Account Classification Through Sign-In Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity measures lack effective differentiation between human-driven and machine-driven accounts, leading to inadequate security investments and increased risk of unauthorized access.
Innovation Solution
A machine learning model is trained to distinguish between human-driven and machine-driven accounts through anomaly detection based on sign-in data, supplemented by other data features and signals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional cybersecurity measures are used without account classification, then security coverage is provided for all accounts, but security effectiveness is reduced due to inability to distinguish between human-driven and machine-driven accounts
Solution Approach 1:
The patent replaces manual security assessment mechanisms with an automated machine learning model that analyzes sign-in data patterns. The model automatically classifies accounts as human-driven or machine-driven based on behavioral characteristics, eliminating the need for manual classification while improving security effectiveness through consistent, data-driven decision-making.
Solution Approach 2:
The patent introduces an intermediary classification layer between the account and security measures. This intermediary system analyzes sign-in data and provides classification information to security mechanisms, enabling them to apply appropriate security controls based on account type without direct human intervention or complex rule-based systems.
2Measurement precision
If machine learning model is implemented for account classification, then account classification accuracy is improved, but computational resources and processing time are increased
Solution Approach 1:
The patent applies partial action by focusing the machine learning model's analysis on specific, high-value features from sign-in data that are most indicative of account type. Rather than analyzing all possible data points, the model concentrates computational resources on key discriminative features such as sign-in frequency, time patterns, and device information, achieving high accuracy with reduced computational overhead.
3Reliability
If comprehensive sign-in data analysis is performed, then classification reliability is improved, but data processing complexity and time are increased
Solution Approach 1:
The patent implements preliminary action by pre-processing and feature-engineering sign-in data before it reaches the classification model. Data is aggregated, cleaned, and transformed into meaningful features in advance, allowing the model to make rapid classification decisions based on prepared information rather than raw data, thus reducing real-time processing time while maintaining reliability.
Data Source
AI summary
A trained machine learning model distinguishes between human-driven accounts and machine-driven accounts by performing anomaly detection based on sign-in data and optionally also based on directory data. This machine versus human distinction supports security improvements that apply security controls and other risk management tools and techniques which are specifically tailored to the kind of account being secured. Formulation heuristics can improve account classification accuracy by supplementing a machine learning model anomaly detection result, e.g., based on directory information, kind of IP address, kind of authentication, or various sign-in source characteristics. Machine-driven accounts masquerading as human-driven may be identified as machine-driven. Reviewed classifications may serve as feedback to improve the model's accuracy. A precursor machine learning model may generate training data for training a production account classification machine learning model.


