Browser Extension Detecting 2FA Gaps for Fraud Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods fail to effectively assess and mitigate fraud risks associated with users' adoption of two-factor authentication (2FA) across various online accounts, particularly in a digital environment where hacking is prevalent and fraud metrics are not adequately updated based on 2FA usage.

Innovation Solution

A web browser extension that identifies accounts on a computing device, detects navigation to third-party servers, and determines if 2FA is enabled or prompted, updating fraud metrics and sensitivity algorithms via an API, prompting users to opt into 2FA and adjusting fraud metric sensitivity based on the type of website, thereby enhancing security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If fraud metrics are not updated based on 2FA usage, then system complexity is reduced, but fraud risk assessment accuracy deteriorates

Engineering Contradiction:
Improvefraud risk assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system continuously monitors whether 2FA prompts are displayed to users and feeds this information back into the fraud risk assessment model. The browser extension detects the presence or absence of 2FA prompts and updates fraud metrics accordingly, creating a closed-loop feedback mechanism that improves assessment accuracy without requiring complex manual configuration.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The browser extension automatically detects and reports 2FA usage status without requiring manual intervention or complex system configuration. The system self-updates fraud metrics by monitoring web page content for 2FA prompt indicators, eliminating the need for complex manual data collection and processing procedures.

Inventive Principle:
Principle #25Self-service

2Reliability

If 2FA is not prompted to users, then ease of operation is improved, but security protection deteriorates

Engineering Contradiction:
Improveaccount securityVSAvoiduser operation convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The browser extension acts as an intermediary between the website and the user, automatically detecting when 2FA prompts should be displayed and presenting this information to users in a standardized manner. This intermediary layer ensures consistent security messaging without requiring users to manually check security settings or understand complex authentication configurations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If fraud algorithm sensitivity is not adjusted, then system stability is maintained, but fraud detection capability deteriorates

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidsystem stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The fraud algorithm sensitivity is dynamically adjusted based on real-time detection of 2FA usage patterns. When the system detects that 2FA prompts are not being displayed, it automatically increases fraud detection sensitivity for that user account. This dynamic adjustment allows the system to adapt to changing security conditions while maintaining overall stability through automated, rule-based sensitivity modulation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240388580A1Method and System for Detecting Two-Factor Authentication
Publication Date: 2024.11.21 CAPITAL ONE SERVICES LLC
  • US20240388580A1 patent drawing
  • US20240388580A1 patent drawing
  • US20240388580A1 patent drawing

AI summary

Embodiments disclosed herein generally related to a system and method for assessing a fraud risk. In one embodiment, a method for assessing a fraud risk is disclosed herein. A web browser extension executing on the computing device identifies an account associated with the computing device. The web browser extension detects that the computing device navigated to a web page hosted by a third party server. The web browser extension determines that the third party server prompted the computing device to opt into two-factor authentication functionality. The web browser extension determines that the computing device did not opt into the two-factor authentication functionality. The web browser extension prompts, via an application programming interface (API), an organization computing system to update a fraud metric associated with the account.