Security Agent MFA Verification for Suspicious Process Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security agents struggle to differentiate between malicious and benign processes on computing devices, leading to either hampered user experience or unchecked malware activity when blocking or allowing execution.
Innovation Solution
Implementing a security agent that initiates multifactor authentication (MFA) upon detecting security triggers, prompting the user to confirm the legitimacy of the process and verifying the user's identity through MFA, involving multiple devices and authentication methods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a security agent blocks execution of suspected processes, then system security is improved, but user experience and system operation are hampered
Solution Approach 1:
The patent introduces multifactor authentication (MFA) as an intermediary mechanism between the security agent and the process execution decision. When a security trigger occurs, the system doesn't immediately block the process but rather initiates MFA verification as an intermediate step. This mediator allows the system to maintain security awareness while giving users a chance to verify legitimate actions, thus resolving the contradiction between security and user experience.
Solution Approach 2:
The patent implements a feedback loop where the security agent monitors process activity, detects security triggers, and seeks user confirmation through MFA. The user's verification response feeds back into the system to make an informed decision about process execution. This feedback mechanism allows the system to learn from user input and adjust its blocking behavior accordingly, balancing security with operational continuity.
2Ease of operation
If a security agent allows continued execution of suspected processes, then user experience is maintained, but unchecked malware activity may occur
Solution Approach 1:
MFA serves as a protective intermediary that stands between allowing process execution and potential malware activity. Instead of blindly allowing all processes, the system uses MFA verification as an intermediate check that authenticates user intent. This mediator enables the system to maintain operational flow while filtering out unauthorized or malicious processes through rigorous authentication.
Solution Approach 2:
The patent applies preliminary action by initiating MFA verification before allowing the suspected process to execute. The security agent performs preliminary authentication checks and user confirmation steps prior to granting execution permission. This preliminary action ensures that only verified legitimate processes are allowed to run, preventing unchecked malware activity while maintaining normal system operation.
3Measurement precision
If multifactor authentication is initiated for every security trigger, then accuracy in distinguishing malicious and benign processes is improved, but system complexity and authentication time increase
Solution Approach 1:
The patent applies local quality by implementing MFA only at specific critical points where security triggers are detected, rather than applying authentication universally to all processes. The system evaluates the local context of each process activity and initiates MFA only when security triggers occur, such as file access to sensitive locations or execution of suspicious processes. This targeted approach improves detection accuracy for malicious activities while minimizing unnecessary authentication complexity for legitimate operations.
Solution Approach 2:
The system dynamically changes the authentication parameter based on the detected security trigger type and severity. Different security triggers may result in different MFA verification depths or methods. The system adjusts the authentication parameters adaptively, initiating MFA only when the security risk threshold is crossed, thereby improving detection accuracy for high-risk activities while reducing overall system complexity by avoiding unnecessary authentication for low-risk events.
4Measurement precision
If multifactor authentication is initiated for every security trigger, then detection accuracy is improved, but time for authentication and process execution increases
Solution Approach 1:
The patent implements local quality by applying MFA verification only at specific local points where security triggers are detected, rather than continuously authenticating all process execution. The system identifies critical security moments (such as access to sensitive files or execution of unknown processes) and initiates MFA only at these localized points. This approach improves detection accuracy for malicious activities while minimizing authentication time delays for legitimate processes that do not trigger security alerts.
Solution Approach 2:
The system performs preliminary security monitoring and trigger detection before initiating MFA authentication. By continuously monitoring process behavior and identifying security triggers in advance, the system can prepare for rapid MFA verification when needed. This preliminary action reduces the overall time required by ensuring that authentication is only initiated when security concerns are already identified, rather than requiring continuous authentication for all operations.
Data Source
AI summary
A security agent configured to initiate multifactor authentication (MFA) in response to security triggers occurring on a computing device. Upon occurrence of a security trigger, the security agent delays action associated with a process on the computing device and provides, to a display of a user of the computing device, a prompt asking if the security trigger resulted from an action of the user. The security agent then initiates MFA with an MFA provider to authenticate the user and, based at least on a result of the MFA and the user answer to the prompt, takes further action. The user answer may be provided separately from the MFA or through successful completion of the MFA.


