US2016373471A1PendingUtilityA1

Human user verification of high-risk network access

Assignee: FORTINET INCPriority: Dec 19, 2013Filed: Sep 6, 2016Published: Dec 22, 2016
Est. expiryDec 19, 2033(~7.4 yrs left)· nominal 20-yr term from priority
Inventors:Qianyong Yu
G06F 2221/2103G06F 2221/2133G06F 21/42G06F 21/34G06F 21/32H04L 63/1466H04L 63/0861H04L 63/126G06F 21/31H04L 63/02H04L 63/083H04L 63/10H04L 63/08H04L 63/1416H04L 67/306G06F 21/36H04L 63/1408H04L 63/0853H04L 63/102
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods for performing a human user test when a high-risk network access is captured by an intermediary security device are provided. According to one embodiment, a high-risk network access initiated by a device is identified by an intermediary security device. A human user test message is sent by the intermediary security device to a human user of the device to verify that the high-risk network access was initiated by or is otherwise authorized by the human user. A response to the human user test message is received by the intermediary security device. It is determined by the intermediary security device whether the response is a correct response to the human user test message. When the response is correct, the high-risk network access is allowed by the intermediary security device.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 identifying, by an intermediary security device, a high-risk network access initiated by a device;   sending, by the intermediary security device, a human user test message to a human user of the device to verify that the high-risk network access was initiated by or is otherwise authorized by the human user;   receiving, by the intermediary security device, a response to the human user test message;   determining, by the intermediary security device, if the response is a correct response to the human user test message; and   allowing, by the intermediary security device, the high-risk network access if the response is correct.   
     
     
         2 . The method of  claim 1 , wherein said identifying a high-risk network access is based on one or more of:
 an outcome of an antivirus scan of a requested resource performed by the intermediary security device;   an outcome of an intrusion detection system/intrusion protection system (IDS/IPS) scan of a request and a response performed by the intermediary security device;   an outcome of a reputation-based evaluation of characteristics of an access performed by the intermediary security device;   an outcome of a cloud-based evaluation of the characteristics of the access performed by a remote computer as requested by the intermediary security device;   an outcome of a scan based on policies and rules configured on the intermediary security device; and   an outcome of a scan based on characteristics of one or more previous access requests and user verifications.   
     
     
         3 . The method of  claim 1 , wherein the human user test comprises presenting an Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) to the human user and verifying a solution allegedly provided by the human user. 
     
     
         4 . The method of  claim 1 , wherein the human user test comprises presenting a challenge question and verifying an answer allegedly provided by the human user. 
     
     
         5 . The method of  claim 4 , wherein the challenge question and the answer comprise a security question and an answer previously set by the human user. 
     
     
         6 . The method of  claim 1 , wherein said sending a human user test message comprises presenting the human user test message to the human user and sending the correct response to the human user through an alternative channel. 
     
     
         7 . The method of  claim 6 , wherein the alternative channel comprises an email address or a mobile phone number of the human user. 
     
     
         8 . The method of  claim 1 , wherein said receiving a response comprises receiving the response of the human user through an alternative channel. 
     
     
         9 . The method of  claim 1 , wherein allowing the high-risk network access comprises one or more of:
 redirecting the human user to the resource originally requested;   directly returning a copy of the requested resource temporarily stored on the intermediary security device;   presenting the human user with an alternative Uniform Resource Locator (URL) that points to a copy of the resource originally requested temporarily stored on the intermediary security device; and   sending a resource originally requested to the human user via an alternative secure channel.   
     
     
         10 . The method of  claim 1 , further comprising storing a mapping of requested resources and verification results to skip verification steps for subsequent requests to previously verified resources. 
     
     
         11 . A computer system comprising:
 non-transitory storage device having tangibly embodied therein instructions representing a security application; and   one or more hardware processors coupled to the non-transitory storage device and operable to execute the security application to perform a method comprising:
 identifying, by an intermediary security device, a high-risk network access initiated by a device; 
 sending, by the intermediary security device, a human user test message to a human user of the device to verify that the high-risk network access was initiated by or is otherwise authorized by the human user; 
 receiving, by the intermediary security device, a response to the human user test message; 
 determining, by the intermediary security device, if the response is a correct response to the human user test message; and 
 allowing, by the intermediary security device, the high-risk network access if the response is correct. 
   
     
     
         12 . The computer system of  claim 11 , wherein said identifying a high-risk network access is based on one or more of:
 an outcome of an antivirus scan of a requested resource performed by the intermediary security device;   an outcome of an intrusion detection system/intrusion protection system (IDS/IPS) scan of a request and a response performed by the intermediary security device;   an outcome of a reputation-based evaluation of characteristics of an access performed by the intermediary security device;   an outcome of a cloud-based evaluation of the characteristics of the access performed by a remote computer as requested by the intermediary security device;   an outcome of a scan based on policies and rules configured on the intermediary security device; and   an outcome of a scan based on characteristics of one or more previous access requests and user verifications.   
     
     
         13 . The computer system of  claim 11 , wherein the human user test comprises presenting an Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) to the human user and verifying a solution allegedly provided by the human user. 
     
     
         14 . The computer system of  claim 11 , wherein the human user test comprises presenting a challenge question and verifying an answer allegedly provided by the human user. 
     
     
         15 . The computer system of  claim 14 , wherein the challenge question and the answer comprise a security question and an answer previously set by the human user. 
     
     
         16 . The computer system of  claim 11 , wherein said sending a human user test message comprises presenting the human user test message to the human user and sending the correct response to the human user through an alternative channel. 
     
     
         17 . The computer system of  claim 16 , wherein the alternative channel comprises an email address or a mobile phone number of the human user. 
     
     
         18 . The computer system of  claim 11 , wherein said receiving a response comprises receiving the response of the human user through an alternative channel. 
     
     
         19 . The computer system of  claim 11 , wherein allowing the high-risk network access comprises one or more of:
 redirecting the human user to the resource originally requested;   directly returning a copy of the requested resource temporarily stored on the intermediary security device;   presenting the human user with an alternative Uniform Resource Locator (URL) that points to a copy of the resource originally requested temporarily stored on the intermediary security device; and   sending a resource originally requested to the human user via an alternative secure channel.   
     
     
         20 . The computer system of  claim 11 , wherein the method further comprises storing a mapping of requested resources and verification results to skip verification steps for subsequent requests to previously verified resources.

Join the waitlist — get patent alerts

Track US2016373471A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.