Behavioral Biometric Authentication for Remote Access Trojan Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for electronic devices are inadequate in detecting and preventing Remote Access Trojan (RAT) attacks, which allow attackers to bypass authentication and steal sensitive data by mimicking user interactions.

Innovation Solution

The system employs Behavioral Biometrics and an Invisible Challenge-Response mechanism to differentiate between genuine users and attackers by monitoring and analyzing user interactions, using modules like user-specific feature extraction, perturbation generation, and stochastic cryptography to detect and prevent RAT attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (username/password) are used, then users can access services, but attackers can bypass authentication by stealing credentials

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical authentication systems (username/password entry) with a behavioral biometric system that automatically analyzes user interactions. The system substitutes manual credential verification with automated monitoring of mouse movements, keyboard typing patterns, and click behaviors to authenticate users, thereby eliminating password theft vulnerabilities while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary behavioral analysis module that sits between the user interface and the authentication system. This intermediary continuously monitors and analyzes user behavior patterns, generating behavioral profiles that serve as the basis for authentication decisions, thus adding a layer of security without requiring users to change their interaction habits.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If behavioral biometrics are implemented to detect attackers, then detection accuracy improves, but processing complexity increases

Engineering Contradiction:
Improveuser differentiation accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the behavioral analysis into distinct modules: one module captures raw interaction data (mouse movements, keyboard strokes), another module extracts behavioral features, a third module compares patterns against stored profiles, and a final module makes authentication decisions. This segmentation allows each module to specialize in specific tasks, improving overall accuracy while making the complex system more manageable and maintainable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs self-calibration by automatically learning and adapting to legitimate user behavior patterns over time. The behavioral profiles are continuously updated based on observed interactions, allowing the system to maintain high detection accuracy without requiring manual reconfiguration or intervention, thus managing complexity through automated adaptation.

Inventive Principle:
Principle #25Self-service

3Reliability

If monitoring of user interactions is performed, then attacker detection capability improves, but computational resources increase

Engineering Contradiction:
ImproveRAT detection capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements partial monitoring by focusing computational resources on analyzing only the most discriminative behavioral features rather than capturing every interaction detail. The system selectively monitors key indicators such as mouse movement trajectories, typing rhythm, and click patterns while sampling interactions at optimized frequencies, thereby achieving effective attacker detection with reduced computational overhead compared to comprehensive continuous monitoring.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3019991B1Device, system, and method of differentiating among users of a computerized service
Publication Date: 2019.02.20 BIOCATCH
  • EP3019991B1 patent drawingFigure 1
  • EP3019991B1 patent drawingFigure 2A
  • EP3019991B1 patent drawingFigure 2B

AI summary

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting a possible attacker. The methods include monitoring of user-side input-unit interactions, in general and in response to an interference introduced to user- interface elements. The monitored interactions are used for detecting an attacker that utilizes a remote access channel; for detecting a malicious automatic script, as well as malicious code injection; to identify a particular hardware assembly; to perform user segmentation or user characterization; to enable a visual login process with implicit two-factor authentication; to enable stochastic cryptography; and to detect that multiple users are utilizing the same subscription account.