Insecure App Credential Transfer Risk Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise computer systems face security risks due to users storing sensitive information, such as passwords, in insecure applications and transferring them to secure fields, which can be accessed by nefarious actors, leading to potential attacks.
Innovation Solution
Implementing event listeners on computing devices to detect copy and paste events, identifying insecure source applications, and performing risk mitigation actions, such as locking accounts or prompting password resets, while sending telemetry data to an analytic server for further risk assessment and dashboard generation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users store credentials in insecure applications for convenience, then ease of operation is improved, but security reliability deteriorates
Solution Approach 1:
The patent introduces an intermediary security system that monitors and controls the interaction between insecure applications and secure systems. Event listeners act as mediators to detect copy-paste operations, and a risk assessment system serves as an intermediary to evaluate and mitigate security risks before allowing credential transfer, thus enabling convenient operation while maintaining security reliability
Solution Approach 2:
The patent implements feedback mechanisms where the system continuously monitors user actions, assesses security risks in real-time, and provides responsive mitigation actions. The risk assessment system receives feedback from event listeners about copy-paste operations and responds with appropriate security measures, creating a dynamic feedback loop that maintains security while allowing legitimate operations
2Reliability
If the system monitors copy and paste events to detect insecure transfers, then security reliability is improved, but device complexity increases
Solution Approach 1:
The patent segments the security monitoring system into distinct modular components: event listeners that detect copy-paste operations, a risk assessment system that evaluates detected operations, and mitigation systems that respond to assessed risks. This segmentation allows each component to perform its specific function independently, improving security reliability while managing device complexity through modular architecture
Solution Approach 2:
The patent applies partial monitoring by focusing event listeners specifically on copy and paste events related to credential fields, rather than monitoring all system operations. The risk assessment system also applies partial action by evaluating only the specific risk factors relevant to credential theft, thus improving security reliability without unnecessarily increasing device complexity through excessive monitoring
Data Source
AI summary
Examples described herein attempt to mitigate risk associated with digitally storing sensitive information (e.g., passwords) in insecure applications and transferring the stored sensitive information to a sensitive information field (e.g., a password field in a login page). A computing device may detect a transfer to a sensitive field. The computing device may determine if a source application for the transfer is an insecure application. If the source application is an insecure application, the computing device may provide a risk mitigation action. The computing device may also transmit to an analytic server telemetry data comprising the identification of the source application, identification of a target application containing the sensitive information field, and a username associated with the computing device. The analytic server may calculate risk score based on the received telemetry data and provide further risk mitigation actions to the computing device.


