Application Trust Overlay Detection for Interface Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively protect against interface overlay attacks by malicious applications without affecting the legitimate application's window or process, particularly in cases of partial overlay or data theft during online transactions.

Innovation Solution

A method and system that monitor a first application for interface overlay by a second application, collect information on the second application's danger status, and determine its category of trust to decide whether to allow or prohibit overlay, using a hardware processor to detect and analyze interface elements and system logs for determining the trustworthiness of the second application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing antivirus systems monitor interface overlay to protect against malicious applications, then security protection is improved, but false positives occur affecting legitimate applications (closing windows, changing sizes)

Engineering Contradiction:
Improvesecurity protectionVSAvoidlegitimate application functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary analysis of the overlaying application's danger status before blocking it. By collecting information about the application's characteristics, behavior patterns, and reputation in advance, the system can distinguish malicious overlays from legitimate ones, preventing false positives that would otherwise close or disrupt legitimate application windows

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary trust determination mechanism between the monitoring system and the blocking action. Instead of directly blocking all detected overlays, the system uses a trust category determination as an intermediary step that analyzes the overlaying application's characteristics and behavior to make an informed decision, thereby protecting legitimate applications while blocking malicious ones

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system blocks all interface overlay to prevent data theft, then security is improved, but legitimate overlay functionality is lost

Engineering Contradiction:
Improvedata protectionVSAvoidoverlay functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system applies different quality standards to different overlaying applications based on their trust category. Trusted applications are allowed to perform overlay operations with full functionality, while untrusted applications are blocked. This local differentiation maintains data protection for critical operations while preserving legitimate overlay functionality where appropriate

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of trust category (safe, unknown, dangerous) based on analyzed characteristics of the overlaying application. This parameter change enables dynamic adjustment of overlay permissions, allowing the system to adaptively grant or restrict overlay functionality based on the specific application's risk profile rather than applying a uniform block

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If the system analyzes application characteristics to determine trust category, then accuracy of malicious application detection is improved, but processing time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs partial analysis by focusing on key characteristics and behavior patterns that are most indicative of malicious activity. Rather than analyzing every possible attribute of an overlaying application, the system concentrates on critical parameters such as danger status, behavior patterns, and reputation data, achieving high detection accuracy with reduced processing time

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9282112B2System and method for determining category of trust of applications performing interface overlay
Publication Date: 2016.03.08 AO KASPERSKY LAB
  • US9282112B2 patent drawing
  • US9282112B2 patent drawing
  • US9282112B2 patent drawing

AI summary

Disclose dare systems and method for determining category of trust of software applications. An example method includes monitoring a first application to detect an overlay of at least one interface element of the first application by at least one interface element of a second application; collecting information about the second application, wherein the information includes at least a danger status of the second application, wherein the danger status determines a danger caused by the second application to the first application; determining a category of trust of the second application based on an analysis of the collected information; and determining, based on the category of trust of the second application, whether to allow or prohibit overlay of the at least one interface element of the first application by the at least one interface element of the second application.