首页> 外国专利> Detecting and responding to attempts to gain unauthorized access to user accounts in an online system

Detecting and responding to attempts to gain unauthorized access to user accounts in an online system

机译:检测和响应尝试在在线系统中获得未经授权访问用户帐户的未经授权访问

摘要

In response to detected attempts to gain unauthorized access to user accounts of an online system, a security module of an online system applies an attack response policy to take actions in response to the attempts. Possible responses of the policy include reordering credential types requested by the online system during multi-factor authentication-enabled login, switching to a mode in which login requests are accepted but login is not permitted for the requesting user, and logging information about the login requests. Logged information may be applied to enhance the ability to prevent future unauthorized accesses, such as adding credential values to a list of common credential values and prohibiting users from associating those values with their accounts, or training a model based on the logged information to predict a probability that a given login request is unauthorized.
机译:为了响应于检测到的尝试未经授权访问在线系统的用户帐户,在线系统的安全模块适用攻击响应策略以响应尝试来采取操作。该策略的可能响应包括在多因素身份验证的登录期间重新排序在线系统请求的凭证类型,切换到接受登录请求但是请求用户的登录或登录登录的模式,以及记录有关登录请求的信息。可以应用记录的信息来增强防止未来未经授权的访问的能力,例如将凭证值添加到常见凭据值的列表中,并禁止用户将这些值与其帐户关联,或者基于记录信息培训模型以预测a未经授权给定登录请求的概率。

著录项

  • 公开/公告号US11012468B2

    专利类型

  • 公开/公告日2021-05-18

    原文格式PDF

  • 申请/专利权人 OKTA INC.;

    申请/专利号US201816175748

  • 申请日2018-10-30

  • 分类号H04L29/06;H04L9/32;H04W12/06;H04W12/122;H04L9;

  • 国家 US

  • 入库时间 2022-08-24 18:42:55

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号