MFA Fatigue Attack Detector for Selective Traffic Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication (MFA) systems are vulnerable to MFA fatigue attacks, where users are overwhelmed with repeated MFA prompts, leading to potential security breaches and user inconvenience, as tightening MFA parameters can introduce inconvenience and lead to behaviors more susceptible to social engineering attacks.

Innovation Solution

An MFA fatigue attack detector is deployed on a firewall to correlate MFA failure events and evaluate them against a defined detection rule, determining whether a user is likely a target of an MFA fatigue attack. The detector analyzes network traffic and API calls to identify failure events and set thresholds that avoid false positives while protecting users against MFA fatigue attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MFA parameters are tightened to prevent fatigue attacks, then security is improved, but user convenience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary system (the MFA fatigue attack detector and blocking mechanism) that sits between the attacker and the MFA system. This intermediary analyzes MFA challenge patterns, identifies fatigue attacks, and selectively blocks only the malicious traffic while allowing legitimate user authentication to proceed normally. This resolves the contradiction by providing enhanced security without interfering with legitimate user operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms by monitoring MFA challenge patterns and user behavior in real-time. It analyzes the frequency, timing, and pattern of MFA requests to detect fatigue attacks, then adjusts blocking decisions accordingly. This feedback loop allows the system to maintain high security while avoiding false positives that would inconvenience legitimate users.

Inventive Principle:
Principle #23Feedback

2Reliability

If MFA parameters are tightened to prevent fatigue attacks, then attack resistance is improved, but false positives increase

Engineering Contradiction:
Improveattack resistanceVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies local quality by analyzing different aspects of MFA traffic patterns with different sensitivity thresholds for different scenarios. Instead of using a single rigid threshold, the system examines multiple parameters (time intervals, frequency patterns, user behavior context) and applies appropriate detection sensitivity locally to each situation, reducing false positives while maintaining attack detection capability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts detection parameters based on observed traffic patterns and contextual information. It modifies thresholds and detection criteria in real-time based on the specific characteristics of each MFA session, allowing for precise differentiation between legitimate users and attackers without relying on fixed, overly stringent parameters.

Inventive Principle:
Principle #35Parameter changes

3Object-generated harmful factors

If repeated MFA prompts are sent to overwhelm users, then attack success is improved, but user frustration increases

Engineering Contradiction:
Improveattack successVSAvoiduser frustration
Core Design Contradiction:
Object-generated harmful factorsVSObject-affected harmful factors

Solution Approach 1:

The patent converts the harmful effect of repeated MFA prompts (which frustrates users and enables fatigue attacks) into a beneficial detection signal. By monitoring and analyzing these repeated prompts, the system identifies fatigue attack patterns and blocks them selectively. The very same repeated prompts that would normally frustrate users become the basis for detecting and preventing attacks, eliminating the harmful effect while preserving user convenience.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS20250202933A1Multi-factor authentication fatigue attack detection and blocking
Publication Date: 2025.06.19 PALO ALTO NETWORKS INC
  • US20250202933A1 patent drawing
  • US20250202933A1 patent drawing
  • US20250202933A1 patent drawing

AI summary

An MFA fatigue attack detector has been created that correlates MFA failure events for evaluation against a MFA fatigue attack detection rule to determine whether a user is likely a target of a MFA fatigue attack. The MFA fatigue attack detection rule is defined based on correlation of failure events for a MFA implementation and a determination of a threshold that can be considered a boundary marking the transition of behavior, as represented by the MFA failure events, from non-suspicious to suspicious. To determine what events to correlate and the thresholds for different MFA implementations, network traffic and/or API calls for different IdPs are analyzed. Based on the analysis, failure events are identified and thresholds of correlated failure events (e.g., a time window and number of failure events within the time window) are determined for the implementations that avoid false positives while still protecting users against MFA fatigue attacks.