×

Systems and methods for IP-based intrusion detection

  • US 9,699,203 B1
  • Filed: 09/22/2015
  • Issued: 07/04/2017
  • Est. Priority Date: 03/13/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • receiving, at a server computer, a first plurality of login requests, each comprising a username and a password;

    identifying a first internet protocol (IP) address and a first request time associated with each of the first plurality of login requests;

    determining that a total number of login requests from the first IP address within a threshold time period is above a credential security threshold;

    determining that a number of usernames associated with the first plurality of login requests is above a username threshold;

    determining that a login success ratio is below a threshold login success ratio after determining that the total number of login requests from the first IP address is above the credential security threshold; and

    in response to determining the login success ratio is below the threshold login success ratio and determining that the number of usernames is above the username threshold, automatically performing a security action using the server computer;

    wherein determining the number of usernames associated with the total number of login requests comprises;

    comparing each username with each other username to determine a difference value for each username pair, wherein the difference value for each username pair comprises a sum of each character change, character addition, and character subtraction required to transform a first username of each username pair into a second username of each username pair; and

    for each username pair identified as similar usernames having a difference value less than a threshold difference value, counting the similar usernames as a single username for the number of usernames as compared to the username threshold.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×