Dynamic Multi-Factor Authentication via Port Scanning Risk Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current multi-factor authentication systems rely heavily on single methods of verification, such as email or one-time codes, which can be compromised, leading to potential unauthorized access to multiple accounts. There is a need for a system that dynamically determines the necessary verification methods based on context and risk associated with each connection.
Innovation Solution
A system and method for risk analysis using port scanning to determine a required verification score for accessing network resources, which involves monitoring network traffic, scanning network ports at the intended destination, and requiring users to accumulate verification points through multiple verification methods to access the resource.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single verification method (email or one-time code) is used for authentication, then the authentication process is simple and fast, but the security is compromised when that single method is breached
Solution Approach 1:
The patent implements dynamic multi-factor authentication where the system automatically selects and adjusts verification methods based on real-time risk assessment. The authentication requirements change dynamically based on factors like destination risk level, user behavior patterns, and connection context, rather than using a fixed set of verification methods for all scenarios.
Solution Approach 2:
The system changes the parameters of authentication by adjusting the number and type of verification factors required based on the assessed risk level. Low-risk connections may require only one factor, while high-risk connections trigger multiple verification methods, effectively changing the authentication parameters to match the threat level.
2Reliability
If multiple verification methods are always required, then security is enhanced, but the authentication process becomes slower and more complex for users
Solution Approach 1:
The patent applies partial action by requiring only the necessary number of verification factors based on risk assessment. Instead of always requiring all possible verification methods, the system applies just enough authentication factors to achieve the required security level for each specific connection attempt, avoiding unnecessary time loss for low-risk scenarios.
Solution Approach 2:
The authentication process is made dynamic, adjusting the number of verification steps in real-time based on risk evaluation. The system starts with baseline verification and adds additional factors only when risk thresholds are exceeded, creating a flexible authentication flow that adapts to each connection attempt rather than following a rigid multi-step process for all users.
3Measurement precision
If port scanning is performed on all connection destinations, then risk assessment accuracy is improved, but the system resource consumption and processing time increase
Solution Approach 1:
The system performs preliminary risk assessment using available connection context information (such as known good destinations, user profiles, and historical data) before initiating full port scanning. This preliminary evaluation allows the system to skip scanning for low-risk connections while reserving comprehensive scanning for suspicious or high-value targets, optimizing the balance between accuracy and speed.
Solution Approach 2:
The patent applies local quality by performing different levels of scanning based on the specific characteristics of each connection destination. Instead of uniform scanning for all targets, the system adjusts the scanning depth and methodology according to the local context—using lightweight checks for trusted destinations and comprehensive scanning only when necessary, thereby improving efficiency without sacrificing accuracy where needed.
Data Source
AI summary
A system for risk analysis using port scanning for multi-factor authentication having a multi-dimensional time series data server configured to monitor and record a network's traffic data and to serve the traffic data to other modules and a directed computational graph module configured to scan open ports on connection destinations, analyze the scan results, and determine a verification score needed before granting access based at least in part on the analysis of the received responses. A plurality of verification methods build up a user's verification score to required level to gain access.


