Artifact Modification System for Account Takeover Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems fail to detect and mitigate account compromise attacks, such as launchpad attacks, which involve compromised email accounts being used to send deceptive messages that evade traditional security controls and detection methods, leading to significant financial losses and infiltration in enterprises and personal accounts.

Innovation Solution

The implementation of an artifact modification system that replaces sensitive items in emails with cloud-hosted links and characterizes requesters based on device, environment, and automation identifiers to detect anomalies and prevent unauthorized access, allowing for real-time security determinations and automated actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security controls and detection methods are used, then system simplicity is maintained, but account compromise attacks such as launchpad attacks cannot be detected

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the email delivery system into multiple components: artifact identification, artifact modification, requester characterization, and security determination. Each component performs a specific function, allowing the system to detect account compromises through layered analysis rather than relying on a single complex detection mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces modified artifacts as intermediaries between the original email content and the recipient. These modified artifacts contain embedded identifiers that enable tracking and characterization of requesters without exposing the full complexity of the detection system to end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If artifacts in emails are modified and replaced with cloud-hosted links, then security detection capability is improved, but message processing time increases

Engineering Contradiction:
Improvesecurity detectionVSAvoidmessage processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs artifact modification in advance before email delivery. By pre-modifying artifacts and hosting them in the cloud with embedded identifiers, the system prepares security detection data beforehand, reducing the time required for real-time analysis when emails are received and processed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical email attachment handling with cloud-hosted link delivery. Instead of directly transferring and analyzing large email artifacts, the system substitutes cloud storage and link-based access, which enables faster processing and embedded security identifiers without the overhead of handling original artifacts.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If requester characterization based on device and environment identifiers is implemented, then accuracy of compromise detection is improved, but data processing requirements increase

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata processing volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent applies different levels of characterization to different requesters based on their behavior patterns and risk profiles. Rather than uniformly processing all requesters with the same level of detail, the system focuses computational resources on suspicious or high-risk requesters, reducing overall data processing requirements while maintaining high detection accuracy where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent dynamically adjusts the granularity of requester characterization based on security determinations. When initial analysis indicates low risk, the system uses coarser parameter groups; when suspicious activity is detected, it transitions to finer-grained parameter analysis, optimizing data processing volume according to actual security needs.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11323464B2Artifact modification and associated abuse detection
Publication Date: 2022.05.03 CARBYNE BIOMETRICS LLC
  • US11323464B2 patent drawing
  • US11323464B2 patent drawing
  • US11323464B2 patent drawing

AI summary

An apparatus comprises at least one processing device comprising a processor coupled to a memory. The processing device is configured to identify artifacts in a plurality of messages of an account of a user, and to replace the identified artifacts in the messages with respective modified artifacts while also maintaining in access-controlled storage at least information related to the identified artifacts. The processing device receives from a requestor a request for a given one of the identified artifacts that has been replaced with a corresponding modified artifact, determines a profile of the requestor based at least in part on the request, makes a security determination based at least in part on the determined profile, and takes at least one automated action based at least in part on the security determination.