Credential Access Control via Anomalous Application Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security systems often falsely block legitimate access to credentials while failing to identify vulnerable applications, leading to ineffective detection of unauthorized access attempts.

Innovation Solution

A computer-implemented method and system that maintains a set of applications exhibiting anomalous behavior, monitors these applications for attempts to access digital credentials, automatically detects such attempts, and performs security actions to secure the credentials, including alerting administrators and updating applications to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security systems block all application access to credentials, then security against credential theft is improved, but legitimate application access to credentials is blocked

Engineering Contradiction:
Improvesecurity against credential theftVSAvoidlegitimate application access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security system segments applications into different categories based on their credential access patterns and risk profiles. High-risk applications are monitored more closely while low-risk applications can access credentials more freely, resolving the contradiction by applying different security levels to different applications rather than blocking all access uniformly

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different security controls to different applications based on their specific characteristics and historical behavior. Each application receives a tailored security approach rather than a blanket blocking policy, allowing legitimate applications to function while preventing credential theft

Inventive Principle:
Principle #3Local quality

2Measurement precision

If traditional security systems monitor all applications for credential access, then detection of unauthorized access is improved, but system performance and resource usage deteriorate

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system applies partial monitoring by focusing surveillance resources on applications identified as high-risk or exhibiting suspicious behavior patterns. Instead of monitoring all applications equally, the system concentrates detection efforts where they are most needed, maintaining high detection accuracy while reducing overall system resource consumption

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

Applications are automatically evaluated and categorized based on their own historical behavior patterns and characteristics. The system self-adjusts which applications require monitoring based on observed credential access patterns, eliminating the need for continuous full-system monitoring while maintaining detection effectiveness

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional security systems block credential access, then prevention of credential misuse is improved, but identification of vulnerable applications deteriorates

Engineering Contradiction:
Improveprevention of credential misuseVSAvoididentification of vulnerable applications
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary analysis of application behavior patterns before blocking credential access. By monitoring and evaluating applications in advance, the system identifies vulnerable applications and assigns appropriate security controls, ensuring both prevention of credential misuse and accurate identification of vulnerable applications

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors credential access patterns and uses this feedback to refine its identification of vulnerable applications. By analyzing actual access behavior rather than relying solely on static blocking rules, the system improves both prevention effectiveness and vulnerability detection accuracy

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10769267B1Systems and methods for controlling access to credentials
Publication Date: 2020.09.08 CA TECH INC
  • US10769267B1 patent drawing
  • US10769267B1 patent drawing
  • US10769267B1 patent drawing

AI summary

A computer-implemented method for controlling access to credentials may include (i) maintaining, by a computing device, a set of applications for which attempting to access digital credentials comprises anomalous behavior, (ii) monitoring, by the computing device, each application within the set of applications for attempts to access digital credentials, (iii) automatically detecting, while monitoring for attempts to access digital credentials, an attempt of an application in the set of applications to access a digital credential, and (iv) performing, in response to detecting the attempt to access the digital credential, a security action to secure the digital credential. Various other methods, systems, and computer-readable media are also disclosed.