Behavioral Authentication System for Fraud Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for electronic devices and systems are inadequate in distinguishing between legitimate and fraudulent user activities, particularly in online transactions, as they fail to effectively analyze cognitive choices and behavioral patterns that may indicate malicious intent.

Innovation Solution

A system that tracks and analyzes user interactions, such as data entry methods and patterns, to differentiate between legitimate and fraudulent users by employing a 'silent key-logger' JavaScript code that monitors keystrokes and mouse interactions, and a fraud detection module that estimates a threat level or fraud score based on these analyses, triggering mitigation measures when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are used for authentication, then implementation is simple, but they fail to distinguish between legitimate and fraudulent user activities

Engineering Contradiction:
Improveauthentication accuracyVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system is segmented into multiple independent modules: a behavioral analysis module that captures user interactions, a pattern recognition module that analyzes the captured behavior, and a fraud detection module that compares patterns against known fraudulent behaviors. This segmentation allows the system to achieve high authentication accuracy through comprehensive behavioral analysis while maintaining manageable complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary behavioral analysis layer between the user and the authentication system. This intermediary captures and analyzes user behavior patterns (keystroke dynamics, mouse movements, navigation patterns) without disrupting the normal authentication flow, thereby improving reliability by adding behavioral verification while keeping the system complexity manageable through non-intrusive monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If behavioral analysis is implemented to detect fraud, then authentication accuracy improves, but processing time increases

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary behavioral capture during normal user interactions with the system, before authentication decisions are made. By continuously capturing keystroke patterns, mouse movements, and navigation behaviors in the background during form filling and data entry, the system accumulates behavioral data in advance, allowing for rapid fraud detection without adding significant processing time to the authentication flow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The behavioral analysis operates continuously in the background during user interactions, rather than interrupting the authentication process to collect data. The system maintains continuous monitoring of user behaviors (typing patterns, cursor movements, form navigation) throughout the session, enabling real-time fraud detection while keeping the authentication process flowing smoothly without temporal interruptions.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20240147234A1Method, Device, and System of Differentiating Between a Cyber-Attacker and a Legitimate User
Publication Date: 2024.05.02 BIOCATCH
  • US20240147234A1 patent drawing
  • US20240147234A1 patent drawing
  • US20240147234A1 patent drawing

AI summary

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting a cyber-attacker. A user utilizes a desktop computer, a laptop computer, a smartphone, a tablet, or other electronic device, to interact with a banking website or application, a retailer website or application, or other computerized service. Input-unit interactions are monitored, logged, and analyzed. Based on several types of analysis of the input-unit interactions, a score is generated to reflect fraud-relatedness or attack-relatedness of the input-unit interactions. Based on the score, the system estimates or determines whether the user is an attacker, and initiates attack-mitigation operations or fraud-mitigation operations.