Behaviometric Authentication for Bot Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack a reliable mechanism to differentiate between human and bot access in financial and other high-value systems, leading to security risks due to the inability to verify the entity seeking access, especially with screen-scraping methods where credentials are easily compromised and misused.

Innovation Solution

Implement behaviometric authentication by collecting and processing user data from devices, including key presses, mouse movements, and other behavioral characteristics to identify and differentiate between human and bot operators, ensuring only authorized bots gain access to sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If screen-scraping methods are used to access account information, then access capability and automation are improved, but security and control over credentials deteriorate

Engineering Contradiction:
Improvebot access capabilityVSAvoidcredential security
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent replaces traditional mechanical credential verification (passwords, tokens) with a behavioral biometric system that captures and analyzes user interaction patterns. Sensors detect behavioral characteristics during device operation, creating a continuous authentication mechanism that substitutes static credentials with dynamic behavioral verification, thereby maintaining automation while improving security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a behavioral authentication intermediary layer between the bot and the account information. This intermediary captures behavioral data from sensors, processes it through machine learning models, and provides continuous verification without blocking automated access. The intermediary acts as a mediator that enables bot functionality while preventing credential misuse through behavioral analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If behavioral biometric authentication is implemented, then security and bot differentiation are improved, but system complexity and data processing requirements increase

Engineering Contradiction:
Improveaccess verification accuracyVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal behavioral authentication framework that works across multiple devices, applications, and user scenarios. The system captures various behavioral parameters (typing patterns, swipe gestures, device handling) and processes them through a unified machine learning model, enabling the same authentication mechanism to serve diverse access control needs without requiring separate systems for each application

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The behavioral biometric system operates autonomously by continuously capturing behavioral data from sensors during normal device usage. The machine learning models automatically process this data in real-time, making authentication decisions without requiring manual intervention or additional user actions. The system serves itself by leveraging existing device sensors and processing capabilities to provide continuous verification

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10650163B2Bot detection and access grant or denial based on bot identified
Publication Date: 2020.05.12 BEHAVIOSEC INC
  • US10650163B2 patent drawing
  • US10650163B2 patent drawing
  • US10650163B2 patent drawing

AI summary

A user accessing data from a server in an authenticated session is determined to be human, an authorized bot, or a non-authorized bot based on receipt of behaviometric information from the user's interactions and responses to and with the server. The user is then denied or granted continued access to receive data, such as financial data, after it is determined if the user is authorized to do so by way of comparing the behaviometric data to known prior behaviometric data for particular humans and bots in embodiments of the disclosed technology.