Unauthorized Access Detection via Leaked Authentication Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques fail to accurately detect fraudulent falsification of Web sites and unauthorized access using leaked authentication information, as such access is indistinguishable from normal login attempts, making it difficult to differentiate between legitimate and malicious changes to Web site content.

Innovation Solution

An unauthorized access detecting system that generates authentication information for leakage, detects unauthorized access, monitors content changes, and identifies falsification by extracting character strings added during unauthorized access, allowing for accurate detection of fraudulent falsification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional content monitoring methods are used to detect falsification, then content changes can be identified, but unauthorized access using leaked authentication information cannot be distinguished from normal login attempts

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by generating authentication information that is intentionally leaked to attackers before actual unauthorized access occurs. This proactive approach allows the system to detect and analyze unauthorized access patterns in advance, improving detection accuracy without requiring complex real-time analysis systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary component (unauthorized access detecting system) that sits between the authentication system and the content monitoring system. This intermediary detects unauthorized access attempts by analyzing authentication information usage patterns, enabling accurate distinction between legitimate and malicious access without complicating the core authentication or content management systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If file history management tools are used to monitor content changes, then falsification can be detected, but the source and nature of unauthorized access cannot be identified

Engineering Contradiction:
Improvedetection reliabilityVSAvoidinformation loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system implements feedback mechanisms where detected unauthorized access information is fed back into the monitoring process. When unauthorized access is detected through authentication analysis, the system responds by intensifying content monitoring and extracting character strings from changed files, creating a closed-loop system that improves detection reliability while preserving critical forensic information.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system segments the detection process into distinct phases: authentication phase (detecting unauthorized login), monitoring phase (tracking content changes), and analysis phase (extracting character strings). This segmentation allows each phase to focus on specific tasks, improving overall reliability while maintaining detailed information about the unauthorized access chain.

Inventive Principle:
Principle #1Segmentation

3Difficulty of detecting and measuring

If authentication information is leaked to detect unauthorized access, then detection capability is improved, but the risk of actual malicious use increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidmalicious impact
Core Design Contradiction:
Difficulty of detecting and measuringVSObject-affected harmful factors

Solution Approach 1:

The system converts the harmful act of authentication information leakage into a beneficial detection opportunity. By intentionally leaking authentication information and monitoring its usage, the system transforms a security vulnerability into a proactive detection mechanism, improving detection capability while actually reducing overall security risk through early identification of malicious actors.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS10033761B2System and method for monitoring falsification of content after detection of unauthorized access
Publication Date: 2018.07.24 NIPPON TELEGRAPH & TELEPHONE CORP
  • US10033761B2 patent drawing
  • US10033761B2 patent drawing
  • US10033761B2 patent drawing

AI summary

In an unauthorized access detecting system, authentication information to be leaked outside is generated, and unauthorized access to a content using the generated authentication information is detected. In the unauthorized access detecting system, if the unauthorized access has been detected, content falsification is monitored. If, as a result of the monitoring, content falsification has been detected, the unauthorized access detecting system extracts a character string, which has been newly added to the content.