发明名称 Defeating real-time trojan login attack with delayed interaction with fraudster
摘要 A method of detecting a fraudulent login attempt across a network is provided. The method includes (a) receiving, at some time, a login request from a client, the login request including (1) a username associated with a user account, (2) a static password associated with the user account, and (3) a one-time password provided by a token, (b) calculating whether the time is more than a predetermined amount of time after a most-recent login to the account, (c) when the time is more than the predetermined time since the most-recent login, accepting the login request according to a first mode, and (d) when the first time is not more than the predetermined time since the most-recent login, accepting the login request according to a second mode, the second mode rejecting a greater proportion of login attempts than the first mode rejects. An apparatus and computer program product are also provided.
申请公布号 US8452980(B1) 申请公布日期 2013.05.28
申请号 US20100748619 申请日期 2010.03.29
申请人 BLACK ROBERT SETH;ACKERMAN KARL;EMC CORPORATION 发明人 BLACK ROBERT SETH;ACKERMAN KARL
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址