IP Library Patent Application 18962240
Patent Application
App. No. 18/962,240

DETECTING ACCOUNT TAKEOVER

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/962,240
Abstract

Indications of login events of a computer account, including a plurality of attributes of the login events, are received. Correlations between the plurality of attributes of the login events are tracked. A new indication of a new login event is received. Based at least in part on the tracked correlations and attributes of the new login event, a machine learning model is used to determine a result associated with whether the new login event is anomalous. A computer security action based on the result of the machine learning model is performed.

Claims (37)

1 . A method, comprising:

receiving indications of login events of a computer account, including a plurality of attributes of the login events;

tracking correlations between the plurality of attributes of the login events;

receiving a new indication of a new login event;

based at least in part on the tracked correlations and attributes of the new login event, using a machine learning model to determine a result associated with whether the new login event is anomalous; and

performing a computer security action based on the result of the machine learning model.

2 . The method of claim 1 , wherein the plurality of attributes of the login events includes at least a location attribute of the computer account or a networking attribute of the computer account.

3 . The method of claim 2 , wherein the location attribute of the computer account includes at is least a city attribute, a state attribute, a country attribute, a region attribute, or a geographical coordinates attribute.

4 . The method of claim 2 , wherein the networking attribute of the computer account includes at least an Internet Protocol address attribute, an Internet Service Provider attribute, or a subnetwork attribute.

5 . The method of claim 1 , wherein the plurality of attributes includes one or more attributes associated with a multi-factor authentication device or an access token.

6 . The method of claim 1 , wherein at least one of the plurality of attributes is tracked using an age metric or a frequency metric.

7 . The method of claim 1 , wherein the tracked correlations are stored using a distributed hash map data structure.

8 . The method of claim 1 , wherein the tracked correlations are stored according to one or more intervals of time.

9 . The method of claim 8 , wherein at least one of the one or more intervals of time corresponds to a time of 7 days, 1 month, 3 months, 6 months, or 12 months.

10 . The method of claim 1 , wherein the computer security action corresponds to blocking the new login event, suspending the computer account, requiring a password change, requiring a new multi-factor authentication device, revoking an existing multi-factor authentication device, revoking an access token, restricting access to network resources, or invalidating one or more existing user sessions.

11 . A system, comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory is configured to provide the one or more processors with instructions which when executed cause the one or more processors to:

receive indications of login events of a computer account, including a plurality of attributes of the login events;

track correlations between the plurality of attributes of the login events;

receive a new indication of a new login event;

based at least in part on the tracked correlations and attributes of the new login event, use a machine learning model to determine a result associated with whether the new login event is anomalous; and

perform a computer security action based on the result of the machine learning model.

12 . The system of claim 11 , wherein the plurality of attributes of the login events includes at least a location attribute of the computer account or a networking attribute of the computer account.

13 . The system of claim 12 , wherein the location attribute of the computer account includes at least a city attribute, a state attribute, a country attribute, a region attribute, or a geographical coordinates attribute.

14 . The system of claim 12 , wherein the networking attribute of the computer account includes at least an Internet Protocol address attribute, an Internet Service Provider attribute, or a subnetwork attribute.

15 . The system of claim 11 , wherein the plurality of attributes includes one or more attributes associated with a multi-factor authentication device or an access token.

16 . The system of claim 11 , wherein at least one of the plurality of attributes is tracked using an age metric or a frequency metric.

17 . The system of claim 11 , wherein the tracked correlations are stored using a distributed hash map data structure.

18 . The system of claim 11 , wherein the tracked correlations are stored according to one or more intervals of time.

19 . The system of claim 1 , wherein the computer security action corresponds to blocking the new login event, suspending the computer account, requiring a password change, requiring a new multi-factor authentication device, revoking an existing multi-factor authentication device, revoking an access token, restricting access to network resources, or invalidating one or more existing user sessions.

20 . A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving indications of login events of a computer account, including a plurality of attributes of the login events;

tracking correlations between the plurality of attributes of the login events;

receiving a new indication of a new login event;

based at least in part on the tracked correlations and attributes of the new login event, using a machine learning model to determine a result associated with whether the new login event is anomalous; and

performing a computer security action based on the result of the machine learning model.

Assignments (3)
CHANGE OF NAME Recorded Apr 22, 2025
From: ABNORMAL SECURITY CORPORATION
To: ABNORMAL AI, INC.
Reel/Frame 070947/0132 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2025
From: JEYAKUMAR, SANJAY; BAGRI, ABHIJIT; KHOT, TEJAS; GULTEPE, UMUT; HAGAR, DAVID; LUDERT, ERIN ELISABETH EDKINS; LAW, ELIZABETH; YEH, CHENG-LIN; PHILIP, MARK STEFFAN; BALACHUNDHAR, NIRMAL
To: ABNORMAL SECURITY CORPORATION
Reel/Frame 070725/0791 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2025
From: KHOT, TEJAS; GULTEPE, UMUT; HAGAR, DAVID; LUDERT, ERIN ELISABETH EDKINS; LAW, ELIZABETH; YEH, CHENG-LIN; PHILIP, MARK STEFFAN; BALACHUNDHAR, NIRMAL; JEYAKUMAR, SANJAY
To: ABNORMAL SECURITY CORPORATION
Reel/Frame 070136/0278 →