Time Since First

Prev Next

Find The: Time Since First Image

time_since_first

The time elapsed since the selected attribute(s) were first seen in an event, in milliseconds for compatibility with the other time Features.

For example:

  • Determining the "age" of a device or other attributes. An account, device and IP network range repeatedly seen together for three or more months is a positive indicator that the activity is legitimate.
  • Performing step-up authentication when the age of a device is less than one day.

Configuration

  • Feature Name: The "dictionary" name under which the feature value will be stored and referenced by in rules.
  • For Events:
    • With The Same: Provides a way of filtering past events based on the attribute values. There must be at least one Identifier and only Identifier and Subject attributes can be used.

Optional Configuration

  • Default Value: A value that can be assigned to the feature if the attributes to calculate the features are not present.
  • Scope: Can be used to extend the event search from the local node, to all nodes within the same organization all the way to all across customers (global).
  • For Events:
    • All event types: Default, no filter
    • Same as current: Filter by event_type of event being processed
    • Specific event type: List out the event_type to restrict to, as a list. Example: only consider account_login_success.
  • Condition: A Query-Language filter that can be used to refine Features for specific use cases.
  • Time Window: Can be used to limit the Feature calculation to a specific time period/window. e.g 1 week. Default is all ; no time window
  • Starting: Can be used to remove recent events from Feature calculation. Default is immediately ; no lag.

How Time Since First is calculated
Configured for account_login_success events with the same customer token and device identifier, it finds the oldest matching event and returns the time from there to this one. Events of other types are skipped, however recent they are.

Time Since First measures from the oldest matching event to this one

Use Case 1

How long this customer has been logging in with this device. A device first seen on the account months ago is a positive indicator for a returning user; one first seen minutes ago, on an account that has existed for years, is worth a step-up challenge.

  • With The Same pairs the customer token with the device identifier, so the age is of that combination and not of either on its own.
  • The Default Value is 0, so the first login on a new device reads as an age of 0 rather than producing no Feature at all. That is the value a step-up rule tests.

Implementing In The Feature Editor

Image
Image

  - name: cust_device_age
    default_value: 0
    time_window: all
    starting: immediately
    find_the:
      time_since_first:
        events:
          event_type:
            - account_login_success
          include_current_event: false
          with_the_same:
            - identity['ACCOUNT'].customer_token.customer_token
            - device_signature['VER_1'].identifier
    with_scope: same_node_instance