Behavioral Biometric Authentication for Remote Access Trojan Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for electronic devices are inadequate in detecting and preventing Remote Access Trojan (RAT) attacks, which allow attackers to bypass authentication and access sensitive data, using techniques like Poison Ivy and Silent VNC, with existing methods failing to differentiate between genuine users and remote attackers effectively.

Innovation Solution

The system employs Behavioral Biometrics and Invisible Challenge-Response mechanisms to analyze user interactions through mouse, keyboard, and touch interfaces, using modules like user-specific feature extraction, perturbation generation, and stochastic cryptography to detect and prevent RAT attacks by differentiating between local users and remote attackers based on interaction patterns and response times.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (username and password) are used, then users can access their accounts, but attackers can bypass authentication using Remote Access Trojan attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidRAT attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces traditional mechanical authentication (username/password entry) with behavioral biometric authentication. The system captures user interactions with the device (mouse movements, keyboard typing patterns, touch gestures) and analyzes these behavioral patterns to verify user identity, making authentication resistant to RAT attacks that cannot replicate human behavioral characteristics.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary behavioral analysis system between the user and the account access. This intermediary layer captures and analyzes behavioral data from user interactions, creating a mediation layer that verifies whether the person accessing the account is the legitimate user by comparing behavioral patterns, thus preventing unauthorized access even if credentials are compromised.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If security measures are increased to detect RAT attacks, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improveattacker detection accuracyVSAvoidsecurity system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically capturing behavioral data during normal user interactions without requiring separate detection mechanisms. The behavioral biometric data is collected passively as users naturally interact with the device, and the system automatically analyzes these patterns to detect attackers, eliminating the need for complex active detection systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The behavioral analysis system serves multiple functions simultaneously: it authenticates users, detects attackers, and continuously monitors for suspicious activities. By using the same behavioral data collection and analysis infrastructure for multiple security purposes, the system achieves high detection accuracy without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If behavioral biometrics are used to differentiate users, then user differentiation accuracy improves, but data processing requirements increase

Engineering Contradiction:
Improveuser differentiation accuracyVSAvoidbehavioral data volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts only the essential behavioral features from raw interaction data, such as mouse movement velocity, acceleration patterns, keyboard typing rhythms, and touch gesture characteristics. By extracting and analyzing only these key differentiating features rather than processing all raw behavioral data, the system achieves high user differentiation accuracy while minimizing data processing requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10055560B2Device, method, and system of detecting multiple users accessing the same account
Publication Date: 2018.08.21 BIOCATCH
  • US10055560B2 patent drawing
  • US10055560B2 patent drawing
  • US10055560B2 patent drawing

AI summary

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting a possible attacker. The methods include monitoring of user-side input-unit interactions, in general and in response to an interference introduced to user-interface elements. The monitored interactions are used for detecting an attacker that utilizes a remote access channel; for detecting a malicious automatic script, as well as malicious code injection; to identify a particular hardware assembly; to perform user segmentation or user characterization; to enable a visual login process with implicit two-factor authentication; to enable stochastic cryptography; and to detect that multiple users are utilizing the same subscription account.