Detecting a compromised online user account
First Claim
1. A method for mitigating a compromised online user account, comprising:
- establishing a baseline for an online user account comprising identifying information about at least one of communications from the online user account or communications to the online user account, comprising identifying one or more of;
a duration of one or more communications;
a mode of one or more communications;
ora type of a contact associated with one or more communications;
detecting a deviation from the baseline indicative of a potential compromise to the online user account, detecting a deviation comprising comparing an activity segment value from a desired period of activity for the online user account with a threshold value, the deviation based upon at least one of;
a duration deviation of one or more durations of one or more first communications from a combination of one or more durations of one or more second communications associated with the baseline, at least one of the one or more durations of the one or more first communications or the one or more durations of the one or more second communications corresponding to a duration of at least one of email messaging, instant messaging (IM), text messaging, voice messaging, video messaging or chatting, posting to a message board, posting a comment to online content, posting an update to a status stream, uploading content, micro-blogging or blogging;
a mode deviation of one or more modes of one or more third communications from a combination of one or more modes of one or more fourth communications associated with the baseline, at least one of the one or more modes of the one or more third communications or the one or more modes of the one or more fourth communications corresponding to at least one of email messaging, IM, text messaging, voice messaging, video messaging or chatting, posting to a message board, posting a comment to online content, posting an update to a status stream, uploading content, micro-blogging or blogging;
ora type deviation of one or more types of one or more contacts of one or more fifth communications from a combination of one or more types of one or more contacts of one or more sixth communications associated with the baseline, the one or more types of the one or more contacts of the one or more fifth communications corresponding to at least one of an age of the one or more contacts of the one or more fifth communications, how long the one or more contacts of the one or more fifth communications have been linked to the online user account, whether the one or more contacts of the one or more fifth communications are linked to the online user account or whether the one or more contacts of the one or more fifth communications are comprised in an address book of the online user account; and
notifying a user of the online user account of the potential compromise.
2 Assignments
0 Petitions
Accused Products
Abstract
One or more techniques and/or systems are disclosed for detecting and/or mitigating a potentially compromised online user account. One or more baselines can be established for a user'"'"'s online account to determine a normal usage pattern for the account by the user (e.g., frequency of incoming/outgoing emails, text messages, etc.). The online user account can be periodically or continually monitored for use of the same resources used to determine the baseline(s). If a deviation from the baseline is detected, the deviation may be compared against a threshold to determine whether the deviation indicates that the account may be compromised. When an indication of a potentially compromised account is detected, the user can be notified of the indication, so that one or more actions can be taken to mitigate the potentially compromised account.
157 Citations
20 Claims
-
1. A method for mitigating a compromised online user account, comprising:
-
establishing a baseline for an online user account comprising identifying information about at least one of communications from the online user account or communications to the online user account, comprising identifying one or more of; a duration of one or more communications; a mode of one or more communications;
ora type of a contact associated with one or more communications; detecting a deviation from the baseline indicative of a potential compromise to the online user account, detecting a deviation comprising comparing an activity segment value from a desired period of activity for the online user account with a threshold value, the deviation based upon at least one of; a duration deviation of one or more durations of one or more first communications from a combination of one or more durations of one or more second communications associated with the baseline, at least one of the one or more durations of the one or more first communications or the one or more durations of the one or more second communications corresponding to a duration of at least one of email messaging, instant messaging (IM), text messaging, voice messaging, video messaging or chatting, posting to a message board, posting a comment to online content, posting an update to a status stream, uploading content, micro-blogging or blogging; a mode deviation of one or more modes of one or more third communications from a combination of one or more modes of one or more fourth communications associated with the baseline, at least one of the one or more modes of the one or more third communications or the one or more modes of the one or more fourth communications corresponding to at least one of email messaging, IM, text messaging, voice messaging, video messaging or chatting, posting to a message board, posting a comment to online content, posting an update to a status stream, uploading content, micro-blogging or blogging;
ora type deviation of one or more types of one or more contacts of one or more fifth communications from a combination of one or more types of one or more contacts of one or more sixth communications associated with the baseline, the one or more types of the one or more contacts of the one or more fifth communications corresponding to at least one of an age of the one or more contacts of the one or more fifth communications, how long the one or more contacts of the one or more fifth communications have been linked to the online user account, whether the one or more contacts of the one or more fifth communications are linked to the online user account or whether the one or more contacts of the one or more fifth communications are comprised in an address book of the online user account; and notifying a user of the online user account of the potential compromise. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14)
-
-
15. A system, implemented at least in part via a processing unit, for mitigating a compromised online user account, comprising:
-
a baseline establishing component configured to establish a baseline for an online user account by identifying information about at least one of communications from the online user account or communications to the online user account, comprising identifying a duration of one or more communications; a deviation detection component configured to detect a deviation from the baseline indicative of a potential compromise to the online user account, detecting a deviation comprising comparing an activity segment value from a desired period of activity for the online user account with a threshold value, the deviation based upon a mode deviation of one or more modes of one or more first communications from a combination of one or more modes of one or more second communications associated with the baseline, at least one of the one or more modes of the one or more first communications or the one or more modes of the one or more second communications corresponding to at least one of email messaging, instant messaging (IM), text messaging, voice messaging, video messaging or chatting, posting to a message board, posting a comment to online content, posting an update to a status stream, uploading content, micro-blogging or blogging; and a user notification component configured to notify a user of the online user account of the potential compromise. - View Dependent Claims (16, 17, 18, 19)
-
-
20. A computer readable medium, excluding signals, comprising instructions that when executed perform a method for mitigating a compromised online user account, comprising:
-
establishing a baseline for an online user account comprising identifying information about at least one of communications from the online user account or communications to the online user account, comprising identifying a type of a contact associated with one or more communications; detecting a deviation from the baseline indicative of a potential compromise to the online user account, detecting a deviation comprising comparing an activity segment value from a desired period of activity for the online user account with a threshold value, the deviation based upon a type deviation of one or more types of one or more contacts of one or more first communications from a combination of one or more types of one or more contacts of one or more second communications associated with the baseline, the one or more types of the one or more contacts of the one or more first communications corresponding to at least one of an age of the one or more contacts of the one or more first communications, how long the one or more contacts of the one or more first communications have been linked to the online user account, whether the one or more contacts of the one or more first communications are linked to the online user account or whether the one or more contacts of the one or more first communications are comprised in an address book of the online user account; and notifying a user of the online user account of the potential compromise.
-
Specification