Adaptive Network Access Control via ML Clustering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Adaptive multifactor authentication (MFA) systems are limited by static rules and do not effectively differentiate between normal and abnormal user behavior based on past network access and usage history, leading to increased complexity and reduced effectiveness.
Innovation Solution
The system employs real-time machine-learning methods to build entity profiles by analyzing event attributes, using clustering algorithms to learn normal behavior patterns and dynamically update risk assessment rules based on continuous event data, eliminating the need for human administration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If adaptive MFA uses static rules to change authentication requirements, then authentication security is improved, but the system complexity increases and effectiveness is limited
Solution Approach 1:
The patent transforms static authentication rules into dynamic, adaptive rules that automatically adjust based on real-time risk assessment. The system continuously monitors user behavior patterns, login locations, device information, and contextual data to dynamically determine authentication requirements, eliminating the need for manual rule configuration while improving both security and adaptability.
Solution Approach 2:
The system performs self-learning and self-adjustment by automatically analyzing user behavior patterns and updating risk assessment models without human intervention. The machine learning algorithms continuously refine their understanding of normal user behavior, enabling the system to autonomously optimize authentication requirements based on observed patterns and detected anomalies.
2Speed
If adaptive MFA acts only on current login conditions, then authentication speed is improved, but the ability to detect abnormal behavior decreases
Solution Approach 1:
The system performs preliminary analysis of user behavior patterns, login histories, and contextual information before the actual authentication occurs. By pre-establishing baseline behavior models and continuously monitoring for deviations, the system can quickly identify abnormal patterns during authentication without requiring extensive real-time analysis, thus maintaining speed while improving detection capability.
Solution Approach 2:
The system incorporates feedback loops that continuously monitor authentication outcomes, user behavior patterns, and security events. This feedback is fed back into the machine learning models to refine risk assessment algorithms, enabling the system to learn from past authentication behavior and improve its ability to detect anomalies in real-time without sacrificing authentication speed.
3Reliability
If MFA requires multiple authentication methods, then security is improved, but user convenience deteriorates
Solution Approach 1:
The patent applies different authentication requirements to different users and contexts based on individual risk profiles. Instead of applying uniform MFA to all users, the system assesses individual risk levels based on user behavior patterns, device trustworthiness, login location, and contextual factors, then tailors authentication requirements accordingly. This allows high-security scenarios to require multiple factors while low-risk scenarios use simpler authentication methods.
Solution Approach 2:
The system dynamically changes authentication parameters such as the number of required factors, type of authentication methods, and verification thresholds based on real-time risk assessment. When risk levels are low, the system accepts simpler authentication; when risk levels increase, it automatically requires additional authentication factors, thus adapting the balance between security and convenience based on actual conditions rather than fixed policies.
Data Source
AI summary
Methods and systems of risk assessment for network access control through data analytics. An embodiment of the invention employs well-known machine-learning clustering methods to learn normal entity behavior by looking for patterns in the events that stream in continuously. In an embodiment of the invention, normal entity behaviors are represented as clusters of event vectors. An embodiment of the invention evaluates the risk level for a new event of an entity by comparing the event with the entity's profile represented as clusters of event vectors. In an embodiment of the invention, the risk level is associated with a confidence level. Confidence level indicates how well the system knows about the entity. Embodiments of the invention do not need human administration in the process of building entity profile and assessing risk level of events associated with an entity.


