Suspicious User Detection via Email Analysis and Behavior Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing platforms, it is challenging to trace and prevent attacks during free-trial or freemium usage periods when users do not provide specific information, making it difficult for security systems to identify the source of attacks.

Innovation Solution

A method and system that classify suspicious users by analyzing email addresses for validity and script-generation likelihood, and comparing usage behavior against a reference model to detect abnormal activity, ultimately rejecting subsequent access requests from suspicious users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are allowed to access the network without providing specific user information during free-trial or freemium periods, then user convenience and network accessibility are improved, but security traceability and attack source identification deteriorate

Engineering Contradiction:
Improveuser convenienceVSAvoidattack source identification
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent uses email addresses as an intermediary identifier to bridge the gap between anonymous user access and security traceability. By analyzing email domain validity, script-generation likelihood, and usage behavior patterns, the system can identify suspicious users without requiring traditional personal information, thus maintaining user convenience while improving security traceability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring usage behavior and comparing it against established patterns. When abnormal behavior is detected, the system can trace back to the email identifier and take appropriate security measures, creating a closed-loop feedback system that maintains security without compromising user convenience during free-trial periods

Inventive Principle:
Principle #23Feedback

2Reliability

If traditional security measures requiring specific user information are implemented, then security traceability is improved, but user convenience and network accessibility deteriorate

Engineering Contradiction:
Improvesecurity traceabilityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the identification parameter from traditional personal information (name, address, phone) to email-based identifiers. This parameter change allows the system to maintain security traceability through email domain analysis and behavior monitoring while preserving user convenience by not requiring extensive personal information during free-trial or freemium access

Inventive Principle:
Principle #35Parameter changes

3Difficulty of detecting and measuring

If comprehensive user information is collected for security purposes, then attack source identification is improved, but data privacy concerns and system complexity increase

Engineering Contradiction:
Improveattack source identificationVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent extracts only the essential email identifier from comprehensive user information, discarding the need to collect extensive personal data. By focusing analysis on email domain validity, script-generation detection, and usage behavior patterns, the system achieves effective attack source identification with minimal data collection, thereby reducing system complexity and data privacy concerns

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10778689B2Suspicious activity detection in computer networks
Publication Date: 2020.09.15 ARKOSE LABS HOLDINGS INC
  • US10778689B2 patent drawing
  • US10778689B2 patent drawing
  • US10778689B2 patent drawing

AI summary

Methods and systems of classifying suspicious users are described. A processor may determine whether a domain name, of an email address of a user that requested to access a network, is valid. The processor may classify the user as a suspicious user if the domain name is invalid. If the domain name is valid, the processor may determine a likelihood that the email address is a script-generated email address. The processor may classify the user as a suspicious user if the email address is likely to be a script-generated email address. If the email address is unlikely to be a script-generated email address, the processor may identify abnormal usage behavior exhibited by the user based on a reference model. The processor may classify the user as a suspicious user if abnormal usage behavior is identified, and may reject a subsequent request from the user to access the network.