Method and system for detecting login anomaly
The method and system generate adaptive login anomaly detection rules to address the inflexibility of conventional techniques, ensuring high accuracy and effective response to changes in login request information and parameters.
Patent Information
- Application Number
- PCT/KR2024/017031
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-20
- Filing Date
- 2024-11-01
- Publication Date
- 2025-05-30
AI Technical Summary
Conventional login anomaly detection techniques struggle to adapt flexibly to changes in business environments or security policies, leading to reduced accuracy in anomaly detection.
A method and system for generating adaptive login anomaly detection rules that can respond to changes in login request information and associated parameters, by determining target parameters and creating temporary detection rules.
The system maintains high accuracy in anomaly detection even with changes in login request information and parameters, ensuring flexible and effective response to evolving security conditions.
Smart Images

Figure KR2024017031_30052025_PF_FP_ABST
Abstract
Description
Method and system for detecting login anomalies
[0001] The present invention relates to a method and system for detecting login anomalies.
[0002] Most services provided through the web or apps require users to log in, and thus, the service providing server is placed in an environment where it must handle numerous login requests from users.
[0003] The user login process involves the user device sending a login request to the service provider server, which then verifies the login request and allows the user device to access the service provider page. When a normal login request is received, the service provider server has no problem processing the request. However, in reality, abnormal login requests (such as repeated login requests received at extremely short intervals) may be received, and in such cases, the service provider server may experience problems processing the login request.
[0004] To address the above issues, numerous prior art techniques have been introduced to detect anomalies in login situations. Conventional techniques, such as the Fraud Detection System (FDS), utilize specific rules for anomaly detection to detect login anomalies based on information regarding login requests provided by users and / or service providers. However, these specific rules have difficulty operating flexibly in response to changes in business environments or security policies.
[0005] For example, if there are four types of parameters A, B, C, and D associated with information about login requests provided from users and / or service provision servers, and a specific rule for anomaly detection uses all four types of parameters, it can be assumed that the parameters are changed to three types A, B, and C due to changes in the business environment or security policy, etc. In this case, since the specific rule is still defined to use up to parameter D, there was a problem that the accuracy of anomaly detection was lowered or separate measures were needed to prevent the anomaly detection model using the specific rule from malfunctioning.
[0006] Accordingly, the inventor(s) of the present invention propose a technique for generating a login anomaly detection rule that can adaptively respond to changes in information about a login request provided from a user and / or a service providing server and / or parameters associated with the information.
[0007] <Prior Art Literature>
[0008] Patent Document
[0009] (Patent Document 1) Patent Registration No. 10-0785715 (December 7, 2007)
[0010] The purpose of the present invention is to solve all of the problems of the above-mentioned prior art.
[0011] In addition, another object of the present invention is to receive information about a login request that occurs for a service providing server that operates a target service, determine at least one target parameter associated with the information about the login request from among a plurality of parameters about a login abnormality, and generate a first temporary login abnormality detection rule that uses the at least one target parameter.
[0012] Another objective is to create anomaly detection rules that can adaptively respond to changes in information about login requests provided by users and / or service providing servers and / or parameters associated with such information.
[0013] Another purpose is to ensure that the accuracy of anomaly detection remains high even when there are changes in information about login requests provided by users and / or service providing servers and / or parameters associated with such information.
[0014] A representative configuration of the present invention to achieve the above purpose is as follows.
[0015] According to one aspect of the present invention, a method is provided, comprising: receiving information about a login request that occurs for a service providing server that operates a target service; determining at least one target parameter associated with the information about the login request from among a plurality of parameters about a login abnormality; and generating a first temporary login abnormality detection rule using the at least one target parameter.
[0016] According to another aspect of the present invention, a system is provided, including a login request management unit that receives information about a login request that occurs for a service providing server that operates a target service, a parameter management unit that determines at least one target parameter associated with the information about the login request from among a plurality of parameters about a login abnormality, and a rule management unit that generates a first temporary login abnormality detection rule using the at least one target parameter.
[0017] In addition, a non-transitory computer-readable recording medium recording another method for implementing the present invention, another system, and a computer program for executing the method are further provided.
[0018] According to the present invention, it is possible to receive information about a login request that occurs for a service providing server that operates a target service, determine at least one target parameter associated with the information about the login request from among a plurality of parameters about a login abnormality, and generate a first temporary login abnormality detection rule that uses the at least one target parameter.
[0019] In addition, according to the present invention, it is possible to create an anomaly detection rule that can adaptively respond to changes in information about a login request provided from a user and / or a service providing server and / or parameters associated with the information.
[0020] In addition, according to the present invention, it is possible to maintain a high level of accuracy in anomaly detection even when there is a change in information regarding a login request provided from a user and / or a service providing server and / or parameters associated with the information.
[0021] FIG. 1 is a diagram schematically illustrating the configuration of an entire system for detecting login abnormalities according to one embodiment of the present invention.
[0022] FIG. 2 is a drawing showing in detail the internal configuration of a login anomaly detection system according to one embodiment of the present invention.
[0023] <Explanation of symbols>
[0024] 100: Communications network
[0025] 200: Service Provider Server
[0026] 300: Device
[0027] 400: Login Anomaly Detection System
[0028] 410: Login Request Management Department
[0029] 420: Parameter Management Department
[0030] 430: Rule Management Department
[0031] 440: Communications Department
[0032] 450: Control Unit
[0033] The following detailed description of the present invention refers to the accompanying drawings, which illustrate specific embodiments in which the present invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the present invention. It should be understood that the various embodiments of the present invention, while different from each other, are not necessarily mutually exclusive. For example, specific shapes, structures, and characteristics described herein may be modified and implemented from one embodiment to another without departing from the spirit and scope of the present invention. Furthermore, it should be understood that the positions or arrangements of individual components within each embodiment may also be modified without departing from the spirit and scope of the present invention. Accordingly, the following detailed description is not to be taken in a limiting sense, and the scope of the present invention is to be construed to encompass the scope of the claims and all equivalents thereof. Like reference numerals in the drawings represent the same or similar elements throughout the several aspects.
[0034] Hereinafter, various preferred embodiments of the present invention will be described in detail with reference to the attached drawings so that a person having ordinary skill in the art to which the present invention pertains can easily practice the present invention.
[0035] Composition of the entire system
[0036] FIG. 1 is a diagram schematically illustrating the configuration of an entire system for detecting login abnormalities according to one embodiment of the present invention.
[0037] As illustrated in FIG. 1, the entire system according to one embodiment of the present invention may include a communication network (100), a service provision server (200), a device (300), and a login anomaly detection system (400).
[0038] First, the communication network (100) according to one embodiment of the present invention can be configured regardless of the communication mode such as wired communication or wireless communication, and can be configured with various communication networks such as a local area network (LAN), a metropolitan area network (MAN), and a wide area network (WAN). Preferably, the communication network (100) referred to herein may be the well-known Internet or the World Wide Web (WWW). However, the communication network (100) is not necessarily limited thereto, and may include at least a portion of a well-known wired or wireless data communication network, a well-known telephone network, or a well-known wired or wireless television communication network.
[0039] For example, the communication network (100) may be a wireless data communication network that implements conventional communication methods such as WiFi communication, WiFi-Direct communication, Long Term Evolution (LTE) communication, 5G communication, Bluetooth communication (including Bluetooth Low Energy (BLE) communication), infrared communication, ultrasonic communication, etc., at least in part. As another example, the communication network (100) may be an optical communication network that implements conventional communication methods such as LiFi (Light Fidelity), etc., at least in part.
[0040] Next, the service providing server (200) according to one embodiment of the present invention may be a server including a function capable of communicating after connecting to a device (300) or a login anomaly detection system (400).
[0041] Next, a device (300) according to one embodiment of the present invention is a digital device that includes a function for communicating after connecting to a service providing server (200) or a login anomaly detection system (400), and any digital device that has a memory means, a microprocessor, and a computing capability, such as a smart phone, a tablet, a smart watch, a smart band, smart glasses, a desktop computer, a notebook computer, a workstation, a PDA, a web pad, a mobile phone, etc., can be adopted as the device (300) according to the present invention.
[0042] In particular, the device (300) may include an application (not shown) that supports a user to receive services from a service providing server (200) or a login anomaly detection system (400). Such an application may be downloaded from the service providing server (200), the login anomaly detection system (400), or an external application distribution server (not shown). Meanwhile, the nature of such an application may be generally similar to the login request management unit (410), parameter management unit (420), rule management unit (430), communication unit (440), and control unit (450) of the login anomaly detection system (400), which will be described later. Here, at least a part of the application may be replaced with a hardware device or firmware device that can perform functions substantially identical to or equivalent thereto, as necessary.
[0043] Next, a login anomaly detection system (400) according to one embodiment of the present invention may perform a function of receiving information about a login request that occurs for a service providing server that operates a target service, determining at least one target parameter associated with the information about the login request among a plurality of parameters about the login anomaly, and generating a first temporary login anomaly detection rule that uses the at least one target parameter.
[0044] The configuration and function of the login anomaly detection system (400) according to the present invention will be described in detail below.
[0045] Configuration of a login anomaly detection system
[0046] Below, the internal configuration and functions of each component of the login anomaly detection system (400) that performs important functions for implementing the present invention will be examined.
[0047] FIG. 2 is a drawing showing in detail the internal configuration of a login anomaly detection system (400) according to one embodiment of the present invention.
[0048] As illustrated in FIG. 2, a login anomaly detection system (400) according to one embodiment of the present invention may be configured to include a login request management unit (410), a parameter management unit (420), a rule management unit (430), a communication unit (440), and a control unit (450). According to one embodiment of the present invention, at least some of the login request management unit (410), the parameter management unit (420), the rule management unit (430), the communication unit (440), and the control unit (450) may be program modules that communicate with the service providing server (200) or an external system (not shown). These program modules may be included in the login anomaly detection system (400) in the form of an operating system, an application program module, or other program modules, and may be physically stored in various known storage devices. In addition, these program modules may also be stored in a remote storage device that can communicate with the login anomaly detection system (400). Meanwhile, these program modules include, but are not limited to, routines, subroutines, programs, objects, components, data structures, etc. that perform specific tasks or execute specific abstract data types, as described later in accordance with the present invention.
[0049] Meanwhile, although the login anomaly detection system (400) has been described above, this description is exemplary, and it is obvious to those skilled in the art that at least some of the components or functions of the login anomaly detection system (400) may be realized within the service providing server (200), device (300), or external server (not shown) or included within an external system (not shown) as needed.
[0050] First, the login request management unit (410) according to one embodiment of the present invention can perform a function of receiving information regarding a login request that occurs for a service providing server (200) that operates a target service.
[0051] Specifically, according to one embodiment of the present invention, a user who wishes to use a target service, such as a financial service, an SNS service, an e-commerce platform service, etc., through a service providing server (200) may be required to authenticate the user, and the user may request a login to the service providing server (200) that operates the target service according to this request.
[0052] The login request management unit (410) according to one embodiment of the present invention can receive information regarding such login requests and process and / or store the same as needed. According to one embodiment of the present invention, the information regarding the login request may include information regarding the time when the login request occurred, information regarding the fingerprint (MAC address, connection location, etc.) of the device that generated the login request, information regarding the entered password, information regarding a password change or reset request, etc. To this end, the login request management unit (410) according to one embodiment of the present invention can provide the service providing server (200) with a program module that helps the service providing server (200) collect information regarding the login request.
[0053] In addition, the login request management unit (410) according to one embodiment of the present invention may perform anonymization processing on information regarding login requests collected as described above.
[0054] Meanwhile, it should be understood that the information regarding login requests received by the login request management unit (410) according to one embodiment of the present invention may include not only login requests occurring at a specific point in time but also information regarding login requests occurring during a specific period of time.
[0055] Next, the parameter management unit (420) according to one embodiment of the present invention may perform a function of determining at least one target parameter associated with information regarding a login request generated for a service providing server (200) among a plurality of parameters regarding login abnormalities.
[0056] Specifically, according to one embodiment of the present invention, a parameter may refer to a specific risk type or attack type that is classified or clustered according to predetermined criteria. According to one embodiment of the present invention, these parameters may have values such as a value assigned to at least one account (e.g., a value between 0 and 1), a flag (e.g., 0 or 1), a count number, etc., but are not limited to this format.
[0057] For example, parameters according to one embodiment of the present invention may include:
[0058]
[0059] *
[0060] 1. Abnormal login times: When a user attempts to log in at a time when they do not normally log in.
[0061] 2. Sudden increase in login attempts: Repeated login attempts occur within a short period of time.
[0062] 3. Failed login attempts: If login attempts fail repeatedly.
[0063] 4. Unusual login location: If the user attempts to log in from a location that is significantly different from the usual login area.
[0064] 5. Simultaneous login attempts from multiple locations: If login attempts occur at an unusually high rate from multiple locations.
[0065] 6. Unusual device, browser, or OS changes: If the user attempts to log in from a device that he or she does not normally use.
[0066] 7. Use a VPN or proxy: If you are trying to hide your login location.
[0067] 8. Frequent password changes: If the user changes their password unusually frequently.
[0068] 9. Attempting to log in to multiple accounts: If you repeatedly attempt to log in to multiple accounts on the same device.
[0069] 10. Increased password reset requests: If multiple password reset requests occur within a short period of time.
[0070] 11. Multiple requests to the server: When a single account makes a sudden surge of requests to the server within a short period of time.
[0071] 12. Using weak passwords: When users set passwords that are considered weak, such as those that are too short, easily guessable, or do not contain a combination of uppercase and lowercase letters, numbers, or special characters.
[0072] 13. Leaked Password: If you use a password similar to a password leaked from a third-party service.
[0073]
[0074] However, parameters according to one embodiment of the present invention are not limited to those listed above, and may be variously changed within a range that can achieve the purpose of the present invention.
[0075] Continuing, the parameter management unit (420) according to one embodiment of the present invention can classify or cluster information regarding a login request occurring to the service providing server (200) according to predetermined criteria, thereby determining which parameter among a plurality of parameters regarding the above login anomaly is associated with the information regarding the corresponding login request, and the parameter thus determined can become a target parameter. Here, it should be understood that according to one embodiment of the present invention, information regarding a specific login request may be associated with one target parameter, but may also be associated with a plurality of target parameters depending on the case.
[0076] Next, the rule management unit (430) according to one embodiment of the present invention can perform a function of generating a first temporary login anomaly detection rule using at least one target parameter determined by the parameter management unit (420) according to one embodiment of the present invention.
[0077] Specifically, according to one embodiment of the present invention, a login anomaly detection rule is a rule for determining whether there is an anomaly in a user's login request, and may be a concept including a predetermined threshold, weight, decision tree, etc. that serve as a criterion or basis for the determination. The rule management unit (430) according to one embodiment of the present invention can generate a temporary login anomaly detection rule by making the login anomaly detection rule have a temporary nature. Since the temporary login anomaly detection rule generated in this way uses at least one target parameter determined as described above rather than a fixed type of parameter, it can adaptively respond to changes in information regarding login requests provided from the user and / or the service providing server (200) and / or changes in parameters associated with the information. Meanwhile, the user above may refer to a device (300) used by the user depending on the context, and it should be noted that the same applies above and below.
[0078] Additionally, the rule management unit (430) according to one embodiment of the present invention can generate a customized first temporary login anomaly detection rule based on the attributes of the user generating the login request.
[0079] Specifically, according to one embodiment of the present invention, the user's attributes may include the user's age, the user's connection location, the user's tendencies regarding the use of the target service, etc. And, for example, if the user tends not to log in often in the late morning hours, the rule management unit (430) according to one embodiment of the present invention may create a first temporary login anomaly detection rule customized to strictly detect anomalies in login requests during such early morning hours and to detect anomalies in login requests at a general level at other times.
[0080] Meanwhile, the rule management unit (430) according to one embodiment of the present invention may generate a first temporary login anomaly detection rule based on the detection results using the second temporary login anomaly detection rule. Here, according to one embodiment of the present invention, the second temporary login anomaly detection rule may be generated before the first temporary login anomaly detection rule is generated.
[0081] Specifically, the second temporary login anomaly detection rule created before the first temporary login anomaly detection rule is created is temporary and thus has been or may be deleted. However, the detection result (e.g., detection result value, detection log, etc.) by the second temporary login anomaly detection rule may be considered when the first temporary login anomaly detection rule is created by the rule management unit (430) according to an embodiment of the present invention. By doing so, it is possible to adaptively respond to changes in information regarding login requests provided from users and / or service provision servers (200) and / or changes in parameters associated with the information, while utilizing past detection results to create a more appropriate (e.g., higher accuracy of anomaly detection) temporary login anomaly detection rule.
[0082] To this end, the rule management unit (430) according to one embodiment of the present invention can store the detection result using the first temporary login anomaly detection rule and delete the first temporary login anomaly detection rule.
[0083] Next, the communication unit (440) according to one embodiment of the present invention can perform a function that enables data transmission and reception from / to the login request management unit (410), parameter management unit (420), and rule management unit (430).
[0084] Finally, the control unit (450) according to one embodiment of the present invention can perform a function of controlling the flow of data between the login request management unit (410), the parameter management unit (420), the rule management unit (430), and the communication unit (440). That is, the control unit (450) according to one embodiment of the present invention can control the flow of data from / to the outside of the login anomaly detection system (400) or the flow of data between each component of the login anomaly detection system (400), thereby controlling the login request management unit (410), the parameter management unit (420), the rule management unit (430), and the communication unit (440) to perform their own functions.
[0085] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the present invention or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. Hardware devices may be changed into one or more software modules to perform processing according to the present invention, and vice versa.
[0086] Although the present invention has been described above with specific details such as specific components and limited examples and drawings, these are provided only to help a more general understanding of the present invention, and the present invention is not limited to the above examples, and those with ordinary knowledge in the technical field to which the present invention pertains can make various modifications and changes based on this description.
[0087] Therefore, the idea of the present invention should not be limited to the embodiments described above, and not only the scope of the patent claims described below but also all scopes equivalent to or equivalently modified from the scope of the patent claims are considered to fall within the scope of the idea of the present invention.
Claims
1. As a method for detecting login abnormalities, A step for receiving information about a login request that occurs for a service providing server that operates the target service; A step of determining at least one target parameter associated with information about the login request among a plurality of parameters related to the login abnormality, and A step of generating a first temporary login anomaly detection rule using at least one target parameter is included. method.
2. In paragraph 1, In the above generation step, the first temporary login anomaly detection rule is generated based on the detection result using the second temporary login anomaly detection rule generated before the first temporary login anomaly detection rule is generated. method.
3. In paragraph 1, The above first temporary login anomaly detection rule is customized based on the attributes of the user generating the login request. method.
4. In paragraph 1, It further includes a step of storing the detection result using the first temporary login anomaly detection rule and deleting the first temporary login anomaly detection rule. method.
5. A non-transitory computer-readable recording medium recording a computer program for executing the method according to paragraph 1.
6. As a system for detecting login abnormalities, A login request management unit that receives information about login requests that occur for the service providing server that operates the target service; A parameter management unit for determining at least one target parameter associated with information about the login request among a plurality of parameters related to the login request, and A rule management unit comprising a first temporary login anomaly detection rule using at least one target parameter. System.
7. In paragraph 6, The above rule management unit generates the first temporary login anomaly detection rule based on the detection result using the second temporary login anomaly detection rule generated before the first temporary login anomaly detection rule is generated. System.
8. In paragraph 6, The above first temporary login anomaly detection rule is customized based on the attributes of the user generating the login request. System.
9. In paragraph 6, The above rule management unit stores the detection results using the first temporary login anomaly detection rule and deletes the first temporary login anomaly detection rule. System.
Citation Information
Patent Citations
Wafer level chip scale package with rhombus shape
KR1020240001888A
Method for measuring displacement using RTK GNSS and device for the same
KR1020240079302A
Apparatus, system, method and program for evaluating patent rights and providing services connecting enterprises
KR1020240175413A
Method and system for detecting login anomaly
KR102721152B1
Supervised learning system for identity compromise risk computation
US20200089848A1