Session Anomaly Detection

Two detectors over login events combine into one compromised-session verdict

Session Anomaly Detection Two detectors over login events combine into one compromised-session verdict 01 / Events 02 / Enrich 03 / Detect 04 / Combine 05 / Verdict Login Events · auth stream · 01 / Events · raw Login Events auth stream raw Geo + IP Lookup · resolve coords · 02 / Enrich · context Geo + IP Lookup resolve coords context Impossible Travel · Haversine dist / time · 03 / Detect · detector Impossible Travel Haversine dist / time detector Credential Stuffing · IP-range density · 03 / Detect · detector Credential Stuffing IP-range density detector Risk Combiner · weighted score · 04 / Combine · fan-in Risk Combiner weighted score fan-in Session Verdict · compromised? · 05 / Verdict · decision Session Verdict compromised? decision raw logins consecutive pairs IP buckets travel score density score risk verdict Legend primary data policy / PII async batch data store

One Stream, Two Views

  • • Login events are enriched once with geo and IP data
  • • The same events feed both detectors in parallel
  • • Detectors are independent and testable

The Detectors

  • • Haversine flags travel too fast to be physical
  • • Density flags many failed logins across an IP range
  • • Each emits a bounded score, not a hard yes/no

Combined Verdict

  • • Scores merge with weights, not a single rule
  • • The combiner is the only place that decides
  • • Output is one compromised-session verdict