International Business Machines Corporation
DETECTING REPLAY ATTACKS USING ACTION WINDOWS

Last updated:

Abstract:

An example system includes a processor to receive a current session and previous sessions associated with an account. The processor can split the current session and the previous sessions into action windows. The processor can calculate a window similarity score for each action window of the current session using a pair-wise comparison with action windows of each of the previous sessions. The processor can aggregate the window similarity scores to generate a replay likelihood score for the current session with respect to each of the previous sessions. The processor can classify the current session as a replay attack in response to detecting that a replay likelihood score of the current session exceeds a threshold.

Status:
Application
Type:

Utility

Filling date:

2 Apr 2020

Issue date:

7 Oct 2021