Behavioral Biometric Authentication for RAT Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures for electronic devices are inadequate in detecting and preventing Remote Access Trojan (RAT) attacks, which allow attackers to bypass hardware detection and steal sensitive data by mimicking user interactions.
Innovation Solution
The system employs Behavioral Biometrics and an Invisible Challenge-Response mechanism to differentiate between genuine users and attackers by analyzing mouse and keyboard interactions, using modules like user-specific feature extraction, perturbation generation, and stochastic cryptography to detect and prevent RAT attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods (username/password) are used, then users can access electronic devices and services, but security is inadequate against RAT attacks that mimic user interactions
Solution Approach 1:
The patent introduces an intermediary authentication mechanism that analyzes behavioral biometrics (mouse movements, keyboard typing patterns) as a mediator between traditional credentials and system access. This intermediary layer detects RAT attacks by comparing behavioral patterns against established user profiles, enhancing security without requiring complete system redesign
Solution Approach 2:
The patent replaces mechanical authentication systems (physical password entry) with behavioral biometric analysis. Instead of relying solely on what users know (passwords), the system analyzes how users interact with the device (mouse trajectories, typing rhythm), substituting mechanical credential verification with pattern recognition-based authentication
2Measurement precision
If security measures are enhanced to detect RAT attacks, then detection accuracy improves, but false positives may increase affecting legitimate users
Solution Approach 1:
The patent employs parameter changes by dynamically adjusting detection thresholds and analyzing multiple behavioral parameters simultaneously (mouse speed, acceleration, typing interval variability). The system adapts parameters based on user profiles and contextual factors, allowing precise differentiation between legitimate users and RAT attacks while minimizing false positives
Solution Approach 2:
The patent implements preliminary action by establishing baseline behavioral profiles during legitimate user sessions before potential attacks occur. The system pre-characterizes normal user patterns, enabling it to quickly identify deviations that indicate RAT activity without immediately flagging legitimate users as threats
3Measurement precision
If behavioral biometric analysis is implemented, then user differentiation capability improves, but processing requirements and system complexity increase
Solution Approach 1:
The patent extracts only the most discriminative behavioral features from raw interaction data, such as mouse movement curvature, typing rhythm variations, and click patterns. By selecting and analyzing only these key extracted features rather than processing all raw input data, the system achieves high user differentiation capability with reduced computational complexity
Data Source
AI summary
Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting a possible attacker. A log-in process or a user-authentication process, is augmented or enriched by one or more incidental tasks, which force the user to perform additional on-screen interactions or input-unit interactions, which in turn enrich and augment the pool of user interactions from which the system extracts one or more user-specific features. The extracted user-specific features are used as part of the user authentication process, and are further used to differentiate among users.


