Patent · US Expired

Method and apparatus for detecting password attacks using modeling techniques

US7386892B2 · kind B2 · utility

33Cited by
6References
5Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJul 17, 2003
Grant dateJun 10, 2008
Priority date
Expiry dateOct 23, 2024

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/31
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

Provided is an apparatus and method for detecting fraudulent passwords so that computer break-in attempts can be distinguished from authorized users incorrectly entering their passwords. An actual password is mapped against a computer keyboard and the resultant data is stored in memory. The profile of an entered password is compared to the stored profile. If the profile of the entered password differs significantly from the stored profile, then the login attempt is flagged as an attempted intrusion. In one embodiment of the current invention, passwords are mapped according to the distance subsequent keystrokes are from each other. Different embodiments may have different mapping schemes. For example, mapping data may correspond to statistical data that corresponds to the likelihood that a particular character is typed by mistake when another character is intended.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.