首页> 外国专利> System and method for protecting online resources against guided username guessing attacks

System and method for protecting online resources against guided username guessing attacks

机译:保护在线资源的系统和方法,反对导游用户名猜测攻击

摘要

The system receives a stream of authentication events, which are associated with authentication events. Next, the system attempts to detect a formation of authentication events, wherein a formation comprises a time window of authentication events that satisfy a formation criterion, which is based on one or more of: a username for the authentication attempt, an Internet Protocol (IP) address from which the authentication attempt originated, and a resource identifier for a computing resource that the authentication attempt was directed to. If a formation is detected, the system determines a number of valid usernames in the formation. If the number of valid usernames is one or less, the system computes a username similarity score for authentication events in the formation, which is a function of a string distance between usernames in the formation. If the username similarity score exceeds a threshold value, the system reports a potential username guessing attack.
机译:系统接收与认证事件相关联的认证事件流。接下来,系统尝试检测身份验证事件的形成,其中形成包括满足形成标准的认证事件的时间窗口,其基于以下一个或多个:用于认证尝试的用户名,一种因特网协议(IP )验证尝试源自的地址,以及用于认证尝试的计算资源的资源标识符。如果检测到形成,系统会在地图中确定许多有效用户名。如果有效用户名的数量是一个或更那么,则系统将计算形成中的身份验证事件的用户名相似度分数,这是形成中用户名之间的字符串距离的函数。如果用户名相似度分数超过阈值,则系统报告潜在的用户名猜测攻击。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号