login location.
[0065] 8. Frequent password changes: If the user changes their password unusually frequently.
[0066] 9. Attempting to log in to multiple accounts: If you repeatedly attempt to log in to multiple accounts on the same device.
[0067] 10. Increased password reset requests: If multiple password reset requests occur within a short period of time.
[0068] 11. Multiple requests to the server: When a single account makes a sudden surge of requests to the server within a short period of time.
[0069] 12. Using weak passwords: When users set passwords that are considered weak, such as those that are too short, easily guessable, or do not contain a combination of uppercase and lowercase letters, numbers, or special characters.
[0070] 13. Leaked Password: If you use a password similar to a password leaked from a third-party service.
[0071]
[0072] However, parameters according to one embodiment of the present invention are not limited to those listed above, and may be variously changed within a range that can achieve the purpose of the present invention.
[0073] In addition, although the risk information and parameters associated with user authentication in the service providing server (200) that operates the target service have been described primarily in relation to a situation in which a login attempt is made, they are not limited thereto, and in some cases, information on the user's behavior while logged in, for example, information on abnormal keyboard / mouse input patterns, etc., may also correspond to such risk information and / or parameters.
[0074] Next, the security risk management unit (420) according to one embodiment of the present invention can perform a function of evaluating whether there is a security risk regarding user authentication in a service provision server (200) that operates a target service using a risk detection model.
[0075] Specifically, when risk information associated with user authentication in a service providing server (200) operating a target service is acquired by a risk information acquisition unit (410) according to an embodiment of the present invention, a security risk management unit (420) according to an embodiment of the present invention may process such risk information using a risk detection model to output at least one of a probability, a vector, a matrix, a logit, and a coordinate associated with whether there is a security risk regarding user authentication. In addition, the security risk management unit (420) according to an embodiment of the present invention may perform an evaluation as to whether there is a security risk regarding user authentication based on such output.
[0076] Here, according to one embodiment of the present invention, the risk detection model may be configured based on an artificial neural network, including an input layer, a hidden layer, and an output layer. Meanwhile, the risk detection model according to the present invention is not necessarily limited to the artificial neural network model described above, and may be modified into a model capable of implementing various learning algorithms included in supervised learning, unsupervised learning, reinforcement learning, or deep learning within the scope that can achieve the purpose of the present invention. As another example, the risk detection model according to one embodiment of the present invention may also be implemented as a rule-based model.
[0077] Meanwhile, according to one embodiment of the present invention, the risk detection model can be customized based on the properties of the service providing server (200) or the properties of the target service provided by the service providing server (200).
[0078] For example, if the target service is a financial service that requires a strong emphasis on security, the risk detection model according to one embodiment of the present invention can be trained and tailored to strictly detect security risks related to user authentication. For another example, if the target service is a social networking service that encourages free user participation, the risk detection model according to one embodiment of the present invention can be trained and tailored to loosely detect security risks related to user authentication.
[0079] By doing this, even if the risk information associated with user authentication is the same, the evaluation result regarding whether there is a security risk regarding user authentication can be made to vary depending on the properties of the target service.
[0080] Meanwhile, the security risk management unit (420) according to one embodiment of the present invention can identify the type of security risk related to user authentication using a risk detection model.
[0081] Specifically, as described above, the security risk management unit (420) according to one embodiment of the present invention may process risk information using a risk detection model to output at least one of a probability, a vector, a matrix, a logit, and a coordinate associated with whether there is a security risk related to user authentication. Furthermore, the security risk management unit (420) according to one embodiment of the present invention may classify or cluster such output into specific security risk types based on predetermined criteria. Here, the criteria used in classifying or clustering the output may be preset or dynamically updated during the learning process.
[0082] In addition, when risk information related to user authentication in a service provision server (200) that operates a target service is acquired for each of a plurality of parameters, the security risk management unit (420) according to one embodiment of the present invention may specify the type of security risk related to user authentication based on the risk information for each of a plurality of parameters.
[0083] Meanwhile, according to one embodiment of the invention, types of security risks may include, but are not limited to, brute force password attacks, phishing attacks, credential stuffing attacks, password spray attacks, etc.
[0084] Next, the security policy management unit (430) according to one embodiment of the present invention can perform a function of determining a security policy to be applied to user authentication in a service provision server (200) that operates a target service based on the evaluation result by the security risk management unit (420) according to one embodiment of the present invention.
[0085] Specifically, the security risk management unit (420) according to one embodiment of the present invention may provide an evaluation result (e.g., score, probability, etc.) regarding whether there is a security risk regarding user authentication or what type of security risk it corresponds to, to the security policy management unit (430) according to one embodiment of the present invention and / or the service provision server (200). In addition, the security policy management unit (430) according to one embodiment of the present invention may determine a security policy to be applied to user authentication based on the evaluation result.
[0086] For example, the security risk management unit (420) according to one embodiment of the present invention may use a risk detection model to calculate a probability (0.7) of whether there is a security risk regarding user authentication or what type of security risk it corresponds to, and provide the probability to the security policy management unit (430) and / or the service provision server (200) according to one embodiment of the present invention. In addition, the security policy management unit (430) according to one embodiment of the present invention may refer to the received probability (0.7) and determine a security policy to be applied to user authentication based on its own judgment criteria.
[0087] Here, according to one embodiment of the present invention, the security policy to be applied to user authentication may be a concept including a security level (e.g., whether to strictly or loosely determine whether the user's behavior is abnormal during user authentication, etc.), how many authentication steps to be configured, whether to perform an additional authentication procedure such as CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart), whether to provide appropriate notifications to the user and / or the service providing server (200), the monitoring speed for a specific attack pattern or parameter, the password policy, the application (or validity) period of the current or to be changed security policy, etc.
[0088] However, the security policy according to one embodiment of the present invention is not limited to those listed above, and may be variously changed within the scope that can achieve the purpose of the present invention.
[0089] More specifically, the security policy management unit (430) according to one embodiment of the present invention may determine a security policy to temporarily strengthen the security level of user authentication in response to an assessment of a security risk related to user authentication. Furthermore, the security policy management unit (430) according to one embodiment of the present invention may determine a security policy to perform an additional authentication procedure during user authentication on the service provision server (200) as the security level is temporarily strengthened.
[0090] Meanwhile, the security policy management unit (430) according to one embodiment of the present invention, as described above, when the type of security risk is specified by the security risk management unit (420) according to one embodiment of the present invention, can determine a security policy to be applied to user authentication in the service provision server (200) that operates the target service based further on the type of security risk.
[0091] For example, let's assume a situation where the risk information acquisition unit (410) according to one embodiment of the present invention detects an abnormal increase in failed login attempts to a third-party service. In this case, the security risk management unit (420) according to one embodiment of the present invention can specify the type of security risk as a brute force password attack. In addition, the security policy management unit (430) according to one embodiment of the present invention can increase sensitivity to fast sequential login attempts and additionally perform a CAPTCHA during user authentication.
[0092] As another example, suppose that the risk information acquisition unit (410) according to one embodiment of the present invention has detected that a customer of a specific European bank has received an email directing them to a fake login page, and that abnormalities have been detected in the login locations and patterns of multiple accounts. In this case, the security risk management unit (420) according to one embodiment of the present invention can identify the type of security risk as a phishing attack. Furthermore, the security policy management unit (430) according to one embodiment of the present invention can increase sensitivity to abnormal login patterns, send appropriate notifications to the user and / or the service provision server (200), and ensure that additional authentication steps are performed during user authentication. Furthermore, the security risk management unit (420) according to one embodiment of the present invention can ensure that the fake login page is added to a blacklist.
[0093] As another example, suppose that the risk information acquisition unit (410) according to one embodiment of the present invention detects multiple login attempts using different username (account)-password combinations on multiple Australian medical portals. In this case, the security risk management unit (420) according to one embodiment of the present invention can identify the type of security risk as a credential stuffing attack. Furthermore, the security policy management unit (430) according to one embodiment of the present invention can increase the speed of monitoring for credential stuffing attacks and adjust the threshold used when detecting login anomalies to make the criteria for anomaly detection more stringent. Furthermore, the security risk management unit (420) according to one embodiment of the present invention can send a notification to the user and / or the service provision server (200) to change their password, and temporarily require multi-factor authentication for all users.
[0094] As another example, suppose that the risk information acquisition unit (410) according to one embodiment of the present invention detects simultaneous login attempts using a common password on multiple Asian educational institution portals. In this case, the security risk management unit (420) according to one embodiment of the present invention can identify the type of security risk as a password spray attack. Furthermore, the security policy management unit (430) according to one embodiment of the present invention can enforce a stricter password policy and temporarily lock the user account if it is determined that the number of login failures due to password spray attacks has decreased. Furthermore, the security policy management unit (430) according to one embodiment of the present invention can send a message to the user and / or the service provision server (200) along with a warning to create a stronger and more unique password, and can also initiate a campaign on password security.
[0095] Meanwhile, the security policy management unit (430) according to one embodiment of the present invention may, in response to the security policy determined as described above being applied to user authentication, provide the target service operator with a user interface that allows the operator to adjust the determined security policy. By doing so, the target service operator, for example, the service provision server (200), can use this user interface to check which security policy is being applied and set or adjust variables or conditions related to the security policy as appropriate for the situation.
[0096] Next, the communication unit (440) according to one embodiment of the present invention can perform a function that enables data transmission and reception from / to the risk information acquisition unit (410), the security risk management unit (420), and the security policy management unit (430).
[0097] Finally, the control unit (450) according to one embodiment of the present invention can perform a function of controlling the flow of data between the risk information acquisition unit (410), the security risk management unit (420), the security policy management unit (430), and the communication unit (440). That is, the control unit (450) according to one embodiment of the present invention can control the flow of data from / to the outside of the security risk response system (400) or the flow of data between each component of the security risk response system (400), thereby controlling the risk information acquisition unit (410), the security risk management unit (420), the security policy management unit (430), and the communication unit (440) to perform their own unique functions.
[0098] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the present invention or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. Hardware devices may be changed into one or more software modules to perform processing according to the present invention, and vice versa.
[0099] Although the present invention has been described above with specific details such as specific components and limited examples and drawings, these are provided only to help a more general understanding of the present invention, and the present invention is not limited to the above examples, and those with ordinary knowledge in the technical field to which the present invention pertains can make various modifications and changes based on this description.
[0100] Therefore, the idea of the present invention should not be limited to the embodiments described above, and not only the scope of the patent claims described below but also all scopes equivalent to or equivalently modified from the scope of the patent claims are considered to fall within the scope of the idea of the present invention.
Claims
1. As a method for adaptively responding to security risks, A step of obtaining risk information associated with user authentication on a service providing server that operates the target service, and A step of evaluating whether there is a security risk regarding the user authentication using a risk detection model, and A step of determining a security policy to be applied to the user authentication based on the evaluation result is included. method.
2. In paragraph 1, In the above acquisition step, attack information associated with user authentication for a third-party service is acquired as the above risk information. method.
3. In paragraph 1, In the above execution step, the type of security risk is specified using the risk detection model, In the above decision step, the security policy is determined based on the type of security risk. method.
4. In paragraph 3, In the above acquisition step, the risk information is acquired for each of multiple parameters, In the above execution step, the type of security risk is specified based on the risk information for each of the plurality of parameters. method.
5. In paragraph 1, In the above decision step, in response to the evaluation that there is a security risk regarding the user authentication, the security policy is determined so as to temporarily strengthen the security level of the user authentication. method.
6. In paragraph 5, As the above security level is temporarily strengthened, the above security policy is determined so that an additional authentication procedure is performed when authenticating a user on the above service providing server. method.
7. In paragraph 1, In response to the application of the above-determined security policy to the above-determined user authentication, a user interface is provided to the operator of the above-determined service that allows the operator to adjust the above-determined security policy. method.
8. A non-transitory computer-readable recording medium recording a computer program for executing the method according to paragraph 1.
9. As a system for adaptively responding to security risks, A risk information acquisition unit that acquires risk information associated with user authentication on a service providing server that operates the target service, and A security risk management department that performs an evaluation on whether there is a security risk regarding the above user authentication using a risk detection model, and Includes a security policy management unit that determines a security policy to be applied to the user authentication based on the evaluation results. System.
10. In paragraph 9, The above risk information acquisition unit acquires attack information related to user authentication for a third-party service as the above risk information. System.
11. In paragraph 9, The above security risk management department uses the risk detection model to identify the type of security risk, The above security policy management unit determines the security policy based on the type of security risk. System.
12. In paragraph 11, The above risk information acquisition unit acquires the risk information for each of a plurality of parameters, The above security risk management unit identifies the type of security risk based on the risk information for each of the plurality of parameters. System.
13. In paragraph 9, The above security policy management unit, in response to an assessment that there is a security risk regarding the user authentication, determines the security policy so as to temporarily strengthen the security level of the user authentication. System.
14. In paragraph 13, The above security policy management unit determines the security policy so that an additional authentication procedure is performed when authenticating a user on the service provision server as the security level is temporarily strengthened. System.
15. In paragraph 9, The above security policy management unit provides the operator of the target service with a user interface that allows the operator to adjust the determined security policy in response to the determined security policy being applied to the user authentication. System.
Citation Information
Patent Citations
Cyber Threat Information Analysis and Management System
KR1020170135495A
System and method for hybrid security
KR102206847B1
Manufacturing method of bus bars with surface structure for improving electrical conductivity
KR102258703B1
Security management system and method for remote working environment
KR102381150B1
Method and system for adaptively responding to security risks
KR102710773B1