Behavioral Biometrics for Remote Access Trojan Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures for electronic devices are inadequate in detecting and preventing Remote Access Trojan (RAT) attacks, which allow attackers to bypass authentication and access sensitive data, using techniques like Silent VNC and Poison Ivy, with existing methods failing to differentiate between genuine users and remote attackers effectively.
Innovation Solution
The system employs Behavioral Biometrics, monitoring user interactions through mouse and keyboard interfaces, using Invisible Challenge-Response mechanisms and a RAT catcher module to detect and prevent RAT attacks by analyzing user-specific features such as mouse movement patterns and introducing perturbations to distinguish between local users and remote attackers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods (username/password) are used, then users can access electronic devices and services, but security is inadequate against RAT attacks that bypass authentication
Solution Approach 1:
The patent replaces traditional mechanical authentication systems (username/password entry) with a behavioral biometric system that monitors and analyzes user interaction patterns through software-based tracking of mouse movements, keyboard typing patterns, and touchscreen gestures. This substitution enables detection of RAT attacks by comparing behavioral signatures against established user profiles, achieving enhanced security without requiring hardware modifications.
Solution Approach 2:
The patent introduces an intermediary behavioral analysis module that sits between the user interface and the authentication system. This module continuously monitors user interactions, extracts behavioral features, and compares them against stored profiles before granting or denying access. The intermediary layer enables sophisticated security checks without disrupting the user experience or requiring changes to existing authentication infrastructure.
2Measurement precision
If behavioral biometrics are implemented to detect RAT attacks, then detection accuracy reaches 100% with zero false positives, but the system complexity increases due to monitoring and analysis requirements
Solution Approach 1:
The patent extracts specific behavioral features from continuous user interaction streams, focusing only on the most discriminative characteristics such as mouse movement velocity, acceleration patterns, keyboard typing rhythm, and touchscreen pressure dynamics. By extracting and analyzing only these key features rather than processing all raw interaction data, the system achieves high detection accuracy with reduced computational overhead and simplified system architecture.
Solution Approach 2:
The patent transforms raw behavioral data into standardized parameters with specific statistical properties, such as converting mouse movement trajectories into velocity and acceleration vectors, or transforming keyboard timing data into inter-key-interval distributions. These parameter transformations normalize the data and highlight discriminative features, enabling accurate detection with simpler comparison logic and reducing false positives.
3Reliability
If user interactions are monitored through input units, then genuine users and remote attackers can be differentiated, but the system requires additional processing of interaction data
Solution Approach 1:
The patent performs preliminary processing of behavioral data during normal user interactions, continuously updating statistical profiles and baseline characteristics without interrupting user workflow. Behavioral features are extracted and stored in optimized formats during routine operations, so that during authentication or anomaly detection events, the system can quickly compare against pre-computed profiles rather than analyzing raw data from scratch, significantly reducing processing time.
Solution Approach 2:
The patent implements a multi-stage filtering approach where obvious patterns are quickly identified and processed through simplified pathways. For example, if behavioral parameters fall within expected ranges, the system skips detailed analysis and grants rapid approval. Only when parameters deviate from norms does the system engage in comprehensive analysis, thereby reducing average processing time while maintaining high detection accuracy for suspicious activities.
Data Source
AI summary
Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting a possible attacker. The methods include monitoring of user-side input-unit interactions, in general and in response to an interference introduced to user-interface elements. The monitored interactions are used for detecting an attacker that utilizes a remote access channel; for detecting a malicious automatic script, as well as malicious code injection; to identify a particular hardware assembly; to perform user segmentation or user characterization; to enable a visual login process with implicit two-factor authentication; to enable stochastic cryptography; and to detect that multiple users are utilizing the same subscription account.


