Security Compute Device for Cross-Cloud Travel Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Detecting impossible travel events across multiple cloud-based application services is complex due to the distributed nature of these services, which can be hindered by virtual private networks, variations in IP address reporting, and differences in device distributions, posing a security risk for entities using these services.
Innovation Solution
A security compute device collects data from multiple cloud-based applications, normalizes it, and uses machine learning models to identify trusted geolocation clusters and ISPs, flagging activities outside these clusters or associated with untrusted ISPs, and verifies transitions that exceed a speed threshold to detect potential security threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional impossible travel detection is applied to multiple cloud-based application services, then security risk is reduced, but detection complexity increases due to distributed nature of services
Solution Approach 1:
The patent segments the detection system into multiple specialized components: geolocation analysis module, IP address analysis module, device fingerprinting module, and behavior analysis module. Each module handles specific aspects of account activity analysis independently, then results are integrated to make comprehensive security decisions. This segmentation reduces overall system complexity by dividing the challenging multi-cloud detection problem into manageable specialized sub-tasks.
Solution Approach 2:
The patent introduces an intermediary security service that acts as a mediator between multiple cloud-based application services and the detection system. This intermediary collects standardized account activity data from various cloud services, normalizes different data formats, and presents unified information to the detection algorithms. This intermediary layer simplifies the detection complexity by providing a consistent interface despite the distributed nature of cloud services.
2Measurement precision
If detection considers multiple factors (geolocation, IP address, device type), then detection accuracy improves, but false positives increase due to legitimate travel and device variations
Solution Approach 1:
The patent implements dynamic adjustment of detection parameters based on learned user behavior patterns. The system continuously adapts geolocation thresholds, time window parameters, and device compatibility criteria based on historical account activity. This dynamic approach allows the system to distinguish between legitimate travel (which follows predictable patterns) and impossible travel (which violates established behavior), thereby reducing false positives while maintaining high detection accuracy.
Solution Approach 2:
The patent incorporates feedback mechanisms where detection results and user responses are fed back into the system to refine future detections. When users confirm or deny suspected impossible travel events, this feedback adjusts the detection algorithms' sensitivity and parameter settings. This feedback loop enables the system to learn from false positives and improve its ability to distinguish legitimate multi-device/multi-location usage from compromised accounts, thereby reducing false positives while maintaining accuracy.
3Speed
If real-time monitoring is implemented across all cloud services, then compromised accounts are detected faster, but computational resources are consumed
Solution Approach 1:
The patent implements partial monitoring by focusing computational resources on high-risk account activities and suspicious patterns rather than uniformly monitoring all activities across all cloud services. The system applies enhanced monitoring selectively to accounts showing anomalous behavior indicators, while using lighter-weight monitoring for normal accounts. This partial action approach maintains fast detection speed for compromised accounts while significantly reducing overall computational resource consumption.
Solution Approach 2:
The patent performs preliminary analysis of account activity data to identify suspicious patterns before initiating full impossible travel detection. The system uses lightweight pre-processing to filter out normal activities and only triggers comprehensive detection algorithms when anomaly indicators are present. This preliminary action enables faster detection of compromised accounts by avoiding unnecessary computational overhead for normal accounts, thereby balancing detection speed with resource efficiency.
Data Source
AI summary
For an entity having access to a plurality of independent cloud-based applications and including a member having access to at least one cloud-based application from the plurality of independent cloud-based applications via at least one member account associated with the at least one cloud-based application, a plurality of activities performed using the at least one member account can be analyzed with at least one machine learning model configured to flag an activity of an activity type from the plurality of activities in response to (1) the activity being associated with a geolocation outside a trusted geolocation cluster at an entity level for the entity, a trusted geolocation cluster at an activity level for the activity type, and/or a trusted geolocation cluster at a member level for the member, or (2) the activity being associated with an internet service provider (ISP) that is not recognized as being (a) a trusted ISP at the entity level for the entity, (b) a trusted ISP at the activity level for the activity type, and/or (c) a trusted ISP at the member level for the member.


