Account Management Using Activity Usage Restrictions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The proliferation of user accounts and devices connected to the Internet creates a large attack surface, making them vulnerable to malicious attacks, particularly brute-force attempts and lateral movement by attackers, which poses a significant security risk for both financial and personal information.
Innovation Solution
Implementing account rules that limit user account activity to specified times, dates, infrastructure, locations, or usage, such as activating or deactivating accounts on-demand, or restricting access to specific times or applications, to reduce the attack surface by monitoring and enforcing permitted parameters like time, location, and usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user accounts are kept active and accessible to maintain operational availability, then system availability is improved, but the attack surface increases and security vulnerability worsens
Solution Approach 1:
The patent implements dynamic account management where user accounts are activated or deactivated based on real-time conditions such as current time, scheduled time windows, and user presence status. This dynamic approach allows accounts to be available when needed while automatically restricting access during periods of low usage or outside authorized timeframes, thereby reducing the attack surface without permanently compromising system availability.
Solution Approach 2:
The system employs periodic account activation and deactivation based on scheduled time windows. Accounts are periodically enabled during authorized timeframes and disabled outside these windows, creating a rhythmic pattern of accessibility that maintains operational availability during business hours while reducing exposure to attacks during off-hours or unauthorized periods.
2Object-affected harmful factors
If account access is restricted to specific time windows and conditions to reduce vulnerability, then security is improved, but account accessibility and operational flexibility worsen
Solution Approach 1:
The system incorporates feedback mechanisms that monitor user presence, device status, and account activity in real-time. Based on this feedback, the system dynamically adjusts account accessibility - activating accounts when users are present and devices are authorized, and deactivating them when users are absent or devices are compromised. This feedback-driven approach maintains ease of operation for authorized users while automatically restricting access to reduce vulnerability.
Solution Approach 2:
The account management system operates autonomously by automatically activating and deactivating accounts based on predefined policies and real-time conditions without requiring manual intervention. The system self-adjusts accessibility based on user presence detection, scheduled time windows, and security conditions, thereby maintaining operational flexibility for authorized users while reducing vulnerability through automated restriction.
3Object-affected harmful factors
If accounts are deactivated when not in use to reduce attack surface, then security is improved, but system productivity and response time worsen
Solution Approach 1:
The system performs preliminary account activation based on scheduled time windows and predicted user needs. Accounts are proactively enabled before anticipated usage periods begin, ensuring immediate accessibility when users need to access the system. This preliminary action prevents delays in system response time while maintaining security by keeping accounts disabled outside of authorized timeframes, thus reducing the overall attack surface.
Data Source
AI summary
Methods, systems, and media are shown for reducing the vulnerability of user accounts to attack that involve creating a rule for a user account that includes a permitted parameter corresponding to a user account activity property, monitoring the account activity of the user account. If it is determined that account activity property is inconsistent with the permitted parameter, then the user account is disabled. An example of a permitted parameter is a permitted time period, such as a start time, an end time, a recurrence definition, a days of the week definition, a start date, an end date, and a number of occurrences definition. Other examples are a physical parameter, such as a permitted geographic location, device, or network, or a permitted usage parameter, such as a permitted application, data access, or domain.


