Application Trust Overlay Detection for Interface Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to effectively protect against interface overlay attacks by malicious applications without affecting the legitimate application's window or process, particularly in cases of partial overlay or data theft during online transactions.
Innovation Solution
A method and system that monitor a first application for interface overlay by a second application, collect information on the second application's danger status, and determine its category of trust to decide whether to allow or prohibit overlay, using a hardware processor to detect and analyze interface elements and system logs for determining the trustworthiness of the second application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing antivirus systems monitor interface overlay to protect against malicious applications, then security protection is improved, but false positives occur affecting legitimate applications (closing windows, changing sizes)
Solution Approach 1:
The system performs preliminary analysis of the overlaying application's danger status before blocking it. By collecting information about the application's characteristics, behavior patterns, and reputation in advance, the system can distinguish malicious overlays from legitimate ones, preventing false positives that would otherwise close or disrupt legitimate application windows
Solution Approach 2:
The patent introduces an intermediary trust determination mechanism between the monitoring system and the blocking action. Instead of directly blocking all detected overlays, the system uses a trust category determination as an intermediary step that analyzes the overlaying application's characteristics and behavior to make an informed decision, thereby protecting legitimate applications while blocking malicious ones
2Reliability
If the system blocks all interface overlay to prevent data theft, then security is improved, but legitimate overlay functionality is lost
Solution Approach 1:
The system applies different quality standards to different overlaying applications based on their trust category. Trusted applications are allowed to perform overlay operations with full functionality, while untrusted applications are blocked. This local differentiation maintains data protection for critical operations while preserving legitimate overlay functionality where appropriate
Solution Approach 2:
The patent changes the parameter of trust category (safe, unknown, dangerous) based on analyzed characteristics of the overlaying application. This parameter change enables dynamic adjustment of overlay permissions, allowing the system to adaptively grant or restrict overlay functionality based on the specific application's risk profile rather than applying a uniform block
3Measurement precision
If the system analyzes application characteristics to determine trust category, then accuracy of malicious application detection is improved, but processing time increases
Solution Approach 1:
The system performs partial analysis by focusing on key characteristics and behavior patterns that are most indicative of malicious activity. Rather than analyzing every possible attribute of an overlaying application, the system concentrates on critical parameters such as danger status, behavior patterns, and reputation data, achieving high detection accuracy with reduced processing time
Data Source
AI summary
Disclose dare systems and method for determining category of trust of software applications. An example method includes monitoring a first application to detect an overlay of at least one interface element of the first application by at least one interface element of a second application; collecting information about the second application, wherein the information includes at least a danger status of the second application, wherein the danger status determines a danger caused by the second application to the first application; determining a category of trust of the second application based on an analysis of the collected information; and determining, based on the category of trust of the second application, whether to allow or prohibit overlay of the at least one interface element of the first application by the at least one interface element of the second application.


