Invention Grant
- Patent Title: System and method for protecting online resources against guided username guessing attacks
-
Application No.: US16011049Application Date: 2018-06-18
-
Publication No.: US10956543B2Publication Date: 2021-03-23
- Inventor: Aleksey M. Urmanov , Alan Paul Wood , Anton A. Bougaev
- Applicant: Oracle International Corporation
- Applicant Address: US CA Redwood Shores
- Assignee: Oracle International Corporation
- Current Assignee: Oracle International Corporation
- Current Assignee Address: US CA Redwood Shores
- Agency: Park, Vaughan, Fleming & Dowler LLP
- Main IPC: G06F21/31
- IPC: G06F21/31 ; H04L29/06 ; G06F21/45

Abstract:
The system receives a stream of authentication events, which are associated with authentication events. Next, the system attempts to detect a formation of authentication events, wherein a formation comprises a time window of authentication events that satisfy a formation criterion, which is based on one or more of: a username for the authentication attempt, an Internet Protocol (IP) address from which the authentication attempt originated, and a resource identifier for a computing resource that the authentication attempt was directed to. If a formation is detected, the system determines a number of valid usernames in the formation. If the number of valid usernames is one or less, the system computes a username similarity score for authentication events in the formation, which is a function of a string distance between usernames in the formation. If the username similarity score exceeds a threshold value, the system reports a potential username guessing attack.
Public/Granted literature
- US20190384897A1 SYSTEM AND METHOD FOR PROTECTING ONLINE RESOURCES AGAINST GUIDED USERNAME GUESSING ATTACKS Public/Granted day:2019-12-19
Information query