Network Traffic Metadata Analysis for MFA Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-factor authentication methods are prone to security risks, and there is a need for better authentication systems to assess and mitigate cyber-risk in enterprise environments.

Innovation Solution

A method that determines a risk score for a communication network by analyzing network traffic metadata, constructing digital signatures, and comparing them to reference models for multi-factor and non-multi-factor authentication, using processes like dynamic time warping and cosine similarity to classify authentication processes and calculate a risk score.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication is implemented, then security reliability is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically detects whether MFA is being used by analyzing network traffic metadata without requiring user configuration or manual input. The detection process self-services by passively monitoring authentication patterns, timing characteristics, and traffic features to classify logins as MFA or non-MFA, eliminating the need for users to manually configure or report their authentication methods.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual security assessment processes with automated machine learning-based detection. Instead of requiring administrators to manually configure and monitor MFA deployment, the system uses ML models to automatically analyze network traffic patterns and determine MFA usage, substituting mechanical manual processes with automated computational analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If multi-factor authentication is implemented, then security reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoiduser authentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically detects whether MFA is being used by analyzing network traffic metadata without requiring user configuration or manual input. The detection process self-services by passively monitoring authentication patterns, timing characteristics, and traffic features to classify logins as MFA or non-MFA, eliminating the need for users to manually configure or report their authentication methods.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If network traffic analysis is performed to detect MFA usage, then measurement precision of authentication methods is improved, but device complexity and processing requirements worsen

Engineering Contradiction:
Improveauthentication method detection accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts only the essential features needed for MFA detection from network traffic metadata, such as timing characteristics, traffic patterns, and authentication response times. By extracting only the relevant features rather than analyzing complete traffic data, the system achieves high detection precision while reducing computational complexity and processing requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The ML detection model serves multiple functions: it classifies authentication methods, estimates MFA adoption rates, identifies security risks, and provides insights into user behavior patterns. This multi-functional approach consolidates multiple analysis tasks into a single unified system, reducing overall complexity while maintaining high measurement precision.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11552980B2Detection of multi-factor authentication and non-multi-factor authentication for risk assessment
Publication Date: 2023.01.10 CYBERLUCENT INC
  • US11552980B2 patent drawing
  • US11552980B2 patent drawing
  • US11552980B2 patent drawing

AI summary

Systems and methods are provided for determining whether or not users of a communication network are implementing Multi-Factor Authentication (MFA) when authenticating with an entity's business tools, applications, and cloud services. This information can be used as component in the calculation of a risk score that can help quantify and assess the risk posture of the entity. In some embodiments, network traffic flow metadata may be used to anonymously identify user data to assess the entity's use of MFA in determining enterprise risk that may not rely on questionnaires, surveys, manual data entry, and/or interviews. Embodiments of the application can produce a real-time analysis of the security risk of the system.