Authorized User Set for Account Security Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computer systems are vulnerable to unauthorized access when unattended, and users' varying levels of competency in protecting their systems allow adversaries to exploit limitations in security software, particularly in detecting malicious activities and social engineering attacks.
Innovation Solution
A system that authorizes a set of users to receive notifications and send responsive security actions when specific activities occur on another user's account, leveraging real-world social relationships to enhance security by allowing community members to monitor and respond to anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security software is used to detect malicious activity, then detection capability is improved, but the system remains vulnerable to social engineering attacks and advanced persistent threats that bypass automated detection
Solution Approach 1:
The patent introduces authorized users as intermediaries between the monitored account and the security response system. When suspicious activity is detected, these intermediary users receive notifications and can manually assess the situation, providing a human judgment layer that complements automated detection and can distinguish between legitimate and malicious activity that automated systems may misclassify
Solution Approach 2:
The system implements a feedback loop where authorized users provide responses to security notifications, which then triggers appropriate security actions. This feedback mechanism allows the system to adapt to detected threats in real-time, with human users providing contextual feedback that improves the overall security response effectiveness
2Speed
If automated security monitoring is implemented, then response speed is improved, but the system cannot detect external conditions and privacy-sensitive data that require human judgment
Solution Approach 1:
The system performs preliminary automated monitoring and detection of suspicious activities, then promptly notifies authorized users who can provide human judgment. This preliminary action by the automated system ensures rapid detection while the human users provide the necessary contextual understanding of external conditions and privacy-sensitive situations
3Ease of operation
If users are directly responsible for protecting their own systems, then system autonomy is improved, but security effectiveness decreases due to varying user competency levels
Solution Approach 1:
The patent creates a universal security network where multiple authorized users can monitor and respond to security events across different accounts. This multi-functional approach allows users with varying competency levels to contribute to security, with more proficient users potentially helping to protect accounts of less proficient users within the trusted network
4Reliability
If security notifications are sent to multiple authorized users, then security coverage is improved, but notification management complexity increases
Solution Approach 1:
The system segments the authorization management by allowing users to selectively specify which users are authorized to receive notifications for particular accounts or types of activities. This segmentation approach enables fine-grained control over notification distribution, improving security coverage while managing complexity through organized, account-specific authorization lists
Data Source
AI summary
An approach is provided that enhances computer system security. In the approach, a set of users is authorized to be notified when any of a selected set of activities occurs on the user's account. When the system detects that one of the activities has occurred on the account, a notification is sent to the set of authorized users. The set of users may individually send a responsive security response to protect the user's account. Responsive to receiving the security response from one of the set of users, a security action is performed that is anticipated to protect the user's account.


