Suspect Session Detection via Interactive Notification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer systems lack effective methods to identify and mitigate suspect interaction sessions, such as vishing attacks, which increase security risks and vulnerability for individuals, as they often require sensitive information or transactions.
Innovation Solution
A computer-based system that utilizes a natural language processing algorithm and machine learning to generate interaction notifications, identifying suspect sessions by analyzing session parameters and historical patterns, and automatically updates a database based on user responses to interactive communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a computer-based system monitors user activities and analyzes session parameters to identify suspect interaction sessions, then security detection capability is improved, but device complexity and processing requirements increase
Solution Approach 1:
The system segments the security monitoring function into distinct modules: a monitoring module that collects session parameters, a verification module that checks parameters against a database, and a notification module that alerts users. This segmentation allows each component to perform its specific function efficiently without requiring the entire system to be overly complex.
Solution Approach 2:
The patent introduces an intermediary database of known session interaction parameters that acts as a reference store. This database serves as a mediator between the monitored session parameters and the security determination logic, simplifying the comparison process by providing pre-stored patterns of suspicious activities.
2Extent of automation
If the system automatically generates interactive notifications using natural language processing and machine learning algorithms, then automation level is improved, but computational resource consumption increases
Solution Approach 1:
The system performs preliminary actions by pre-processing and storing known session interaction parameters in a database before actual security monitoring begins. This preliminary setup includes categorizing suspicious patterns and creating reference profiles, which reduces the computational burden during real-time monitoring and notification generation.
Solution Approach 2:
The system implements feedback mechanisms where user responses to interactive notifications are automatically processed and used to update the database of known session parameters. This feedback loop allows the system to learn from actual interactions and improve future detection accuracy without requiring increased computational resources for basic pattern recognition.
3Measurement precision
If the system continuously monitors user activities across multiple computing devices for a predetermined period, then detection accuracy is improved, but loss of time and user privacy increases
Solution Approach 1:
The system extracts only the essential session parameters needed for security verification from the full set of user activities. Instead of analyzing all user actions, it selectively monitors specific parameters such as communication patterns, transaction behaviors, and device interaction sequences that are most indicative of suspicious activities.
Solution Approach 2:
The monitoring is conducted periodically over a predetermined time frame rather than continuously without interruption. The system collects session parameters at regular intervals and performs verification at defined checkpoints, balancing detection accuracy with reduced time loss and minimized user awareness of monitoring.
Data Source
AI summary
In some embodiments, the present disclosure provides an exemplary method that may include steps of obtaining a permission from the user to monitor a plurality of activities executed within the computing device; receiving monitoring data of the activities executed within the plurality of computing devices for a predetermined period of time; identifying incoming interaction sessions across the plurality of computing devices; verifying one common session parameter associated with the incoming interaction sessions to identify the incoming interaction sessions as suspect interaction sessions; determining a frequency metric for the suspect interaction sessions; determining a threshold value for the frequency metric; receiving new monitoring data; determining that the new incoming interaction session has at least one common session interaction parameter with the suspect interaction sessions; automatically generating an interaction notification for transmission to the computing device; receiving a response to the interactive communication; and updating the database of known session interaction parameters.


