Suspicious User Detection via Email Analysis and Behavior Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing platforms, it is challenging to trace and prevent attacks during free-trial or freemium usage periods when users do not provide specific information, making it difficult for security systems to identify the source of attacks.
Innovation Solution
A method and system that classify suspicious users by analyzing email addresses for validity and script-generation likelihood, and comparing usage behavior against a reference model to detect abnormal activity, ultimately rejecting subsequent access requests from suspicious users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users are allowed to access the network without providing specific user information during free-trial or freemium periods, then user convenience and network accessibility are improved, but security traceability and attack source identification deteriorate
Solution Approach 1:
The patent uses email addresses as an intermediary identifier to bridge the gap between anonymous user access and security traceability. By analyzing email domain validity, script-generation likelihood, and usage behavior patterns, the system can identify suspicious users without requiring traditional personal information, thus maintaining user convenience while improving security traceability
Solution Approach 2:
The system implements feedback mechanisms by continuously monitoring usage behavior and comparing it against established patterns. When abnormal behavior is detected, the system can trace back to the email identifier and take appropriate security measures, creating a closed-loop feedback system that maintains security without compromising user convenience during free-trial periods
2Reliability
If traditional security measures requiring specific user information are implemented, then security traceability is improved, but user convenience and network accessibility deteriorate
Solution Approach 1:
The patent changes the identification parameter from traditional personal information (name, address, phone) to email-based identifiers. This parameter change allows the system to maintain security traceability through email domain analysis and behavior monitoring while preserving user convenience by not requiring extensive personal information during free-trial or freemium access
3Difficulty of detecting and measuring
If comprehensive user information is collected for security purposes, then attack source identification is improved, but data privacy concerns and system complexity increase
Solution Approach 1:
The patent extracts only the essential email identifier from comprehensive user information, discarding the need to collect extensive personal data. By focusing analysis on email domain validity, script-generation detection, and usage behavior patterns, the system achieves effective attack source identification with minimal data collection, thereby reducing system complexity and data privacy concerns
Data Source
AI summary
Methods and systems of classifying suspicious users are described. A processor may determine whether a domain name, of an email address of a user that requested to access a network, is valid. The processor may classify the user as a suspicious user if the domain name is invalid. If the domain name is valid, the processor may determine a likelihood that the email address is a script-generated email address. The processor may classify the user as a suspicious user if the email address is likely to be a script-generated email address. If the email address is unlikely to be a script-generated email address, the processor may identify abnormal usage behavior exhibited by the user based on a reference model. The processor may classify the user as a suspicious user if abnormal usage behavior is identified, and may reject a subsequent request from the user to access the network.


