Network Security System with Risk-Based Authentication Restrictions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security is increasingly challenged by unauthorized access attempts, particularly in wireless networks, due to public discoverability and vulnerabilities in password security, which can lead to compromised network and data security.

Innovation Solution

A security system that detects failed authentication attempts, determines a risk score based on the number of attempts, and generates notifications to administrators when the risk score exceeds a threshold, applying network activity restrictions to devices that successfully authenticate after multiple failed attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If basic password security is used to protect wireless networks, then network accessibility is maintained, but network security deteriorates due to vulnerability to unauthorized access attempts

Engineering Contradiction:
Improvenetwork securityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by detecting and tracking failed authentication attempts before unauthorized access can be established. The security system monitors authentication attempts in real-time, calculates risk scores based on the number of failures, and prepares restriction measures in advance. When a device successfully authenticates after multiple failures, the system has already predetermined the application of network restrictions, preventing potential damage before it occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring authentication attempts and adjusting risk scores dynamically. The risk score is updated based on the number of failed attempts, and this feedback loop enables the system to adapt its security response. The notification system provides feedback to administrators about high-risk devices, enabling informed security decisions while maintaining automated response capabilities.

Inventive Principle:
Principle #23Feedback

2Reliability

If network restrictions are applied to devices with failed authentication attempts, then network security is improved, but network productivity deteriorates due to potential false positives affecting legitimate users

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies local quality by implementing differentiated security responses based on the specific risk profile of each device. Instead of uniformly restricting all devices with failed attempts, the system calculates individual risk scores and applies restrictions only to devices exceeding the threshold. This localized approach ensures that legitimate users with occasional authentication errors (such as typos) are not unnecessarily restricted, while truly suspicious devices are targeted for restriction.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system utilizes parameter changes by dynamically adjusting the risk score parameter based on the number of failed authentication attempts. The risk score serves as a variable parameter that changes with each failed attempt, allowing the system to adapt its security posture. The threshold parameter provides a configurable boundary that balances security and productivity, enabling administrators to adjust the sensitivity of the restriction mechanism based on their specific needs.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If continuous monitoring of authentication attempts is implemented, then detection precision is improved, but system complexity increases

Engineering Contradiction:
Improveunauthorized access detection accuracyVSAvoidsecurity system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically performing detection, risk assessment, and restriction application without requiring continuous administrator intervention. The security system autonomously monitors authentication attempts, calculates risk scores, identifies high-risk devices, and applies network restrictions automatically. This self-service capability reduces the operational complexity for administrators while maintaining high detection precision through continuous automated monitoring.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system applies segmentation by dividing the security monitoring function into discrete, manageable components: authentication attempt detection, risk score calculation, threshold comparison, notification generation, and restriction application. This modular segmentation reduces system complexity by making each component independent and easily implementable, while the collective operation of these segments achieves comprehensive monitoring with high detection precision.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12301632B2Systems and methods for network security
Publication Date: 2025.05.13 CAPITAL ONE SERVICES LLC
  • US12301632B2 patent drawing
  • US12301632B2 patent drawing
  • US12301632B2 patent drawing

AI summary

A security system for a network may be configured to detect one or more failed authentication attempts to access the network by at least one user device and determine the number of the failed authentication attempts. The system may determine a first risk score based on the number of failed authentication attempts and determine whether the first risk score is greater than or equal to a first risk score threshold and generate a first notification indicating that the user device is attempting to gain unauthorized access onto the network. The system may transmit the first notification to an administrator of the network, determine the user device is successfully authenticated to access the network after the number of failed authentication attempts has been detected, and apply a first set of network activity restrictions to the user device.