Real-Time Risk Assessment Caching for Online Activity Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in detecting and mitigating high-risk online activities in real-time, such as command and control beaconing, lateral movement of assets, and denial of service attacks, which can lead to loss of control of computing devices and digital assets.
Innovation Solution
A computer-implemented method and system that determines risk assessments for online activities using a prediction model applied to data defining the activities, updating in-memory storage with risk scores and categories, and denying access to computing platforms when high-risk activities are detected, employing a risk analysis subsystem and access control module to block malicious access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If real-time risk assessment is performed for all online activities, then system security is improved, but processing time and computational resources increase
Solution Approach 1:
The system pre-calculates and stores risk assessments in an in-memory cache before they are needed for actual access decisions. Risk assessments are computed in advance using prediction models and stored for rapid retrieval, eliminating the need to perform full risk calculations in real-time when access requests occur.
Solution Approach 2:
The risk assessment system is divided into distinct components: a prediction model for calculating risk scores, an in-memory cache for storing assessments, and a cache validation mechanism for ensuring data freshness. This segmentation allows each component to operate independently and optimally.
2Measurement precision
If comprehensive risk assessment data is stored in memory, then detection accuracy is improved, but memory usage and system resources increase
Solution Approach 1:
The system stores only the most critical risk assessment data in the in-memory cache rather than maintaining complete historical records. By storing partial risk assessment information that is most relevant for real-time decision-making, the system achieves high detection accuracy while limiting memory consumption to essential data only.
3Speed
If risk assessments are cached in memory, then access speed is improved, but data freshness and reliability may deteriorate
Solution Approach 1:
The system implements a cache validation mechanism that continuously monitors and verifies the freshness of cached risk assessments. When accessing cached data, the system validates whether the assessment is still current and reliable, providing feedback to determine whether to use the cached value or recalculate the risk assessment.
Data Source
AI summary
Technologies are provided for detection and mitigation of high-risk online activity. The detection and mitigation can be implemented in real-time. In some embodiments, a computing system can determine that a risk assessment for an online activity is unavailable from an in-memory storage. The computing system can obtain the risk assessment for the online activity from a second computing system configured to apply a prediction model to data defining the online activity. The risk assessment can comprise a risk score and a risk category. The computing system can update the in-memory storage to incorporate the data and the risk assessment, and can determine that the risk assessment is indicative of the online activity being high-risk activity. The computing system can then cause denial of access to a computing platform to a user device associated with the online activity.


