Predicting Account Takeover Tsunamis via Dump Quake Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number and sophistication of data breaches and account takeovers in computer systems pose a significant challenge in predicting and mitigating cybercriminal activities, as existing technologies often fail to detect these incidents until significant harm has been inflicted.

Innovation Solution

A cyber-threat intelligence system that monitors system activity for unusual spikes in user account validation attacks, identifies attributes of affected accounts, and searches for evidence of undetected data breaches, allowing for proactive security adjustments and notifications to other organizations before private user data is published, thereby preventing a 'tsunami' of account takeovers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing monitoring technologies are used to detect data breaches, then detection capability is limited, but response time is too late causing significant harm

Engineering Contradiction:
Improvedetection capabilityVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by monitoring for account validation attacks before a data breach occurs. By detecting unusual patterns of account validation attempts and identifying them as potential precursors to data breaches, the system enables organizations to take preventive measures before actual data exposure happens, thus resolving the contradiction between detection capability and response time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by implementing security measures in response to detected account validation attacks before the actual data breach occurs. Organizations can proactively strengthen security controls, notify users, and prevent account takeovers before the tsunami of fraudulent activities begins, thereby reducing harm while maintaining detection accuracy

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If proactive monitoring for account validation attacks is implemented, then early detection of data breaches is enabled, but system complexity increases

Engineering Contradiction:
Improveearly detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system achieves multi-functionality by using the same monitoring infrastructure to detect both account validation attacks and actual data breaches. The account activity monitoring system serves multiple purposes: detecting validation attacks, identifying potential data breaches, and tracking subsequent account takeovers, thereby enabling early detection without proportionally increasing system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback mechanisms where detected account validation attacks trigger automated responses and notifications. The feedback loop connects monitoring data to alerting systems and security controls, enabling reliable early detection while managing complexity through automated decision-making rather than requiring complex manual analysis systems

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10021118B2Predicting account takeover tsunami using dump quakes
Publication Date: 2018.07.10 PAYPAL INC
  • US10021118B2 patent drawing
  • US10021118B2 patent drawing
  • US10021118B2 patent drawing

AI summary

Methods, systems, and computer program products for predicting an account takeover tsunami using dump quakes are disclosed. A computer-implemented method may include analyzing activity for a plurality of user accounts based on detecting an abnormal increase in system activity, determining the abnormal increase in the system activity is associated with account validation attacks performed by an unauthorized party, identifying attributes of a plurality of user accounts associated with the account validation attacks, searching online locations using the identified attributes of the user accounts to find a data breach source, monitoring the online locations periodically based on the identified attributes of the user accounts to detect future publication of a dump of private user data, sending a notification to another organization in advance of the publication of the dump of private user data to allow the other organization to adjust security of one or more other systems in advance.