The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
May. 18, 2021

Filed:

Oct. 30, 2018
Applicant:

Okta, Inc., San Francisco, CA (US);

Inventors:

Jason Erickson, San Mateo, CA (US);

Unmesh Vartak, Palo Alto, CA (US);

Amogh Vasekar, San Mateo, CA (US);

Gabriel Werman, San Francisco, CA (US);

Assignee:

Okta, Inc., San Francisco, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 9/32 (2006.01); H04W 12/06 (2021.01); H04W 12/122 (2021.01); H04L 9/00 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1441 (2013.01); H04L 9/3226 (2013.01); H04L 9/3228 (2013.01); H04L 63/102 (2013.01); H04L 63/1425 (2013.01); H04L 63/20 (2013.01); H04W 12/06 (2013.01); H04L 9/002 (2013.01); H04L 63/08 (2013.01); H04L 63/083 (2013.01); H04L 63/1408 (2013.01); H04L 63/1483 (2013.01); H04W 12/068 (2021.01); H04W 12/122 (2021.01);
Abstract

In response to detected attempts to gain unauthorized access to user accounts of an online system, a security module of an online system applies an attack response policy to take actions in response to the attempts. Possible responses of the policy include reordering credential types requested by the online system during multi-factor authentication-enabled login, switching to a mode in which login requests are accepted but login is not permitted for the requesting user, and logging information about the login requests. Logged information may be applied to enhance the ability to prevent future unauthorized accesses, such as adding credential values to a list of common credential values and prohibiting users from associating those values with their accounts, or training a model based on the logged information to predict a probability that a given login request is unauthorized.


Find Patent Forward Citations

Loading…