US2010229230A1PendingUtilityA1

System and method for securing computer system against unauthorized access

Assignee: EDEKI OMON AYODELEPriority: Jul 23, 2003Filed: Dec 31, 2009Published: Sep 9, 2010
Est. expiryJul 23, 2023(expired)· nominal 20-yr term from priority
G06F 21/31G06F 21/552G06F 2221/2105G06F 2221/2103
42
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present invention described secures a computer account against unauthorized access caused as a result of identity-theft, and insider-espionage using artificial intelligence and behavioral modeling methods. The present invention has the ability to detect intruders or impersonators by observing “suspicious” activity under a computer account. When it sees such suspicious behavior, it uses artificial intelligence to authenticate the suspect by interrogation. The present invention asks the suspect questions that only the legitimate computer account owner can verify correctly. If the suspect fails the interrogation, that proves that he/she is an impersonator and therefore further access to the computer account is denied immediately. On the other hand if the suspect passes, access to the computer account is restored. The present invention uses a Programmable Artificial Intelligence Engine (PAIE) to interact with computer users in human natural language. The PAIE can also be programmed to suit other applications where natural language interaction with humans is helpful.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
   
   
       2 . (canceled) 
   
   
       3 . A method for securing access to a computer account, comprising:
 based on user interaction and user activity monitoring of an authorized user over a predetermined time period, generating a use profile associated with the computer account;   based on the use profile, detecting user behavior indicative of intrusion in the computer account; and   in response to detecting the user behavior, interrogating a current user of the computer account using human natural language generated from the use profile.   
   
   
       4 . The method of  claim 3 , further comprising:
 if said interrogating indicates that the current user is not the authorized user, denying the current user access to the computer account.   
   
   
       5 . The method of  claim 4 , wherein said interrogating further comprises:
 asking the current user a natural language question;   comparing an answer provided by the current user in response to the question to the use profile; and   measuring a response time of the current user in providing the answer to the question.   
   
   
       6 . The method of  claim 5 , wherein said comparing further comprises:
 determining a deviation amount between the answer and the use profile, wherein the deviation amount is an indication of an identity of the current user.   
   
   
       7 . The method of  claim 5 , wherein the value of the response time is an indication of an identity of the current user. 
   
   
       8 . The method of  claim 3 , further comprising:
 logging on the current user to the computer account using a means for log on including at least one of: an authorization code, a key, a password, and an electronic means for identification; and   enabling the current user to access the computer account, wherein the means for log on is used to identify the use profile.   
   
   
       9 . The method of  claim 3 , wherein said user interaction includes engaging in natural language dialog with the authorized user to obtain information for the use profile, and wherein said user activity monitoring includes monitoring interactions of the authorized user with a computer system hosting the computer account. 
   
   
       10 . The method of  claim 4 , further comprising:
 if said interrogating indicates that the current user is the authorized user, updating the use profile to indicate that the detected user behavior is associated with the authorized user and is not indicative of intrusion.   
   
   
       11 . The method of  claim 3 , wherein said interrogating is performed using a programmable artificial intelligence engine. 
   
   
       12 . A computer-readable memory medium for securing access to a computer system, including programmable instructions executable to:
 based on a use profile describing usage of the computer system by an authorized user, detect user behavior indicative of intrusion in a computer account on the computer system; and   in response to detecting the user behavior, interrogate a current user of the computer account to determine whether the current user is the authorized user, wherein said instructions to interrogate are executable to use human natural language generated from the use profile.   
   
   
       13 . The memory medium of  claim 12 , further comprising instructions executable to:
 generate the use profile for the authorized user of the computer account, including instructions executable to:   interact with the authorized user by engaging in natural language dialog to obtain dialog information indicative of the authorized user;   monitor user activity over a predetermined time period by recording interactions of the authorized user with the computer system to obtain activity information indicative of the authorized user; and   store the dialog information and the activity information in the user profile.   
   
   
       14 . The memory medium of  claim 13 , wherein the computer system is a client system in a computer network, and further comprising instructions executable to:
 store the use profile on a network server.   
   
   
       15 . The memory medium of  claim 13 , wherein said instructions executable to generate the use profile are further executable to:
 delete information in the use profile generated prior to a predetermined point in time.   
   
   
       16 . The memory medium of  claim 13 , wherein said instructions executable to interact with the authorized user are further executable to:
 receive input volunteered by the authorized user; and   store information indicative of the input in the use profile.   
   
   
       17 . The memory medium of  claim 13 , further comprising instructions executable to:
 based on the use profile, detect user behavior indicative of intrusion in the computer account;   in response to detecting the user behavior, interrogate a current user of the computer account using human natural language generated using the use profile; and   in response to said instructions executable to interrogate determining that the current user is not the authorized user, deny the current user access to the computer account.   
   
   
       18 . The memory medium of  claim 14 , further comprising instructions executable to:
 in response to detecting user behavior indicative of intrusion in the computer account, notify an administrator for the computer account.   
   
   
       19 . The memory medium of  claim 14 , wherein said instructions executable to interrogate further comprise instructions executable to:
 construe an answer provided by the current user in response to asking a question, wherein the answer is construed based on the context of the question; and   measure a response time of the current user in providing the answer to the question.   
   
   
       20 . The memory medium of  claim 19 , further comprising instructions executable to:
 generate the question based on the use profile; and   ask the current user the question.   
   
   
       21 . The memory medium of  claim 19 , further comprising instructions executable to:
 depending on the value of the answer and the response time, determine an identity of the current user respective to the authorized user.

Join the waitlist — get patent alerts

Track US2010229230A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.