Credential Sharing Detection System for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Standalone mobile applications that detect and share communication network login credentials introduce severe security vulnerabilities, as fraudsters can access networks using leaked credentials, posing a risk to both the mobile device and the communication network.

Innovation Solution

A detection and defense system that simulates a request for network passwords and user credentials from a public cloud repository, using a conventional application on a mobile device or virtual machine, establishing a dedicated communication tunnel to detect potential security breaches and alert network administrators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile devices share network credentials through standalone applications, then network connectivity and ease of access are improved, but security vulnerabilities and risk of unauthorized access increase

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary detection by simulating credential requests before actual breaches occur. The detection system proactively monitors for patterns indicating compromised credentials, allowing preventive action to be taken before fraudsters successfully access networks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where credential usage patterns are monitored, analyzed, and reported back to network administrators. This feedback mechanism enables real-time detection of anomalous behavior and automated responses to potential breaches.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If credential sharing applications are used to connect to communication networks, then device functionality is enhanced, but detection of security breaches becomes more difficult

Engineering Contradiction:
Improvedevice functionalityVSAvoidsecurity breach detection
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The detection system acts as an intermediary between the credential sharing application and the network. It intercepts and analyzes credential requests and usage patterns, providing a layer of monitoring that makes breach detection easier despite the complexity of credential sharing functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates simulated copies of credential request patterns to analyze and detect actual breaches. By monitoring for patterns that match known breach scenarios, the system can detect security issues without interfering with legitimate credential sharing operations.

Inventive Principle:
Principle #26Copying

3Measurement precision

If network administrators manually monitor for credential leaks, then security response accuracy is improved, but time required for detection and response increases

Engineering Contradiction:
Improvesecurity response accuracyVSAvoiddetection and response time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The detection system performs self-service monitoring and analysis of credential patterns without requiring constant human intervention. It automatically detects anomalies, generates reports, and can trigger responses, reducing the time administrators need to spend on manual monitoring while maintaining high accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system provides continuous automated monitoring of credential usage patterns, ensuring that security detection is an ongoing process rather than periodic manual checks. This continuous action eliminates detection gaps and reduces response time by immediately identifying and reporting breaches.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11722898B2Detection and defense system of a network credential sharing application
Publication Date: 2023.08.08 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11722898B2 patent drawing
  • US11722898B2 patent drawing
  • US11722898B2 patent drawing

AI summary

Systems and methods are provided for a detection and defense system relating to a network connection sharing application. For example, the system can simulate a request for a network password using a conventional application that shares this information. The application may be implemented on, for example, a mobile device or a virtual machine (VM). In some embodiments, the mobile device/VM attempts to establish a network connection to an access point (AP) using the shared password over a tunnel established between the AP and mobile device/VM. If the mobile device/VM can connect to the AP, an assumption may be made that the user credentials have been leaked and a potential security risk exists. An alert can be sent to a network administrator of the communication network (e.g., to perform an action, etc.). The action may include, for example, changing the password, removing access from one or more users, and the like.