Holds recent fraud scores in memory so that intrusion detection can act on them. This exists because the two systems keep different shapes: fraud scores a transaction, while IDP evaluates an HTTP request. The bridge is that a score is remembered against the IP and the profile it came from for a short while, and IDP's rules can then ask about it on this and subsequent requests using the vocabulary they already have. It is deliberately in memory and deliberately approximate: a score that is lost to a restart costs the client one missed escalation, not a fraudulent transaction, since the transaction was already scored and, if it was bad enough, already blocked. The durable record lives elsewhere; this is only the short-lived signal IDP reads.
Properties
| Property | Returns | Description |
|---|---|---|
| trackedKeys | int | How many distinct keys (profiles, IPs and accounts) currently have scores tracked in memory, for the IDP status display. |
Methods
record(Long tenantId, Long profileId, String ipAddress, int score)
Returns: void
Records a score against the profile and the IP it came from, and against the account as a whole, so later lookups can find it by whichever key IDP is using.
| Parameter | Description |
|---|---|
tenantId | the account the score belongs to. Must not be null |
profileId | the profile, or null if there was none |
ipAddress | the client IP, or null if it could not be determined |
score | the score, 0 to 100 |
findMaxScore(String key, long windowSecs)
Returns: long
The highest score seen for a key within a window.
| Parameter | Description |
|---|---|
key | the key, built by userKey, ipKey or globalKey. Must not be null |
windowSecs | how far back to look, in seconds. Must be greater than zero |
countScores(String key, long windowSecs)
Returns: long
How many scores were recorded for a key within a window. A run of moderate scores can be more telling than one high score, so IDP is given both.
| Parameter | Description |
|---|---|
key | the key. Must not be null |
windowSecs | how far back to look, in seconds. Must be greater than zero |
getTrackedKeys()
Returns: int
How many distinct keys (profiles, IPs and accounts) currently have scores tracked in memory, for the IDP status display.