Filtering Egress Point Locations for Impossible Travel Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing impossible travel detection systems often generate false positives due to the complexities of network communication, where different locations are determined for a single user based on different network devices, leading to limited effectiveness in identifying actual impossible travel scenarios.

Innovation Solution

A method is introduced that utilizes a user behavior analytics service to filter out locations associated with enterprise egress points, which helps in accurately determining the real-world location of a user device, thereby mitigating false positives by distinguishing between valid and invalid location data for impossible travel detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network location identification is performed for all user accesses, then security monitoring capability is improved, but false positive rate increases due to egress point locations being misinterpreted as actual user locations

Engineering Contradiction:
Improveimpossible travel detection accuracyVSAvoidfalse positive alerts
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts and removes egress point location data from the set of locations used in impossible travel detection. By identifying locations associated with enterprise egress points and excluding them from analysis, the system eliminates the source of false positives while maintaining detection of actual impossible travel scenarios.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary classification process that distinguishes between egress point locations and actual user device locations. This intermediary step filters out network infrastructure locations before they can trigger false impossible travel alerts, allowing genuine security threats to be detected accurately.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If all user access locations are monitored for impossible travel, then security detection coverage is improved, but computing resources are wasted processing false positive scenarios

Engineering Contradiction:
Improvesecurity detection effectivenessVSAvoidcomputing resource consumption
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The system extracts and removes egress point locations from the monitoring dataset before analysis. By eliminating these locations that cannot possibly indicate real user travel, the system reduces unnecessary computing resource consumption while maintaining comprehensive monitoring of actual user device locations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary identification and filtering of egress point locations before impossible travel analysis is conducted. This preliminary action prevents wasteful processing of location data that would inevitably lead to false positives, optimizing computing resource utilization.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If location data from all network devices is used for detection, then detection comprehensiveness is improved, but false positive rate increases due to network infrastructure locations

Engineering Contradiction:
Improveuser location identification accuracyVSAvoidfalse positive alerts
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent extracts and removes location data associated with enterprise egress points from the comprehensive set of network device locations. This extraction eliminates the harmful false positive effect while preserving the comprehensive monitoring capability for actual user device locations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different quality treatment to different types of location data. Egress point locations are identified and excluded from impossible travel detection, while other user device locations are retained for analysis. This local quality differentiation ensures high measurement precision without generating false positives from network infrastructure.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3596908B1System to filter impossible user travel indicators
Publication Date: 2022.02.02 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3596908B1 patent drawingFigure 1~2
  • EP3596908B1 patent drawingFigure 3
  • EP3596908B1 patent drawingFigure 4

AI summary

Mitigating false positives for impossible travel alerts. A first user access location for a user is provided, for a first user access of computing resources identified using a first identification process, to a user behavior analytics service. The first identification process identifies a real world indicator of location for a device associated with the first user access. A second user location is provided for the user, for a second user access of computing resources, to the user behavior analytics service, using a second identification process. The second identification process identifies a location associated with an egress point to which communication to and from a device is routed to access computing resources, such that the user behavior analytics service receives a location associated with the egress point as the second user location. At the user behavior analytics service, the second user location is filtered from being used for impossible travel detection.