Artifact Modification System for Account Takeover Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems fail to detect and mitigate account compromise attacks, such as launchpad attacks, which involve compromised email accounts being used to send deceptive messages that evade traditional security controls and detection methods, leading to significant financial losses and infiltration in enterprises and personal accounts.
Innovation Solution
The implementation of an artifact modification system that replaces sensitive items in emails with cloud-hosted links and characterizes requesters based on device, environment, and automation identifiers to detect anomalies and prevent unauthorized access, allowing for real-time security determinations and automated actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security controls and detection methods are used, then system simplicity is maintained, but account compromise attacks such as launchpad attacks cannot be detected
Solution Approach 1:
The patent segments the email delivery system into multiple components: artifact identification, artifact modification, requester characterization, and security determination. Each component performs a specific function, allowing the system to detect account compromises through layered analysis rather than relying on a single complex detection mechanism.
Solution Approach 2:
The patent introduces modified artifacts as intermediaries between the original email content and the recipient. These modified artifacts contain embedded identifiers that enable tracking and characterization of requesters without exposing the full complexity of the detection system to end users.
2Reliability
If artifacts in emails are modified and replaced with cloud-hosted links, then security detection capability is improved, but message processing time increases
Solution Approach 1:
The patent performs artifact modification in advance before email delivery. By pre-modifying artifacts and hosting them in the cloud with embedded identifiers, the system prepares security detection data beforehand, reducing the time required for real-time analysis when emails are received and processed.
Solution Approach 2:
The patent replaces traditional mechanical email attachment handling with cloud-hosted link delivery. Instead of directly transferring and analyzing large email artifacts, the system substitutes cloud storage and link-based access, which enables faster processing and embedded security identifiers without the overhead of handling original artifacts.
3Measurement precision
If requester characterization based on device and environment identifiers is implemented, then accuracy of compromise detection is improved, but data processing requirements increase
Solution Approach 1:
The patent applies different levels of characterization to different requesters based on their behavior patterns and risk profiles. Rather than uniformly processing all requesters with the same level of detail, the system focuses computational resources on suspicious or high-risk requesters, reducing overall data processing requirements while maintaining high detection accuracy where needed.
Solution Approach 2:
The patent dynamically adjusts the granularity of requester characterization based on security determinations. When initial analysis indicates low risk, the system uses coarser parameter groups; when suspicious activity is detected, it transitions to finer-grained parameter analysis, optimizing data processing volume according to actual security needs.
Data Source
AI summary
An apparatus comprises at least one processing device comprising a processor coupled to a memory. The processing device is configured to identify artifacts in a plurality of messages of an account of a user, and to replace the identified artifacts in the messages with respective modified artifacts while also maintaining in access-controlled storage at least information related to the identified artifacts. The processing device receives from a requestor a request for a given one of the identified artifacts that has been replaced with a corresponding modified artifact, determines a profile of the requestor based at least in part on the request, makes a security determination based at least in part on the determined profile, and takes at least one automated action based at least in part on the security determination.


