How can I distinguish the genuine user from an intruder?¶
id: "AI-028" title: "How can I distinguish the genuine user from an intruder?" series: "Accounts and Identity" content_type: "video-script" status: "draft" owner: "IF Digital"
How can I distinguish the genuine user from an intruder?¶
Script¶
An account may contain activity from both the genuine user and an intruder.
Your task is to separate them.
Start with a timeline.
Identify activity that is clearly linked to the genuine user before the suspected compromise.
Then identify the first event that may show unauthorised access.
A new device.
A password reset.
A changed recovery address.
An unfamiliar session.
A security alert.
Next, examine the disputed activity.
Which session performed it?
Which device, application and IP address were associated with that session?
Did the activity continue from the intruder's new session, or did it come from a long-standing trusted device?
Compare behaviour as well.
Who was contacted?
What information was used?
What language, spelling or working pattern appears?
Did the user know facts that only the genuine holder would know?
Did the activity benefit the account holder, the intruder or somebody else?
Behavioural features can help, but they are not decisive on their own.
People change tone.
Offenders can imitate language.
Automated systems can produce consistent patterns.
Device and session evidence is usually stronger when it can be tied to possession or control.
Look for corroboration outside the account.
Messages on another platform.
Bank activity.
CCTV.
Location records.
Malware or phishing evidence.
Possession of the device used for the suspicious session.
Also consider overlap.
The genuine user and intruder may both be active at the same time.
One may read messages while the other sends them.
Do not force the evidence into a single-user explanation if the records support concurrent access.
Your conclusion should be tied to particular events.
You may be able to attribute some activity confidently while leaving other actions unresolved.
The goal is not to label the entire account as genuine or compromised.
It is to identify which person most likely carried out each relevant action, based on the session, device, timing and surrounding evidence.