Fictitious Account Generation for Malicious Activity Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures are inadequate in preventing account takeovers and subsequent fraudulent activities, as they often focus on blocking malicious actors after an account has been compromised, failing to effectively deter or track their actions.
Innovation Solution
The implementation of fictitious accounts that mimic real accounts, allowing malicious actors to log in and engage in monitored activities, thereby tracking their behavior and preventing further unauthorized access while protecting legitimate user data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security measures (blocking, credential resetting) are used to prevent account takeovers, then account security is improved, but the ability to detect and track malicious activities is reduced
Solution Approach 1:
The system creates a fictitious account that copies the essential characteristics of the compromised account, allowing malicious actors to believe they have successfully taken over the real account. This copy enables monitoring and tracking of malicious activities without exposing the actual account data or functionality, thus maintaining security while preserving detection capabilities
Solution Approach 2:
The fictitious account serves as an intermediary between the malicious actor and the real account system. It mediates by providing a safe environment for monitoring malicious behavior while preventing direct access to the real account, thus resolving the contradiction between security and detection
2Loss of information
If fictitious accounts are created to monitor malicious activities, then detection capability is improved, but system complexity increases
Solution Approach 1:
The system segments account functionality by creating a separate fictitious account instance for each suspected compromised account. This segmentation isolates monitoring operations from the main system, allowing complex detection capabilities to be implemented in discrete, manageable units that can be independently managed and scaled
3Loss of information
If access is granted to suspected compromised accounts, then malicious activity tracking is improved, but security risk increases
Solution Approach 1:
The system converts the harmful situation of potential account compromise into a beneficial monitoring opportunity by creating fictitious accounts. Malicious actors believe they have successfully compromised accounts, but instead they are granted access to controlled environments where their activities are tracked and analyzed, transforming security threats into intelligence gathering opportunities
Solution Approach 2:
The fictitious accounts have modified parameters compared to real accounts - they lack certain functionalities, have restricted access levels, and include embedded monitoring capabilities. These parameter changes enable safe tracking of malicious activities while preventing actual harm to the real account system
Data Source
AI summary
Methods and systems for fictitious account generation on detection of account takeover conditions are described. A login attempt may be detected and determined to indicate fraud, such as when the login attempt is accompanied by many failed login attempts or is from an untrusted or known malicious endpoint. A fictitious account may be generated, which may include falsified account data and may limit account functionality to prevent unauthorized and fraudulent use of the account. The computing device that performs the login attempt may be routed and permitted to log in to the fictitious account, where the service provider or another computing entity may then monitor activity and usage of the fictitious account by the potentially malicious party. The fictitious account may be maintained so that other actors using the account may access the account and their activity also monitored.


