- 专利标题: Third-party application risk assessment in an authorization service
-
申请号: US16870721申请日: 2020-05-08
-
公开(公告)号: US11503062B2公开(公告)日: 2022-11-15
- 发明人: Tatjana Vlahovic , Gail Anna Rahn Frederick
- 申请人: eBay Inc.
- 申请人地址: US CA San Jose
- 专利权人: eBay Inc.
- 当前专利权人: eBay Inc.
- 当前专利权人地址: US CA San Jose
- 代理机构: Shook, Hardy & Bacon L.L.P.
- 主分类号: H04L29/00
- IPC分类号: H04L29/00 ; H04L9/40 ; G06Q10/06 ; G06Q10/10 ; G06Q30/00 ; G06Q50/26 ; G06N20/00 ; G06F9/54
摘要:
Technologies are shown for application risk assessment in an authentication service where an authorization request is received from a third party application calling an Application Programming Interface (API). Risk assessment policies that pertain to behavioral characteristics, such as API usage patterns or past delegation of permissions, are applied to the authorization request to obtain a risk assessment score. If the risk assessment score does not exceed a risk threshold, then an authorization message is sent in response to the authorization request. If the risk assessment score exceeds the risk threshold, then remedial action, such as suspending the application, limiting the available actions, or sending a notification to a trusted security application, is executed for an account associated with the third party application. Machine learning can be applied to historical behavioral data to generate the risk assessment policies.
公开/授权文献
信息查询