Dynamic Authentication System for Network Fraud Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication and authorization methods, including multifactor authentication and machine learning-based threat analysis, face challenges such as increased complexity, vulnerabilities to unauthorized access, and inefficiencies in detecting malicious behavior within network sessions, particularly due to static rules and outdated risk assessment models.

Innovation Solution

A system that monitors and analyzes real-time entity events to learn standard behavior patterns, detects aberrant behavior, and takes remedial action without human assistance, by building entity profiles using multi-dimensional arrays and considering multiple event parameters to dynamically adjust authentication requirements and authorization levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multifactor authentication is implemented to increase security, then authentication security is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authentication that adapts the number and type of factors required based on real-time risk assessment. The system monitors entity behavior, session characteristics, and contextual parameters to dynamically adjust authentication requirements, requiring more factors only when risk thresholds are exceeded, thereby maintaining security while reducing complexity for low-risk scenarios

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters (number of factors, type of factors) based on detected conditions and risk levels. By monitoring multiple parameters including entity behavior patterns, session duration, and access requests, the system adjusts authentication requirements to match the actual security risk, avoiding unnecessary complexity for routine operations

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If static rules are used for adaptive MFA, then ease of operation is improved, but detection precision of malicious behavior deteriorates

Engineering Contradiction:
Improveauthentication simplicityVSAvoidbehavior detection accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system employs machine learning models that automatically learn and adapt to entity behavior patterns without requiring manual rule configuration. The models self-adjust detection parameters based on observed behavior, session data, and attack patterns, eliminating the need for static rules while maintaining operational simplicity through automated decision-making

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors entity behavior and uses this feedback to refine risk assessment models in real-time. By analyzing session characteristics, access patterns, and anomaly detection results, the system dynamically adjusts authentication requirements and detection sensitivity, improving precision without requiring manual intervention or static rule sets

Inventive Principle:
Principle #23Feedback

3Ease of operation

If traditional authentication methods are used, then ease of operation is improved, but reliability against sophisticated attacks deteriorates

Engineering Contradiction:
Improvelogin simplicityVSAvoidprotection against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system maintains simple authentication for routine operations but dynamically introduces additional verification factors when risk indicators are detected. The authentication process adapts in real-time based on entity behavior, session context, and threat detection, preserving simplicity for legitimate users while strengthening protection against sophisticated attacks

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary risk assessment and behavior analysis before finalizing authentication decisions. By pre-monitoring entity patterns, session characteristics, and contextual parameters, the system can proactively adjust authentication requirements to prevent unauthorized access while maintaining smooth operation for legitimate users

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11902307B2Method and apparatus for network fraud detection and remediation through analytics
Publication Date: 2024.02.13 CYBER ARK SOFTWARE LTD
  • US11902307B2 patent drawing
  • US11902307B2 patent drawing
  • US11902307B2 patent drawing

AI summary

A system and method for assessing the identity fraud risk of an entity's (a user's, computer process's, or device's) behavior within a computer network and then to take appropriate action. The system uses real-time machine learning for its assessment. It records the entity's log-in behavior (conditions at log-in) and behavior once logged in to create an entity profile that helps identify behavior patterns. The system compares new entity behavior with the entity profile to determine a risk score and a confidence level for the behavior. If the risk score and confidence level indicate a credible identity fraud risk at log-in, the system can require more factors of authentication before log-in succeeds. If the system detects risky behavior after log-in, it can take remedial action such as ending the entity's session, curtailing the entity's privileges, or notifying a human administrator.