US2020137076A1PendingUtilityA1

Stolen credential use prevention on a web service

Assignee: CEQUENCE SECURITY INCPriority: Mar 26, 2015Filed: Dec 30, 2019Published: Apr 30, 2020
Est. expiryMar 26, 2035(~8.7 yrs left)· nominal 20-yr term from priority
H04L 63/123H04L 63/102H04L 63/1416H04L 67/02H04L 63/101H04L 63/1466H04L 63/083
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques to facilitate securing web services from unauthorized access are disclosed herein. In at least one implementation, user interactions with a web service are monitored, and sets of the user interactions are generated per originator based on origination information associated with the user interactions. The sets of the user interactions are processed to identify credentials used to access the web service per originator. The credentials used to access the web service per originator are compared with compromised credentials stored in a database to identify one or more user accounts of the web service associated with an originator that used the compromised credentials found in the database. Security measures are applied for at least the one or more user accounts of the web service associated with the originator that used the compromised credentials found in the database.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method to facilitate securing web services from unauthorized access, the method comprising:
 monitoring user interactions with a web service;   generating sets of the user interactions per originator based on origination information associated with the user interactions;   processing the sets of the user interactions to identify credentials used to access the web service per originator;   comparing the credentials used to access the web service per originator with compromised credentials stored in a database to identify one or more user accounts of the web service associated with an originator that used the compromised credentials found in the database; and   applying security measures for at least the one or more user accounts of the web service associated with the originator that used the compromised credentials found in the database.   
     
     
         2 . The method of  claim 1  wherein the origination information associated with the user interactions uniquely identifies each originator. 
     
     
         3 . The method of  claim 1  wherein applying the security measures for at least the one or more user accounts of the web service associated with the originator comprises increasing a level of authentication required for the one or more user accounts to access the web service. 
     
     
         4 . The method of  claim 1  wherein applying the security measures for at least the one or more user accounts of the web service associated with the originator comprises blocking access to the web service for all access attempts associated with the originator. 
     
     
         5 . The method of  claim 1  wherein applying the security measures for at least the one or more user accounts of the web service associated with the originator comprises sending automatic password reset notifications to owners of the one or more user accounts. 
     
     
         6 . The method of  claim 1  further comprising determining other user accounts of the web service having passwords found in a same credential data source as the compromised credentials used by the one or more user accounts associated with the originator that used the compromised credentials, and responsively sending automatic password reset notifications to owners of the other user accounts. 
     
     
         7 . The method of  claim 1  further comprising receiving a credential query transmitted from an authorized user of the web service, responsively comparing legitimate credentials of the authorized user received in the credential query with the compromised credentials in the database, and transferring a notification for delivery to the authorized user that indicates whether or not the legitimate credentials of the authorized user appear in the database of compromised credentials. 
     
     
         8 . An apparatus comprising:
 one or more computer-readable storage media;   a processing system operatively coupled with the one or more computer-readable storage media; and   program instructions stored on the one or more computer-readable storage media that, when executed by the processing system, direct the processing system to at least:
 monitor user interactions with a web service; 
 generate sets of the user interactions per originator based on origination information associated with the user interactions; 
 process the sets of the user interactions to identify credentials used to access the web service per originator; 
 compare the credentials used to access the web service per originator with compromised credentials stored in a database to identify one or more user accounts of the web service associated with an originator that used the compromised credentials found in the database; and 
 apply security measures for at least the one or more user accounts of the web service associated with the originator that used the compromised credentials found in the database. 
   
     
     
         9 . The apparatus of  claim 8  wherein the origination information associated with the user interactions uniquely identifies each originator. 
     
     
         10 . The apparatus of  claim 8  wherein the program instructions direct the processing system to apply the security measures for at least the one or more user accounts of the web service associated with the originator by directing the processing system to increase a level of authentication required for the one or more user accounts to access the web service. 
     
     
         11 . The apparatus of  claim 8  wherein the program instructions direct the processing system to apply the security measures for at least the one or more user accounts of the web service associated with the originator by directing the processing system to block access to the web service for all access attempts associated with the originator. 
     
     
         12 . The apparatus of  claim 8  wherein the program instructions direct the processing system to apply the security measures for at least the one or more user accounts of the web service associated with the originator by directing the processing system to send automatic password reset notifications to owners of the one or more user accounts. 
     
     
         13 . The apparatus of  claim 8  wherein the program instructions further direct the processing system to determine other user accounts of the web service having passwords found in a same credential data source as the compromised credentials used by the one or more user accounts associated with the originator that used the compromised credentials, and responsively send automatic password reset notifications to owners of the other user accounts. 
     
     
         14 . The apparatus of  claim 8  wherein the program instructions further direct the processing system to receive a credential query transmitted from an authorized user of the web service, responsively compare legitimate credentials of the authorized user received in the credential query with the compromised credentials in the database, and transfer a notification for delivery to the authorized user that indicates whether or not the legitimate credentials of the authorized user appear in the database of compromised credentials. 
     
     
         15 . One or more computer-readable storage media having program instructions stored thereon to facilitate securing web services from unauthorized access, wherein the program instructions, when executed by a computing system, direct the computing system to at least:
 monitor user interactions with a web service;   generate sets of the user interactions per originator based on origination information associated with the user interactions;   process the sets of the user interactions to identify credentials used to access the web service per originator;   compare the credentials used to access the web service per originator with compromised credentials stored in a database to identify one or more user accounts of the web service associated with an originator that used the compromised credentials found in the database; and   apply security measures for at least the one or more user accounts of the web service associated with the originator that used the compromised credentials found in the database.   
     
     
         16 . The one or more computer-readable storage media of  claim 15  wherein the origination information associated with the user interactions uniquely identifies each originator. 
     
     
         17 . The one or more computer-readable storage media of  claim 15  wherein the program instructions direct the computing system to apply the security measures for at least the one or more user accounts of the web service associated with the originator by directing the computing system to increase a level of authentication required for the one or more user accounts to access the web service. 
     
     
         18 . The one or more computer-readable storage media of  claim 15  wherein the program instructions direct the computing system to apply the security measures for at least the one or more user accounts of the web service associated with the originator by directing the computing system to block access to the web service for all access attempts associated with the originator. 
     
     
         19 . The one or more computer-readable storage media of  claim 15  wherein the program instructions direct the computing system to apply the security measures for at least the one or more user accounts of the web service associated with the originator by directing the computing system to send automatic password reset notifications to owners of the one or more user accounts. 
     
     
         20 . The one or more computer-readable storage media of  claim 15  wherein the program instructions further direct the computing system to determine other user accounts of the web service having passwords found in a same credential data source as the compromised credentials used by the one or more user accounts associated with the originator that used the compromised credentials, and responsively send automatic password reset notifications to owners of the other user accounts.

Join the waitlist — get patent alerts

Track US2020137076A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.