Machine learning assisted bot detection
The method uses machine learning to identify and monitor malicious bots by analyzing user behaviors, enhancing detection accuracy and protecting data through real-time platform configuration, addressing the limitations of existing cybersecurity solutions.
Patent Information
- Authority / Receiving Office
- GB · GB
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-30
- Publication Date
- 2026-04-01
AI Technical Summary
Current cybersecurity solutions struggle to accurately detect and monitor malicious bots mimicking human behavior, leading to potential data breaches and financial losses, as they lack real-time behavioral pattern analysis and are easily evaded by sophisticated bots.
A method and system that utilize machine learning to identify bot-like and human-like behaviors, determining a bot-likelihood score by monitoring user activities in real-time, and configure the electronic platform to inhibit access to secure data without alerting the bot, preserving navigational structure.
Enhances detection accuracy by combining bot-like and human-like behavior analysis, allowing real-time monitoring of malicious bots while protecting sensitive data and maintaining platform functionality, thereby reducing security risks and operational losses.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
FIELD The present invention relates in general to cybersecurity, cybersecurity systems and more specifically the detection and monitoring of malicious bots presenting as humans. BACKGROUND It is recognized that approximately half of all visits to websites are from non-human software entities, also known as bots. Bots account for an average of 47% of website visits. Of these bot visits, approximately 40% are from legitimate sources (e.g., search engine scrapers, preview bots, and the like), but the remainder (approximately 60% of all bots) are malicious and looking to do harm. Malicious bots are responsible for many types of harmful behavior, including account takeover, credential stuffing, content scraping, denial of inventory, planting ransomware, data theft, phishing attacks, malware injection, information gathering purposes and more. Bots can also corrupt website visitor analytics and waste advertising spend. According to the UK National Cyber Security Centre (NCSC), data breaches cost upwards of $180k to fix and 60% of small and medium companies go out of business within six months of falling victim to a data breach or cyber-attack. Businesses may be faced with direct financial consequences as a result of malicious bots acting on websites. For example, an organization investing in digital advertising may be likely to pay for malicious bots to view and click on their digital adverts and paying per click. This wastes budget and can pollute advertising analytics which may result in poor spending decisions for future adverts, wasting further budget. A further consequence of malicious bots for businesses is one of analytical visibility. Many analytical platforms will exclude the metrics of non-malicious bots from their data, but because malicious bots are designed or programmed to present as human, their behavior may be counted as human behavior for the purposes of decision making regarding the success and future direction of a platform or website. This may have an impact on peripheral but nonetheless important business factors, such as valuation, profitability that ultimately may have a bearing on an organization’s success. As the sophistication of malicious users, particular with the advent of easily deployable machine learning (ML) modelling, make detection increasingly harder and may require a comprehensive and regularly updated set of ML tools. This may lead to an “arms race” scenario whereby bot makers innovate to avoid detection, and bot detectors innovate to improve detection capability. Typical solutions currently offered may comprise ‘detect and protect’ protocols. However, said detect and protect protocols may not be sufficient to deal with cutting edge malicious bot technology. For example, ‘edge based’ security solutions have access to limited data, as a network &packet layer and may not capture real-time behavioural patterns that are available client-side (e.g., in a user network in a browser or app). Malicious bots, e.g., on a website, web app, or mobile app, may be involved in any number of activities from short-term / drive-by attacks such as credential stuffing, account creation or takeover, web scraping, defacement and the like. Bots may be active in longer-term reconnaissance activities, such as vulnerability scanning, industry tech stack mapping and phishing preparation. Blocking bots at point of detection may remove any ability to understand an intent of the bot (i.e., the purpose it was created for). Similarly, shutting down a bot at the point of detection may remove a potentially large set of useful data about the bot and the bot owner for multiple uses. State of the art bots may be “self-aware” to a greater or lesser extent, e.g., to understand the framework of the environment they are operating in (e.g., website address, site structure, API format, mobile app structure). Thus, any obvious changing of the environment in order to evaluate the bot (by for example, moving the bot to a sandtrap URL) may be detected and may result in the bot shutting down and / or taking counter measures. Thus, it is desirable that a bot is not “aware” that it is being observed for accurate monitoring results and providing more data for offline analysis, law enforcement purposes and Al learning. As bots improve human-mimicking behaviour, state of the art bot detection tools are increasingly likely to fail. To aid detection, an understanding of bot intent by monitoring bot behaviour in real-time without giving the bot, or any observer of the bot such as a malicious C&C system, any indication that monitoring is taking place is desirable, as awareness of monitoring may result in the creation of bots that are capable of monitoring for observation in order to take counter measures. Accordingly, it may be desirable to provide for modifying, or configuring, real data served from e.g., an end-user core network in order to protect any sensitive information and / or technical data from being exposed to malicious users; setting detection traps for bots in order to better understand their intent; and building a comprehensive set of data about bots for offline processing of any types required. SUMMARY In a first aspect, there is provided a method of configuring an electronic platform, the method comprising: monitoring, by a user monitoring entity, an activity of a user on the electronic platform; determining, by the user monitoring entity, a user type based on the activity of the user; and based on a determination that the user type is malicious; sending, from the user monitoring entity to a platform configuring entity, an indication that the user type is malicious; and configuring, by the platform configuring entity, the electronic platform to inhibit access by the user to secure data, wherein a navigational structure of the electronic platform is preserved. By preserving the navigation structure of the platform, it is possible to monitor malicious users without alerting said malicious user to being monitored and thus monitor the malicious user’s intention. In some examples, the method may further comprise determining, by the user monitoring entity, a machine learning model based on historical user activity; and determining a user type based on the machine learning model. In some examples, the step of determining a user type may comprise: determining bot-like behaviors; determining human-like behaviors; and determining a bot-likelihood score based on the bot-like behaviors and the human like-behaviors. By determining human like-behaviors in addition to bot like-behaviors the accuracy of determining a bot may be improved. In some examples, determining that the user is malicious may comprise determining that the user is a bot. In some examples, the step of determining that the user is a bot may be based on the bot-likelihood score. In some examples, the method may further comprise determining a bot type based on the machine learning model. In some examples, the platform configuring entity and the user monitoring entity may be comprised in a user network. In some examples, the electronic platform may be any of a web-based environment, an internet-of-things-based environment, or an operational technology-based environment. In some examples, the step of configuring the platform may comprises at least one of: changing, removing and / or adding textual content; obscuring and / or replacing dynamic content; modifying an element of a document object model; or adding a document object model element. In this way, sensitive data may be protected whilst monitoring the activity of the malicious user. In some examples, the step of configuring the electronic platform may be based on a required level of protection. In some examples, the step of configuring may be based on a type and / or intent of the user. In some examples, the platform configuring entity may be disposed above a firewall of a user network and below a network edge. In this way, the platform configuring entity does not interfere with network traffic until directed to do so by user monitoring entity and therefore adds no latency to genuine traffic. In some examples, the method may further comprise monitoring the activity of the user; and predicting a future activity of the user based on the monitoring the activity of the user. In some examples, the activity of the user comprises cursor movement. In some examples, the step of configuring the electronic platform to inhibit access by the user to secure data may further comprise restricting access by the user to secure data. In some examples, the user monitoring entity may be comprised in a server network. In a second aspect, there is provided a computer program comprising instructions such that, when executed by a processor, cause a computer system comprising said processor to perform the method of the first aspect and examples. In a third aspect, there is provided a computer readable medium comprising instructions stored thereon such that, when executed by a processor, causes a computer system comprising said processor to execute the method of the first aspect and examples. In a fourth aspect there is provided a system for configuring an electronic platform, the system configured to: monitor, by a user monitoring entity, an activity of a user on the electronic platform; determine, by the user monitoring entity, a user type based on the activity of the user; and based on a determination that the user type is malicious; send, from the user monitoring entity to a platform configuring entity, an indication that the user type is malicious; and configure, by the platform configuring entity, the electronic platform to inhibit access by the user to secure data, wherein a navigational structure of the electronic platform is preserved. In some examples, the system may be configured to perform the method of any of the first aspect and examples. BRIEF DESCRIPTION OF DRAWINGS Figure 1 depicts a method of configuring an electronic platform and / or monitoring a user of an electronic platform in accordance with some embodiments; and Figure 2 depicts a system for configuring an electronic platform and / or monitoring a user of an electronic platform in accordance with some embodiments. DETAILED DESCRIPTION To address the problems associated with malicious users on electronic platforms, the present inventors have devised improved methods and systems for configuring an electronic platform and / or monitoring a user of an electronic platform such as a website, mobile app, internet of things environment, operational technology environment and the like. The methods provided for herein may solve many of the problems caused by malicious bots by identifying malicious bots when they enter electronic platforms in a timely manner, inhibiting the malicious bots before they can do damage, and alerting users within a network (e.g., other users, cybersecurity service providers, law enforcement agencies and the like) to assist them in countering the malicious bots. The methods provided for herein may differ from typical cybersecurity platforms because they may operate “client-side”, e.g., in a user network in a web or mobile browser where conventional security technology has no visibility. This may give access to behavioural patterns that may be used to determine a malicious bot by looking for bot behaviours and human behaviours within said behavioural patterns and combining them into a bot-likelihood score. The proposed methods may be applied to any electronic platform that may be susceptible to malicious user activity and may also include internet of things (loT) or operational technology (OT) environments and the like. Identifying human and bot behaviour via e.g., the browser may allow identification and trapping of bots that may not have been detected by other elements (i.e., conventional cybersecurity methods and systems) of an organisations’ cybersecurity stack. With reference to Figure 1 and Figure 2, in an aspect there may be provided a method 100 of configuring an electronic platform and / or monitoring a user of an electronic platform, the method comprising monitoring 110, by a user monitoring entity 220, an activity of a user on the electronic platform. Said user monitoring entity 220 may be cloud hosted, for example as a neural net. The user monitoring entity 220 may monitor for malicious user activity and in response to determining 120 that a user is malicious may send 130 an indication to a platform configuring entity 210 that said user is malicious. The determination that a user is malicious may be based on an activity of said user as described in more detail below. Said platform configuring entity 210 may be deployed in an end user network, for example as containerized software. Said platform configuring entity 210 may handle future requests from the malicious user and may report key metrics and user activity to the monitoring entity for real-time monitoring. Said platform configuring entity 210 may configure 140 the electronic platform, for example to inhibit access by the user to secure data, whilst preserving a navigational structure of the electronic platform. The electronic platform may be configured in real time. In this way, it may be possible to continue to monitor the (malicious) user in order to determine the intent and behavior of said user whilst minimizing a security risk. That is, said monitoring entity may monitor 150 the activity of the user after the platform has been configured to inhibit the user’s access to secure data. In this way, it may be possible to analyze active malicious user activity in real-time without alerting the malicious user (e.g., a malicious bot and / or an owner / originator) to the monitoring, or allowing the malicious user to access resources (e.g., a network and / or data hosted by the electronic platform) that the owner of wishes to keep secure. In some examples, the user monitoring entity 220 may determine a machine learning model based on historical user activity. For example, the user monitoring entity 220 may monitor cursor behavior of a user, (e.g., as would be provided by the movement of an input device such as a mouse). By taking historic user journey data (e.g., cursor trajectories) from anonymised journeys determined from user data and plotting cursor movements, it may be possible to determine a training set comprising images that may be used to train said machine learning model. In this way, the model may be trained to identify non-human behaviour and / or human behaviour. Accordingly, the machine learning model may be used by the user monitoring entity 220 to determine a user type (e.g., human, non-human and / or malicious). An example of bot behaviour that may be observed is bots simulating human cursor movements by tracing polynomial curves. This is a specific example of bot behaviour that may be used to differentiate bots from humans owing to the low probability that a human will produce a cursor plot that matches a polynomial curve. In some examples, regression modelling may be used to fit a given curve to known polynomial curve and returns a similarity metric for each of the known polynomial curves. A user’s cursor movements closely matching a known polynomial curve may be an indicator that said user may be a malicious bot. Determining a user type may, in some examples, further comprise determining non-human, or bot-like behaviours. That is, the user monitoring entity 220 may determine (e.g., based on the machine learning model), that the user activity comprises bot-like behaviours. Determining a user type may, in some examples, further comprise determining human-like behaviours. That is, the user monitoring entity 220 may determine (e.g., based on the machine learning model), that the user activity comprises human-like behaviours. Determining a user type may, in some examples, further comprise determining a bot-likelihood score. That is, the user monitoring entity 220 may determine based on the bot-like behaviours and the human-like behaviours, a score that may indicate a likelihood that a user is a bot. In this way, by determining not only bot-like behaviours (e.g., not just physical characteristics such as IP address and browser origin) but also human-like behaviours, a more accurate likelihood that a user is a bot may be determined. In some examples, the bot-like behaviours may comprise an indication that the user is malicious. Thus, the bot-likelihood score may comprise a likelihood that a user is malicious. Accordingly, in addition to identifying bots, there may be provided methods of proving humanity e.g., in a website visit (i.e., that the website visit is by that of a human and not a bot). By combining the results of human identification and bot identification, the resultant of the two separate determinations may provide a higher probability of detection success compared to bot identification alone. In some examples, the detection of human behaviour and / or bot behaviour may be based on machine learning methods. In some examples the machine learning model may be configured to determine a type of bot, for example a bot configured for creating fake accounts (also known as a fake account creating bot); a bot configured for breaking into legitimate user accounts with stolen credentials (known as a credential stuffing bot) and / or through a brute force attack; a bot configured for scraping data (e.g., extracting data from a website) for the creation of phishing sites and / or for commercial gain (also known as a scraping bot). A machine learning algorithm for human and / or bot detection may be updated and / or retrained as and when necessary, e.g., to allow determination of new or adapted bot behaviours. In some cases, a machine learning algorithm may be monitored, and if the performance of said algorithm falls below a pre-defined threshold a training cycle may be automatically triggered. This may save time over manually retraining the algorithm, may be a more robust and reliable way to ensure that the algorithm maintains a required performance level, and automatically keeps up with developments in bot behaviours. Supervised machine learning models may operate by taking in training data along with a series of correct responses (i.e., labels) to each of the training data points, also known as supervised learning. Unsupervised learning models, in contrast, may not require labelled training data. Known examples of unsupervised learning models include K-means clustering algorithms and reinforcement learning algorithms. Such unsupervised learning models may learn by finding patterns or structures within data to differentiate between different types of data. Unsupervised learning models may be advantageous over supervised models as the data may not have to be labelled with correct responses, an activity which may introduce a degree of bias into a model. In a specific example, a machine learning solution based on a random forest algorithm may be used to detect malicious bots. A random forest may comprise network of decision trees, each of which may make a prediction from a data point as to whether the origin of said data point is a human or a malicious bot. The random forest algorithm may learn to classify data points by finding an optimal weighting for all the trees based on how important it determines each of the trees to be. Trees determined to be more important may be given a higher weighting and thus more influence over the final output. When making predictions on data, the random forest may use a voting system across all trees while taking their weighting into account. In some examples, the platform configuring entity 210 and the user monitoring entity 220 may be comprised in a user network. That is, the platform configuring entity 210 and the user monitoring entity 220 may be comprised in a non-connected or offline environment such as an operational technology (OT) or internet of things (loT) environment. In other examples, the platform configuring entity 210 may be comprised in a user network (e.g., in a mobile app) and the user monitoring entity 220 may be comprised in a server network, such as provided by a service provider. In some examples, the user monitoring service may be cloud hosted (e.g., as a neural net). In response to receiving an indication that a user is a malicious bot, the platform configuring entity 210 may proceed to configure the electronic platform. Configuring the electronic platform may comprise any of: changing, removing and / or adding textual content on the electronic platform; obscuring and / or replacing dynamic content on the electronic platform; modifying an element of a document object model on the electronic platform; or adding a document object model element on the electronic platform. In any or all examples, the step of configuring the electronic platform may comprise preserving a navigational structure of the electronic platform. In this way, it may be possible to inhibit access by the user to secure data, such as personal data, passwords, financial data and / or the like, without stopping the user from navigating the platform. Advantageously, the user monitoring entity 220 may continue to monitor the user activity (e.g., in order to learn more about the user’s intent and behaviour to update the machine learning model and predict user activity) whilst maintaining a required level of protection and without alerting the malicious user. For example, the configuring the electronic platform may comprise removing a website link to sensitive or secure data, and replacing said website link with an imitation that does not lead to said sensitive or secure data. Accordingly, the user monitoring entity 220 may monitor the user’s interaction with the imitation link and learn the user’s behaviour and / or intent without presenting a security risk. Thus, aspects of the present disclosure may provide for detected bots to continue to interact with a web or mobile platform for data capture, learning and analysis without said detected bot being aware of monitoring. In some examples, this may be achieved by changing the served platform content in real time to ensure data and platform security whilst analysing said bot’s activity to continually update platform defences. Thus, the presently disclosed method may allow for the modification of data to e.g., a website and / or an app in real-time as determined by a user monitoring entity 220 (e.g., a new neural net Al) that may learn about malicious user types and / or intent to determine active defense strategies. In other words, aspects of the present disclosure may provide methods for determining an intention of a malicious bot. In some cases, the intention of the malicious bot may be shared with other users. In some examples, inhibiting access by the user to secure data may further comprise restricting access by the user to secure data. In some examples, the platform modification may be based on a required level of protection. That is, the platform modification may be based on a level of financial risk, or access to certain types of data. In a non-limiting example, a malicious bot may be allowed to create a user account that the malicious bot (and / or owner thereof) understands to be legitimate. However, the account is known as a malicious bot account and thus limited (e.g., confined to a controlled space, also known as sandboxing). In some examples, the platform modification may be based on a type and / or intent of the user. E.g. if the user is determined to be a scraping bot the electronic platform may be configured by replacing legitimate text with fake text, for example “Lorem Ipsum” or more realistic looking text generated by, for example, a generative Al system, and / or changing product pricing for an ecommerce site. The platform configuring entity 210 may be disposed above a firewall 240 of a user network and below a network edge 230. In this way, platform configuring entity 210 does not interfere with network traffic until directed to do so by user monitoring entity 220 and therefore adds no latency to genuine traffic, and / or is immediately available when required. In any or all examples, the user activity may comprise cursor movement (e.g., cursor trajectory as would be provided by the movement of an input device such as a mouse). An example of bot behaviour that may be observed is bots simulating human cursor movements by tracing polynomial curves. This is a specific example of bot behaviour that may be used to differentiate bots from humans owing to the low probability that a human will produce a cursor plot that matches a polynomial curve. In some examples, regression modelling may be used to fit a given curve to known polynomial curve and returns a similarity metric for each of the known polynomial curves. A user’s cursor movements closely matching a known polynomial curve may be an indicator that said user may be a malicious bot. In an aspect, there may be provided computer program comprising instructions such that, when executed by a processor, cause a computer system comprising said processor to perform any of the methods described herein. In a further aspect there may be provided a computer readable medium comprising instructions stored thereon such that, when executed by a processor, causes a computer system comprising said processor to execute any of the methods described herein. In a further aspect, there may be provided a system for configuring an electronic platform and / or monitoring a user of an electronic platform, the system configured to monitor, by a user monitoring entity 220, an activity of a user on the electronic platform; determine, by the user monitoring entity 220, a user type based on the activity of the user; and based on a determination that the user type is malicious; send, from the user monitoring entity 220 to a platform configuring entity, an indication that the user type is malicious; configure, by the platform configuring entity, the electronic platform to inhibit access by the user to secure data, wherein a navigational structure of the electronic platform is preserved; and monitor, by the user monitoring entity 220, the activity of the user. The description provided herein may be directed to specific implementations. It should be understood that the discussion provided herein is provided for the purpose of enabling a person with ordinary skill in the art to make and use any subject matter defined herein by the subject matter of the claims. It should be intended that the subject matter of the claims not be limited to the implementations and illustrations provided herein, but include modified forms of those implementations including portions of implementations and combinations of elements of different implementations in accordance with the claims. It should be appreciated that in the development of any such implementation, as in any engineering or design project, numerous implementation-specific decisions should be made to achieve a developers’ specific goals, such as compliance with system-related and business-related constraints, which may vary from one implementation to another. Moreover, it should be appreciated that such a development effort may be complex and time consuming, but would nevertheless be a routine undertaking of design, fabrication, and manufacture for those of ordinary skill having benefit of this disclosure. Reference has been made in detail to various implementations, examples of which are illustrated in the accompanying drawings and figures. In the detailed description, numerous specific details are set forth to provide a thorough understanding of the disclosure provided herein. However, the disclosure provided herein may be practiced without these specific details. In some other instances, well-known methods, procedures, components, circuits, and networks have not been described in detail so as not to unnecessarily obscure details of the embodiments. It should also be understood that, although the terms first, second, etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and, similarly, a second element could be termed a first element. The first element and the second element are both elements, respectively, but they are not to be considered the same element. The terminology used in the description of the disclosure provided herein is for the purpose of describing particular implementations and is not intended to limit the disclosure provided herein. As used in the description of the disclosure provided herein and appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. The term “and / or” as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items. The terms “includes,” “including,” “comprises,” and / or “comprising,” when used in this specification, specify a presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof. While the foregoing is directed to implementations of various techniques described herein, other and further implementations may be devised in accordance with the disclosure herein, which may be determined by the claims that follow. Although the subject matter has been 5 described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.
Claims
1. A method of configuring an electronic platform, the method comprising:monitoring, by a user monitoring entity, an activity of a user on the electronic platform;determining, by the user monitoring entity, a user type based on the activity of the user; andbased on a determination that the user type is malicious;sending, from the user monitoring entity to a platform configuring entity, an indication that the user type is malicious; andconfiguring, by the platform configuring entity, the electronic platform to inhibit access by the user to secure data, wherein a navigational structure of the electronic platform is preserved.
2. The method of claim 1, further comprising:determining, by the user monitoring entity, a machine learning model based on historical user activity; anddetermining a user type based on the machine learning model.
3. The method of claim 2, wherein the step of determining a user type comprises:determining bot-like behaviours;determining human-like behaviours; anddetermining a bot-likelihood score based on the bot-like behaviours and the human like-behaviours.
4. The method of any of claims 1 to 3 wherein determining that the user is malicious comprises determining that the user is a bot.
5. The method of claim 4, wherein the step of determining that the user is a bot is based on the bot-likelihood score.
6. The method of any of claims 4 or 5, further comprising determining a bot type based on the machine learning model.
7. The method of any previous claim, wherein the platform configuring entity and the user monitoring entity are comprised in a user network.
8. The method of any of previous claim, wherein the electronic platform is any of a webbased environment, an internet-of-things-based environment, or an operational technologybased environment.
9. The method of any previous claim, wherein the step of configuring the platform comprises at least one of:changing, removing and / or adding textual content;obscuring and / or replacing dynamic content;modifying an element of a document object model; or adding a document object model element.
10. The method of any preceding claim, wherein the step of configuring the electronic platform is based on a required level of protection.
11. The method of any preceding claim, wherein the step of configuring is based on a type and / or intent of the user.
12. The method of any preceding claim, wherein the platform configuring entity is disposed above a firewall of a user network and below a network edge.
13. The method of any previous claim, further comprising monitoring the activity of the user; andpredicting a future activity of the user based on the monitoring the activity of the user.
14. The method of any previous claim, wherein the activity of the user comprises cursor movement.
15. The method of any previous claims, wherein the step of configuring the electronic platform to inhibit access by the user to secure data further comprises restricting access by the user to secure data.
16. The method of any previous claim, wherein the user monitoring entity is comprised in a server network.
17. A computer program comprising instructions such that, when executed by a processor, cause a computer system comprising said processor to perform the method of any of claims 1 to 16.
18. A computer readable medium comprising instructions stored thereon such that, when executed by a processor, causes a computer system comprising said processor to execute the method of any of claims 1 to 16.
19. A system for configuring an electronic platform, the system configured to: monitor, by a user monitoring entity, an activity of a user on the electronic platform; determine, by the user monitoring entity, a user type based on the activity of the user;andbased on a determination that the user type is malicious;send, from the user monitoring entity to a platform configuring entity, an indication that the user type is malicious; andconfigure, by the platform configuring entity, the electronic platform to inhibit access by the user to secure data, wherein a navigational structure of the electronic platform is preserved.
20. The system of claim 18 configured to perform the method of any of claims 1 to 16.
Citation Information
Patent Citations
Malicious activity detection in memory of data processing unit
CN116595519A
Isolated container event monitoring
US10885189B2