System and method for risk assessment of a third party application for controlling competitive migration
In general, the invention relates to a method involving allowing access to a financial application by a third-party extension based on a single license to use the financial application, where the third-party extension was developed by a third-party developer using one or more tools in a software development kit (SDK) for the financial application and where the financial application stores first transaction data obtained for a first user of the financial application, monitoring operations performed on the financial application by the third-party extension to detect operations that migrate transaction data to a competitive application, using distributed computing software adjust a risk index that is associated with the third-party extension, determining that the risk index exceeds a pre-defined threshold, and controlling future access to the financial application by the third-party extension.
1. A method, comprising operations of:
servicing, by an application, access by a third-party extension, executing on each of a plurality of devices, to the application based on a single license to use the application, wherein the third-party extension was developed by a third-party developer using one or more tools in a software development kit (SDK) for the application and wherein the application stores first transaction data obtained for a first user of the application;
monitoring operations that are performed on the application by the third-party extension to detect operations that migrate transaction data from the application to a competitive application with the third-party extension and generate a plurality of action scores for the third-party extension, wherein the monitored operations include a relatively large number of unique commands written in a structured query language (SQL);
applying a classifier to the plurality of action scores to generate a risk index with a processor that applies the classifier to the plurality of action scores,
wherein training the classifier comprises using a plurality of monitored operations, the plurality of monitored operations performed on the application, the plurality of monitored operations comprising one or more of continuous reads, bulk data extractions, and a number of unique commands written in the structured query language,
wherein the risk index measures a likelihood that the third-party application is being used to migrate transaction data to the competitive application, and
wherein software that maintains the risk index is trained on past monitored operations using unsupervised machine-learning;
using distributed computing software to adjust the risk index that is associated with the third-party extension;
determining that the risk index exceeds a pre-defined threshold; and
denying access, from the third-party extension on each of the plurality of devices using the third-party extension, to the application after determining that the risk index exceeds the pre-defined threshold.
2. The method of claim 1 , wherein the application stores second transaction data obtained for a second user of the application.
3. The method of claim 2 , wherein the monitored operations include a first continuous read of the first transaction data and a second continuous read of the second transaction data.
4. The method of claim 2 , wherein the monitored operations include a first bulk data extraction of the first transaction data and a second bulk data extraction of the second transaction data.
5. The method of claim 1 , wherein denying access includes revoking the single license to use the application.
6. A non-transitory computer-readable storage medium configured to store a program, wherein the program, when executed, performs operations to:
service, by an application, access by a third-party extension, executing on each of a plurality of devices, to the application based on a single license to use the application, wherein the third-party extension was developed by a third-party developer using one or more tools in a software development kit (SDK) for the application and wherein the application stores first transaction data obtained for a first user of the application;
monitor operations that are performed on the application by the third-party extension to detect operations that migrate transaction data from the application to a competitive application with the third-party extension and generate a plurality of action scores for the third-party extension, wherein the monitored operations include a relatively large number of unique commands written in structured query language (SQL);
apply a classifier to the plurality of action scores to generate a risk index with a processor that applies the classifier to the plurality of action scores,
wherein training the classifier comprises using a plurality of monitored operations, the plurality of monitored operations performed on the application, the plurality of monitored operations comprising one or more of continuous reads, bulk data extractions, and a number of unique commands written in the structured query language,
wherein the risk index measures a likelihood that the third-party application is being used to migrate transaction data to the competitive application, and
wherein software that maintains the risk index is trained on past monitored operations using unsupervised machine-learning;
use distributed computing software to adjust the risk index that is associated with the third-party extension, wherein the risk index is based at least in part on the monitored operations;
determine that the risk index exceeds a pre-defined threshold; and
deny access, from the third-party extension on each of the plurality of devices using the third-party extension, to the application after determining that the risk index exceeds the pre-defined threshold.
7. The non-transitory computer-readable storage medium of claim 6 , wherein the application stores second transaction data obtained for a second user of the application.
8. The non-transitory computer-readable storage medium of claim 7 , wherein the monitored operations include a first continuous read of the first transaction data and a second continuous read of the second transaction data.
9. The non-transitory computer-readable storage medium of claim 7 , wherein the monitored operations include a first bulk data extraction of the first transaction data and a second bulk data extraction of the second transaction data.
10. The non-transitory computer-readable storage medium of claim 6 , wherein denying access includes revoking the single license to use the application.
11. The non-transitory computer-readable storage medium of claim 6 , wherein the unsupervised machine-learning is based at least in part on clustering techniques.
12. A system, comprising:
a hardware processor and memory;
software instructions stored in the memory and configured to execute on the hardware processor, which, when executed cause the hardware processor to:
service, by an application, access by a third-party extension, executing on each of a plurality of devices, to the application based on a single license to use the application, wherein the third-party extension was developed by a third-party developer using one or more tools in a software development kit (SDK) for the application and wherein the application stores first transaction data obtained for a first user of the application;
monitor operations that are performed on the application by the third-party extension to detect operations that migrate transaction data from the application to a competitive application with the third-party extension and generate a plurality of action scores for the third-party extension, wherein the monitored operations include a relatively large number of unique commands written in structured query language (SQL);
apply a classifier to the plurality of action scores to generate a risk index with a processor that applies the classifier to the plurality of action scores,
wherein training the classifier comprises using a plurality of monitored operations, the plurality of monitored operations performed on the application, the plurality of monitored operations comprising one or more of continuous reads, bulk data extractions, and a number of unique commands written in the structured query language,
wherein the risk index measures a likelihood that the third-party application is being used to migrate transaction data to the competitive application, and
wherein software that maintains the risk index is trained on past monitored operations using unsupervised machine-learning;
use distributed computing software to adjust the risk index that is associated with the third-party extension, wherein the risk index is based at least in part on the monitored operations;
determine that the risk index exceeds a pre-defined threshold; and
deny access, from the third-party extension on each of the plurality of devices using the third-party extension, to the application after determining that the risk index exceeds the pre-defined threshold.