Risk Score Calculation for Credential Reuse Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The reuse of user credentials across multiple online domains poses a significant security risk for individuals and organizations, as unauthorized access can lead to costly and time-consuming issues, including the exposure of sensitive information.

Innovation Solution

A computer-implemented method and system that assesses security risks by detecting host locations accessed by user devices outside an organization's network, identifying matching user credentials, and calculating a risk score to determine potential security threats, enabling corrective security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users reuse credentials across multiple online domains, then ease of operation is improved, but security risk increases

Engineering Contradiction:
Improveease of operationVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary detection of credential reuse patterns by monitoring user authentication activities across multiple domains. Before a security incident occurs, the risk assessment system identifies users who reuse credentials and calculates risk scores, enabling preventive actions to be taken ahead of time to block potential unauthorized access attempts.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If credential reuse is monitored and assessed, then security risk is reduced, but device complexity increases

Engineering Contradiction:
Improvesecurity riskVSAvoiddevice complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The risk assessment system is designed as a multi-functional platform that performs credential monitoring, pattern recognition, risk scoring, and alert generation within a single integrated architecture. This universal system can assess security risks across multiple domains and user types without requiring separate specialized systems for each function, thereby managing complexity while maintaining comprehensive security monitoring.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If risk scores are calculated for all users, then measurement precision is improved, but loss of time increases

Engineering Contradiction:
Improvemeasurement precisionVSAvoidloss of time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies differentiated risk assessment strategies based on local characteristics of users and domains. Rather than uniformly assessing all users with equal depth, the system calculates risk scores with varying precision levels - performing detailed analysis for high-risk users while using simplified assessments for low-risk users. This localized approach maintains measurement precision where needed while reducing overall processing time.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10313386B1Systems and methods for assessing security risks of users of computer networks of organizations
Publication Date: 2019.06.04 CA TECH INC
  • US10313386B1 patent drawing
  • US10313386B1 patent drawing
  • US10313386B1 patent drawing

AI summary

The disclosed computer-implemented method for assessing security risks of users of computer networks of organizations may include (i) detecting, at a risk computing device, a location of a host electronically accessed by a user computing device, the host location having an electronic address outside of a computer network of an organization, (ii) identifying, at the risk computing device, a host user credential sent to the host location from the user computing device, (iii) determining, at the risk computing device, that the host user credential matches an organization user credential associated with the organization's computer network, and (iv) calculating, at the risk computing device, a risk score for a user of the user computing device based on the determination that the host user credential matches the organization user credential. Various other methods, systems, and computer-readable media are also disclosed.