← Back to plugin index

Typical Geolocation Risk Extractor

Description
Emits tags based on whether the current geolocation of the end-user is typical or not by comparing it to stored geolocation information from preceding logins.

  • This risk extractor depends on the user identity. Make sure to place the corresponding Risk Assessment Step after the user-identifying step (e.g. the Password Authentication Step) in the authentication flow.
  • This plugin requires that a Login History Repository is configured in the Authentication Flows configuration.
  • This plugin requires a geolocation provider to be configured in Loginapp's REST settings.

Type name
TypicalGeolocationRiskExtractorFlow
Class
com.airlock.iam.authentication.application.configuration.risk.extractor.geolocation.TypicalGeolocationRiskExtractorFlowConfig
May be used by
Properties
Geolocation Attribute To Match (geolocationAttributeToMatch)
Description

The geolocation attribute to compare with those from previous logins.

  • Continent: Uses the continent for comparison
  • Country: Uses the country for comparison
Attributes
Enum
Optional
Default value
COUNTRY
Minimal Required History Entries (minimalRequiredHistoryEntries)
Description

The minimal number of previously recorded logins required. If the user's entire login history contains fewer entries, this extractor always returns the "Tags When Below Percentage Tage Of Matches".

The optimum value depends on the exact use-case:

  • A low value like 1 or 2 may be preferred in low-risk environments or in new setups with fresh users where the first login is often the most trusted one because it might have involved an IAK or alike.
  • A medium value like 5 may be preferred when a longer, consistent history is required; thus the user must perform strong logins for an extended period of time before he may be granted a relaxation of authentication.
Attributes
Integer
Optional
Default value
3
Maximal Considered History Entries (maximalConsideredHistoryEntries)
Description
The maximal number of previously recorded logins to compare with the current data. If the user's login history contains more entries, only this number of entries (the most recent ones) will be considered.

The optimum value depends on the exact use-case and on the setting of the "Percentage Of Matches":

  • A low value like 1 or 2 may be preferred in low-risk environments where changes in the user's context are frequent.
  • A medium value like 5 may be preferred when a longer, consistent history is the typical use case for users.

Attributes
Integer
Optional
Default value
6
Percentage Of Matches (percentageOfMatches)
Description
The minimum percentage of the login history that have to match.

The optimum value depends on the exact use-case and on the setting of the "Maximal Considered History Entries":

  • A low value like 25 or 30 may be preferred in low-risk environments where users often work in different locations and access the system with more than two devices. In such a scenario the "Maximal Considered History Entries" may be increased to a high value.
  • A medium value like 40 or 45 may be preferred where users often work in two locations and access the system with two different devices (e.g. office location, home office). In such a scenario the "Maximal Considered History Entries" may be increased to a medium to high value.
  • A high value like 80 or 90 may be preferred where users always use the same device and rarely change their context. In such a scenario the "Maximal Considered History Entries" may be set to a low to medium value so that an exception in the history will be recovered quickly.

Attributes
Integer
Optional
Default value
80
Tags When Above Or Equal Percentage Of Matches (tagsWhenAboveOrEqualPercentageOfMatches)
Description
The tags to grant if the current information matches at least the specified "Percentage Of Matches".
Attributes
Plugin-List
Optional
Assignable plugins
Tags When Below Percentage Tage Of Matches (tagsWhenBelowPercentageOfMatches)
Description
The tags to grant if the current information does not match the specified "Percentage Of Matches" or there were too few history entries or the current information could not be determined.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: TypicalGeolocationRiskExtractorFlow
id: TypicalGeolocationRiskExtractorFlow-xxxxxx
displayName: 
comment: 
properties:
  geolocationAttributeToMatch: COUNTRY
  maximalConsideredHistoryEntries: 6
  minimalRequiredHistoryEntries: 3
  percentageOfMatches: 80
  tagsWhenAboveOrEqualPercentageOfMatches:
  tagsWhenBelowPercentageOfMatches: