AI Sandbox Detection for Unauthorized Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identity theft and unauthorized access to user accounts are difficult to detect, especially when perpetrators use valid credentials, and relying on human operators can be insufficient due to judgment biases and potential malicious motives.

Innovation Solution

A system using machine learning models processes communication data streams between users and agents to generate a confidence score, deploying a sandbox context for suspicious interactions, simulating successful access, and further analyzing the communication to determine malicious intent, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If human operators or service agents are used to detect malicious attempts to access user accounts, then the system can identify unauthorized access attempts, but the detection is insufficient due to human judgment biases and potential malicious motives of agents

Engineering Contradiction:
Improvedetection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an artificial intelligence system as an intermediary between users and service agents. This AI intermediary automatically analyzes communication data streams to detect malicious access attempts, eliminating human judgment biases and potential agent malice while maintaining reliable detection without requiring complex human oversight structures

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical human detection process with an automated AI-based detection system. Instead of relying on human operators to manually analyze and detect malicious attempts, the system uses machine learning models to automatically process communication data streams, thereby improving reliability while reducing the complexity associated with human operational procedures

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If a sandbox context is deployed to simulate successful access and extend conversation for analysis, then the system can detect malicious intent with higher accuracy, but the processing time and system complexity increase

Engineering Contradiction:
Improvemalicious intent detection accuracyVSAvoidaccess processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by deploying a sandbox context that simulates successful access before actual resource access is granted. This allows the system to extend the conversation and gather additional communication data for analysis, improving detection accuracy by examining user behavior in a controlled environment before making the final access decision

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copy of the access environment through the sandbox context. This simulated environment replicates the appearance and functionality of successful resource access, allowing the system to observe user behavior in a safe copy of the system without affecting actual resources, thereby improving detection precision while managing time through parallel processing

Inventive Principle:
Principle #26Copying

3Reliability

If the system processes communication data streams using machine learning models to generate confidence scores and determine malicious intent, then unauthorized access is prevented effectively, but the computational resources and system complexity increase

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by using machine learning models to process only the necessary portions of communication data streams. Instead of analyzing all possible data, the system focuses on key features and patterns that indicate malicious intent, generating confidence scores based on selective data processing. This approach maintains effective unauthorized access prevention while reducing computational resource consumption by avoiding excessive analysis of irrelevant data

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12381907B2Systems and methods for preventing unauthorized resource access
Publication Date: 2025.08.05 CAPITAL ONE SERVICES LLC
  • US12381907B2 patent drawing
  • US12381907B2 patent drawing
  • US12381907B2 patent drawing

AI summary

Methods and systems for preventing unauthorized resource access. In some aspects, the system obtains, in real time, a first data stream between a user requesting access to resources in a user account and an agent. The system processes, using a first machine learning model, the first data stream to generate a confidence score. If the confidence score exceeds a threshold, the system generates a sandbox context configured to simulate output indicative of successful resource access. The system obtains a second data stream for the sandbox context and processes it using a second machine learning model to determine whether the communication between the agent and the user was malicious. If the communication was not malicious, the system removes the user account from the sandbox context and effects grant of resource access. Otherwise, the system reports the agent and the user account for further processing for attempts to obtain unauthorized user access.