首页> 外国专利> DETECTING AND RESPONDING TO ATTEMPTS TO GAIN UNAUTHORIZED ACCESS TO USER ACCOUNTS IN AN ONLINE SYSTEM

DETECTING AND RESPONDING TO ATTEMPTS TO GAIN UNAUTHORIZED ACCESS TO USER ACCOUNTS IN AN ONLINE SYSTEM

机译:检测并响应尝试获得在线系统中未经授权的用户帐户访问权限的尝试

摘要

In response to detected attempts to gain unauthorized access to user accounts of an online system, a security module of an online system applies an attack response policy to take actions in response to the attempts. Possible responses of the policy include reordering credential types requested by the online system during multi-factor authentication-enabled login, switching to a mode in which login requests are accepted but login is not permitted for the requesting user, and logging information about the login requests. Logged information may be applied to enhance the ability to prevent future unauthorized accesses, such as adding credential values to a list of common credential values and prohibiting users from associating those values with their accounts, or training a model based on the logged information to predict a probability that a given login request is unauthorized.
机译:响应于检测到试图获得对在线系统的用户帐户的未授权访问的尝试,在线系统的安全模块应用攻击响应策略以响应于该尝试而采取措施。该策略的可能响应包括:在启用多因素身份验证的登录期间对在线系统请求的凭据类型进行重新排序;切换到接受登录请求但不允许请求用户登录的模式;以及记录有关登录请求的信息。记录的信息可用于增强防止将来未经授权的访问的能力,例如将凭证值添加到公共凭证值列表中,并禁止用户将这些值与他们的帐户相关联,或基于记录的信息训练模型以预测给定登录请求未经授权的可能性。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号