Behavioral Biometric Authentication for RAT Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for electronic devices are inadequate in detecting and preventing Remote Access Trojan (RAT) attacks, which allow attackers to bypass hardware detection and steal sensitive data by mimicking user interactions.

Innovation Solution

The system employs Behavioral Biometrics and an Invisible Challenge-Response mechanism to differentiate between genuine users and attackers by analyzing mouse and keyboard interactions, using modules like user-specific feature extraction, perturbation generation, and stochastic cryptography to detect and prevent RAT attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (username/password) are used, then users can access electronic devices and services, but security is inadequate against RAT attacks that mimic user interactions

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that analyzes behavioral biometrics (mouse movements, keyboard typing patterns) as a mediator between traditional credentials and system access. This intermediary layer detects RAT attacks by comparing behavioral patterns against established user profiles, enhancing security without requiring complete system redesign

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces mechanical authentication systems (physical password entry) with behavioral biometric analysis. Instead of relying solely on what users know (passwords), the system analyzes how users interact with the device (mouse trajectories, typing rhythm), substituting mechanical credential verification with pattern recognition-based authentication

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If security measures are enhanced to detect RAT attacks, then detection accuracy improves, but false positives may increase affecting legitimate users

Engineering Contradiction:
Improveattack detection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent employs parameter changes by dynamically adjusting detection thresholds and analyzing multiple behavioral parameters simultaneously (mouse speed, acceleration, typing interval variability). The system adapts parameters based on user profiles and contextual factors, allowing precise differentiation between legitimate users and RAT attacks while minimizing false positives

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements preliminary action by establishing baseline behavioral profiles during legitimate user sessions before potential attacks occur. The system pre-characterizes normal user patterns, enabling it to quickly identify deviations that indicate RAT activity without immediately flagging legitimate users as threats

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If behavioral biometric analysis is implemented, then user differentiation capability improves, but processing requirements and system complexity increase

Engineering Contradiction:
Improveuser identity differentiationVSAvoidprocessing system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the most discriminative behavioral features from raw interaction data, such as mouse movement curvature, typing rhythm variations, and click patterns. By selecting and analyzing only these key extracted features rather than processing all raw input data, the system achieves high user differentiation capability with reduced computational complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10032010B2System, device, and method of visual login and stochastic cryptography
Publication Date: 2018.07.24 BIOCATCH
  • US10032010B2 patent drawing
  • US10032010B2 patent drawing
  • US10032010B2 patent drawing

AI summary

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting a possible attacker. A log-in process or a user-authentication process, is augmented or enriched by one or more incidental tasks, which force the user to perform additional on-screen interactions or input-unit interactions, which in turn enrich and augment the pool of user interactions from which the system extracts one or more user-specific features. The extracted user-specific features are used as part of the user authentication process, and are further used to differentiate among users.