Impossible Travel Detection via On-Premises Location Estimation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In computing environments, especially in multi-site organization networks, it is challenging to detect impossible travel scenarios due to the obfuscation of real-world locations, making it difficult to identify potential security breaches from compromised credentials.
Innovation Solution
A computer-implemented method that aggregates connection information from remote devices to estimate the location of on-premises sites within an organization network, using geolocation services and machine learning techniques to detect impossible travel by analyzing location and time data from user connections, and providing alerts for potential security breaches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If impossible travel detection is implemented in on-premises network environments, then security against compromised credentials is improved, but difficulty in identifying real-world locations worsens
Solution Approach 1:
The patent uses network connection information as an intermediary to infer real-world locations. Instead of directly accessing GPS or physical location data, the system uses connection events, IP addresses, and network metadata as mediators to estimate user locations and detect impossible travel scenarios in on-premises environments where direct location identification is difficult.
Solution Approach 2:
The patent replaces traditional mechanical location detection methods (GPS, physical tracking) with network-based detection mechanisms. By substituting physical location tracking with network connection analysis, the system can detect impossible travel in on-premises environments where physical location sensors are unavailable or obscured.
2Measurement precision
If connection information from multiple remote devices is aggregated to estimate on-premises site location, then location estimation accuracy is improved, but data processing complexity worsens
Solution Approach 1:
The patent merges connection information from multiple remote devices to estimate the location of on-premises sites. By combining data from multiple sources (connection events, IP addresses, timestamps), the system improves location estimation accuracy while distributing the data processing burden across the network infrastructure.
Solution Approach 2:
The patent creates a multi-functional system that uses the same connection information aggregation mechanism for multiple purposes: estimating on-premises site locations, detecting impossible travel, and identifying security breaches. This universal approach reduces overall system complexity by reusing data processing pipelines across different security functions.
3Reliability
If analysis of location and time data from user connections is performed to detect impossible travel, then detection capability is improved, but computational resources required worsen
Solution Approach 1:
The patent applies partial action by analyzing only the necessary subset of connection data required for impossible travel detection. Instead of processing all available network data, the system focuses on location and time information from connection events, reducing computational overhead while maintaining detection effectiveness.
Solution Approach 2:
The system uses existing network infrastructure and logged connection data to perform detection, rather than requiring dedicated computational resources. By leveraging already-collected network metadata and existing authentication logs, the system reduces additional energy consumption while maintaining detection capability.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Determining impossible travel for a specific user entity associated with an on-premises site. A method includes identifying an estimated location of an on-premises site associated with an organization network. Identifying the estimated location of an on-premises site comprises aggregating connection information of remote devices, remote from the on-premises site connecting to the on-premises site. Information related to an on-premises connection event is identified including the estimated location, time information, and a first user identification for an entity. Information is identified related to a different connection event. The information comprises location information, time information and a second user identification for the entity. The information related to the on-premises connection event and the information related to the different connection event are used to detect impossible travel for the entity. An alert indicating an impossible travel condition is provided.