Human user verification of high-risk network access
Abstract
Systems and methods for performing a human user test when a high-risk network access is captured by an intermediary security device are provided. According to one embodiment, a high-risk network access initiated by a device is identified by an intermediary security device. A human user test message is sent by the intermediary security device to a human user of the device to verify that the high-risk network access was initiated by or is otherwise authorized by the human user. A response to the human user test message is received by the intermediary security device. It is determined by the intermediary security device whether the response is a correct response to the human user test message. When the response is correct, the high-risk network access is allowed by the intermediary security device.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
identifying, by an intermediary security device, a high-risk network access initiated by a device; sending, by the intermediary security device, a human user test message to a human user of the device to verify that the high-risk network access was initiated by or is otherwise authorized by the human user; receiving, by the intermediary security device, a response to the human user test message; determining, by the intermediary security device, if the response is a correct response to the human user test message; and allowing, by the intermediary security device, the high-risk network access if the response is correct.
2 . The method of claim 1 , wherein said identifying a high-risk network access is based on one or more of:
an outcome of an antivirus scan of a requested resource performed by the intermediary security device; an outcome of an intrusion detection system/intrusion protection system (IDS/IPS) scan of a request and a response performed by the intermediary security device; an outcome of a reputation-based evaluation of characteristics of an access performed by the intermediary security device; an outcome of a cloud-based evaluation of the characteristics of the access performed by a remote computer as requested by the intermediary security device; an outcome of a scan based on policies and rules configured on the intermediary security device; and an outcome of a scan based on characteristics of one or more previous access requests and user verifications.
3 . The method of claim 1 , wherein the human user test comprises presenting an Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) to the human user and verifying a solution allegedly provided by the human user.
4 . The method of claim 1 , wherein the human user test comprises presenting a challenge question and verifying an answer allegedly provided by the human user.
5 . The method of claim 4 , wherein the challenge question and the answer comprise a security question and an answer previously set by the human user.
6 . The method of claim 1 , wherein said sending a human user test message comprises presenting the human user test message to the human user and sending the correct response to the human user through an alternative channel.
7 . The method of claim 6 , wherein the alternative channel comprises an email address or a mobile phone number of the human user.
8 . The method of claim 1 , wherein said receiving a response comprises receiving the response of the human user through an alternative channel.
9 . The method of claim 1 , wherein allowing the high-risk network access comprises one or more of:
redirecting the human user to the resource originally requested; directly returning a copy of the requested resource temporarily stored on the intermediary security device; presenting the human user with an alternative Uniform Resource Locator (URL) that points to a copy of the resource originally requested temporarily stored on the intermediary security device; and sending a resource originally requested to the human user via an alternative secure channel.
10 . The method of claim 1 , further comprising storing a mapping of requested resources and verification results to skip verification steps for subsequent requests to previously verified resources.
11 . A computer system comprising:
non-transitory storage device having tangibly embodied therein instructions representing a security application; and one or more hardware processors coupled to the non-transitory storage device and operable to execute the security application to perform a method comprising:
identifying, by an intermediary security device, a high-risk network access initiated by a device;
sending, by the intermediary security device, a human user test message to a human user of the device to verify that the high-risk network access was initiated by or is otherwise authorized by the human user;
receiving, by the intermediary security device, a response to the human user test message;
determining, by the intermediary security device, if the response is a correct response to the human user test message; and
allowing, by the intermediary security device, the high-risk network access if the response is correct.
12 . The computer system of claim 11 , wherein said identifying a high-risk network access is based on one or more of:
an outcome of an antivirus scan of a requested resource performed by the intermediary security device; an outcome of an intrusion detection system/intrusion protection system (IDS/IPS) scan of a request and a response performed by the intermediary security device; an outcome of a reputation-based evaluation of characteristics of an access performed by the intermediary security device; an outcome of a cloud-based evaluation of the characteristics of the access performed by a remote computer as requested by the intermediary security device; an outcome of a scan based on policies and rules configured on the intermediary security device; and an outcome of a scan based on characteristics of one or more previous access requests and user verifications.
13 . The computer system of claim 11 , wherein the human user test comprises presenting an Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) to the human user and verifying a solution allegedly provided by the human user.
14 . The computer system of claim 11 , wherein the human user test comprises presenting a challenge question and verifying an answer allegedly provided by the human user.
15 . The computer system of claim 14 , wherein the challenge question and the answer comprise a security question and an answer previously set by the human user.
16 . The computer system of claim 11 , wherein said sending a human user test message comprises presenting the human user test message to the human user and sending the correct response to the human user through an alternative channel.
17 . The computer system of claim 16 , wherein the alternative channel comprises an email address or a mobile phone number of the human user.
18 . The computer system of claim 11 , wherein said receiving a response comprises receiving the response of the human user through an alternative channel.
19 . The computer system of claim 11 , wherein allowing the high-risk network access comprises one or more of:
redirecting the human user to the resource originally requested; directly returning a copy of the requested resource temporarily stored on the intermediary security device; presenting the human user with an alternative Uniform Resource Locator (URL) that points to a copy of the resource originally requested temporarily stored on the intermediary security device; and sending a resource originally requested to the human user via an alternative secure channel.
20 . The computer system of claim 11 , wherein the method further comprises storing a mapping of requested resources and verification results to skip verification steps for subsequent requests to previously verified resources.Join the waitlist — get patent alerts
Track US2016373471A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.