IP Library › Granted Patent US 12,457,206
Granted Patent B2
US 12,457,206 · App. 18/341,069 · Granted Oct 28, 2025

Techniques for risk evaluation of access events

Inventor: Pushkar Singh (Sammamish, WA)
Assignee: Salesforce, Inc.
H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,457,206
App. No.
18/341,069
Granted
Oct 28, 2025
Kind
B2
Abstract

A system may receive, via a cloud-based platform supporting a plurality of tenants, one or more access events from a user of a host platform associated with a tenant, the one or more access events comprising one or more keystroke events at the host platform and one or more commands inputted by the user at the host platform, wherein the one or more access events are captured by a continuous authentication agent associated with the host platform. The system may identify fraudulent access events based at least in part on executing a machine learning model to perform a pattern matching between previously authenticated browsing behavior of the user and the one or more access events at the host platform. The system may generate a challenge question for reauthenticating the user of the host platform based at least in part on identifying the at least one fraudulent access event.

Claims (50)

1. A method for data processing, comprising:

receiving, via a cloud-based platform supporting a plurality of tenants, one or more access events from a user of a host platform associated with a tenant of the plurality of tenants, the one or more access events comprising one or more keystroke events at the host platform and one or more commands inputted by the user at the host platform, wherein the one or more access events are captured by a continuous authentication agent associated with the host platform;

training a machine learning model with a list of known fraudulent access events, a list of known authenticated browsing behaviors, and previously authenticated browsing behavior of the user;

identifying at least one fraudulent access event based at least in part on executing the machine learning model to perform a pattern matching between the previously authenticated browsing behavior of the user and the one or more access events at the host platform; and

generating a challenge question for reauthenticating the user of the host platform based at least in part on identifying the at least one fraudulent access event.

2. The method of claim 1 , further comprising:

receiving, from the host platform, an indication of an initial login authorization event prior to an occurrence of the one or more access events, wherein the initial login authorization event corresponds to a first authorization method; and

monitoring the one or more access events for fraudulent access events in response to receiving the indication of the initial login authorization event.

3. The method of claim 2 , further comprising:

initiating a reauthentication procedure based at least in part on identifying the at least one fraudulent access event, wherein the reauthentication procedure comprises generating the challenge question for reauthenticating the user.

4. The method of claim 2 , wherein the challenge question corresponds to a second authorization method different from the first authorization method.

5. The method of claim 2 , wherein the first authorization method comprises one or more of a password authentication, a fingerprint authentication, a face recognition authentication, or a combination thereof.

6. The method of claim 1 , further comprising:

identifying initiation of a new session at the host platform based at least in part on receiving the one or more access events from the user of the host platform associated with the tenant of the plurality of tenants; and

encoding session data corresponding to the new session at the host platform, wherein identifying the at least one fraudulent access event is based at least in part on executing the machine learning model on the encoded session data.

7. The method of claim 1 , further comprising:

receiving a response to the challenge question from the user of the host platform;

performing a reauthentication procedure of the user of the host platform based at least in part on receiving the response to the challenge question; and

updating the machine learning model based at least in part on performing the reauthentication procedure of the user.

8. The method of claim 7 , further comprising:

determining that the response to the challenge question fails to satisfy an authentication threshold; and

generating a second challenge question based at least in part on the response to the challenge question failing to satisfy the authentication threshold.

9. The method of claim 1 , wherein the one or more keystroke events comprise one or more secure socket shell keystroke events.

10. The method of claim 1 , wherein the at least one fraudulent access event comprises at least one of a suspicious command, a suspicious pattern of keystrokes, or a combination thereof.

11. An apparatus for data processing, comprising:

at least one processor;

at least one memory coupled with the at least one processor; and

instructions stored in the at least one memory and executable by the at least one processor to cause the apparatus to:

receive, via a cloud-based platform supporting a plurality of tenants, one or more access events from a user of a host platform associated with a tenant of the plurality of tenants, the one or more access events comprising one or more keystroke events at the host platform and one or more commands inputted by the user at the host platform, wherein the one or more access events are captured by a continuous authentication agent associated with the host platform;

train a machine learning model with a list of known fraudulent access events, a list of known authenticated browsing behaviors, and previously authenticated browsing behavior of the user;

identify at least one fraudulent access event based at least in part on executing the machine learning model to perform a pattern matching between the previously authenticated browsing behavior of the user and the one or more access events at the host platform; and

generate a challenge question for reauthenticating the user of the host platform based at least in part on identifying the at least one fraudulent access event.

12. The apparatus of claim 11 , wherein the instructions are further executable by the at least one processor to cause the apparatus to:

receive, from the host platform, an indication of an initial login authorization event prior to an occurrence of the one or more access events, wherein the initial login authorization event corresponds to a first authorization method; and

monitor the one or more access events for fraudulent access events in response to receiving the indication of the initial login authorization event.

13. The apparatus of claim 12 , wherein the instructions are further executable by the at least one processor to cause the apparatus to:

initiate a reauthentication procedure based at least in part on identifying the at least one fraudulent access event, wherein the reauthentication procedure comprises generating the challenge question for reauthenticating the user.

14. The apparatus of claim 12 , wherein the challenge question corresponds to a second authorization method different from the first authorization method.

15. The apparatus of claim 12 , wherein the first authorization method comprises one or more of a password authentication, a fingerprint authentication, a face recognition authentication, or a combination thereof.

16. The apparatus of claim 11 , wherein the instructions are further executable by the at least one processor to cause the apparatus to:

identify initiation of a new session at the host platform based at least in part on receiving the one or more access events from the user of the host platform associated with the tenant of the plurality of tenants; and

encode session data corresponding to the new session at the host platform, wherein identifying the at least one fraudulent access event is based at least in part on executing the machine learning model on the encoded session data.

17. A non-transitory computer-readable medium storing code for data processing, the code comprising instructions executable by at least one processor to:

receive, via a cloud-based platform supporting a plurality of tenants, one or more access events from a user of a host platform associated with a tenant of the plurality of tenants, the one or more access events comprising one or more keystroke events at the host platform and one or more commands inputted by the user at the host platform, wherein the one or more access events are captured by a continuous authentication agent associated with the host platform;

train a machine learning model with a list of known fraudulent access events, a list of known authenticated browsing behaviors, and previously authenticated browsing behavior of the user;

identify at least one fraudulent access event based at least in part on executing the machine learning model to perform a pattern matching between the previously authenticated browsing behavior of the user and the one or more access events at the host platform; and

generate a challenge question for reauthenticating the user of the host platform based at least in part on identifying the at least one fraudulent access event.

18. The non-transitory computer-readable medium of claim 17 , wherein the instructions are further executable by the at least one processor to:

receive, from the host platform, an indication of an initial login authorization event prior to an occurrence of the one or more access events, wherein the initial login authorization event corresponds to a first authorization method; and

monitor the one or more access events for fraudulent access events in response to receiving the indication of the initial login authorization event.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2023
From: SINGH, PUSHKAR
To: SALESFORCE, INC.
Reel/Frame 064086/0656 →
Continuity (1)
Related Publication 20240430247A1 · Dec 26, 2024
References Cited (6)
US 20160078120A1 · Pradeep · 2016 [cited by examiner]
US 20160105420A1 · Engan · 2016 [cited by examiner]
US 20160125522A1 · Tang · 2016 [cited by examiner]
US 20200293638A1 · Rose · 2020 [cited by examiner]
US 20240022593A1 · Costa · 2024 [cited by examiner]
US 20240356965A1 · Chu · 2024 [cited by examiner]