Autolearning Pattern-Based Policy: OAAM Users vs. All Users

11-22 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager

11.5.4.1.2 OAAM Registration Flow Diagram

Figure 11–11 OAAM Registration Flow

11.5.4.1.3 OAAM Registration: Details of Rules

Table 11–18 OAAM Registration Policy Summary Summary Details Purpose Determines what parts of user information has to be registered Scoring Engine Weighted Average Weight 100 Group Linking All Users Table 11–19 OAAM Registration Policy Rules Details Rule Rule Condition and Parameters Results Check Registration User: Account Status User Account Status = ACTIVE Is = FALSE Action = OAAM Register Alert = NONE Score = 0 Register Questions User: Question Status User Question Status = Set Is = FALSE Action = OAAM Register Challenge Questions Alert = NONE Score = 0 OAAM Security and Autolearning Policies 11-23

11.5.4.1.4 OAAM Registration: Trigger Combinations

None

11.5.5 Challenge Policies

Challenge policies are presented in this section.

11.5.5.1 OAAM Challenge

This policy determines how the user has to be challenged. All the decision making in this policy is achieved using trigger combinations.

11.5.5.1.1 OAAM Challenge Policy Summary

11.5.5.1.2 OAAM Challenge Flow Diagram

Skipped registration more than 3 times User: Action Count Timed Checkpoint Optional = NONE Action = Register User Optional In seconds = 300 Count Action only once per session? = TRUE More Than = 3 Action = OAAM Registration Required Alert = NONE Score = 0 Register User Information User: Check Information Key to comma separated values to check = RequiredChallengeInfo If Information is set, return = FALSE Action = OAAM Register User Information Alert = NONE Score = 0 Register Image and Caption User: Authentication Image Assigned Is Assigned = FALSE Action = OAAM Register Preferences Alert = NONE Score = 0 Table 11–20 OAAM Challenge Policy Summary Summary Details Purpose Determines how the user has to be challenged. All the decision making in this policy is achieved using trigger combinations. Scoring Engine Weighted Average Weight 100 Group Linking All Users Table 11–19 Cont. OAAM Registration Policy Rules Details Rule Rule Condition and Parameters Results 11-24 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager Figure 11–12 OAAM Challenge Flow

11.5.5.1.3 OAAM Challenge: Details of Rules

OAAM Security and Autolearning Policies 11-25

11.5.5.1.4 OAAM Challenge: Trigger Combinations

Table 11–21 OAAM Challenge Policy Rules Details Rule Rule Condition and Parameters Results Max failed SMS attempts User: Check OTP failures OTP Challenge Type = ChallengeSMS Failure More than or Equal To = 3 If above or equal = TRUE Action = NONE Alert = NONE Score = 0 Max failed Email attempts User: Check OTP failures OTP Challenge Type = ChallengeEmail Failure More than or Equal To = 3 If above or equal = TRUE Action = NONE Alert = NONE Score = 0 Max failed Question attempts User: Challenge Maximum Failures Number of Failures More than or equal to = 3 Current Question Count only? = False If above or equal, return = True Action = NONE Alert = NONE Score = 0 Questions Active User: Question Status User Question Status = Set Is = True Action = NONE Alert = NONE Score = 0 Challenge Email Available Session: Check value in comma separated values Parameter Key = AvailableChallengeTypes Value to Check = ChallengeEmail Return if in list = True Action = NONE Alert = NONE Score = 0 Challenge SMS Available Session: Check value in comma separated values Parameter Key = AvailableChallengeTypes Value to Check = ChallengeSMS Return if in list = True Action = NONE Alert = NONE Score = 0 Check for HIGH Risk Score Session: Check Risk Score Classification Risk score classification to check = High Risk Default value to return in case of errors = False Action = NONE Alert = NONE Score = 0