Dynamic Risk Score for Compromised Login Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing number of credential breaches on the dark web poses a significant risk for customers, as compromised login credentials can be reused across multiple service providers, leading to increased likelihood of fraud and unauthorized access, with existing security measures failing to provide real-time, dynamic risk detection and mitigation.
Innovation Solution
A machine learning-based system that aggregates data from the dark web, deep web, and surface web to calculate a dynamic Risk Score for customer login credentials, incorporating unique authentication controls of service providers, allowing for real-time risk detection and preemptive mitigation by modifying authentication requirements or suspending services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional static security measures are used, then implementation is simple, but real-time risk detection capability is insufficient
Solution Approach 1:
The patent implements dynamic risk scoring that continuously updates based on real-time dark web data, authentication attempt patterns, and credential compromise indicators. The system transitions from static security rules to dynamic, adaptive risk assessment that adjusts authentication requirements based on current threat levels and individual user behavior patterns.
Solution Approach 2:
The system performs preliminary risk assessment by continuously monitoring dark web sources for compromised credentials before they are used for unauthorized access. By detecting credential leaks in advance and pre-calculating risk scores, the system can proactively implement mitigations such as requiring additional authentication factors before compromise occurs.
2Measurement precision
If continuous dark web monitoring is implemented, then risk detection accuracy improves, but computational resources and time increase
Solution Approach 1:
The patent applies local quality by focusing monitoring efforts on specific high-value targets and relevant threat indicators rather than uniformly monitoring all data. The system adjusts monitoring intensity and data collection frequency based on individual user risk profiles, authentication patterns, and current threat intelligence, optimizing resource allocation to where it provides maximum security value.
Solution Approach 2:
The system dynamically changes monitoring parameters such as data collection frequency, analysis depth, and alert thresholds based on risk levels. During low-risk periods, monitoring operates at baseline levels to conserve resources. When threat indicators increase or compromise events are detected, the system intensifies monitoring and analysis to maintain high detection accuracy while managing computational load.
3Reliability
If dynamic risk scoring is implemented, then security response effectiveness improves, but authentication process complexity increases
Solution Approach 1:
The patent segments the authentication process into multiple risk-based stages. Users experiencing low-risk authentication attempts complete simple single-factor login. When risk scores exceed thresholds, the system progressively introduces additional authentication factors such as multi-factor authentication, biometric verification, or security questions, creating a segmented authentication journey that adapts to detected threat levels.
Solution Approach 2:
The system introduces an intermediary risk assessment layer between the user and the authentication system. This intermediary continuously evaluates risk based on dark web monitoring, authentication patterns, and user behavior, then mediates the authentication process by selectively applying additional verification steps. This intermediary layer transparently manages complexity while maintaining user-friendly authentication for low-risk scenarios.
Data Source
AI summary
This invention relates to a process for detecting and mitigating risk generated when a customer's log-in credentials are compromised. A significant majority of stolen credentials and customer's personally identifiable information data eventually make their way to the dark web. By dynamically monitoring the dark web and combining the analysis with related information about the user and their credentials on the deep web and the surface web, through a machine learning model, a service provider pre-emptively or otherwise can act to mitigate the risk arising from such compromise of said customer log-in credentials.


