Botnet Device Identification via Cluster Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques for mitigating brute force attacks are often deficient or sub-optimal, leading to a significant burden on software platform infrastructure and compromising user access reliability.

Innovation Solution

The software platform employs a technique to identify devices of a botnet by assigning a device token and determining a cluster score based on device characteristics, such as IP addresses or usernames, using machine learning processes to prevent brute force attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional brute force attack mitigation techniques are used, then attack sources may be blocked, but infrastructure burden increases and user access reliability decreases

Engineering Contradiction:
Improveuser access reliabilityVSAvoidinfrastructure burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by assigning device tokens and calculating cluster scores before attacks occur. The machine learning model pre-establishes relationships between devices and characteristics, enabling proactive identification of malicious entities before they can overwhelm the infrastructure with brute force attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces conventional mechanical brute force mitigation (blocking IP addresses, rate limiting) with an intelligent system using device tokens and machine learning-based cluster scoring. This substitution enables more precise identification of malicious devices without imposing broad infrastructure burdens on legitimate users.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If device tracking and cluster scoring is implemented, then malicious entity identification improves, but system complexity increases

Engineering Contradiction:
Improvemalicious entity identification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The device token serves multiple functions: it identifies the device, tracks its characteristics, enables cluster scoring, and facilitates malicious entity detection. This multi-functionality reduces the need for separate tracking systems, thereby managing system complexity while improving identification accuracy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The cluster score acts as an intermediary metric that synthesizes multiple device characteristics and relationships into a single actionable indicator. This intermediary enables the system to manage complexity by providing a unified measure for malicious entity identification rather than requiring direct analysis of numerous individual characteristics.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12294590B2Techniques for malicious entity discovery
Publication Date: 2025.05.06 OKTA INC
  • US12294590B2 patent drawing
  • US12294590B2 patent drawing
  • US12294590B2 patent drawing

AI summary

Methods, systems, and devices for access management are described. A software platform may identify devices of a botnet based on a cluster score associated with a device characteristic. For example, the software platform may receive a request from a device to access an application. The software platform may determine a cluster score for the characteristic of the device. The cluster score may be based on a link between the device and a list of devices (e.g., devices of a botnet). If the cluster score satisfies (e.g., exceeds) a cluster score threshold, the software platform may deny the access request. In some examples, the cluster score may be determined using machine learning techniques. Based on determining the cluster score, the software platform may efficiently identify devices of the botnet and prevent brute force attacks, which may improve reliability of access for users of the application.