Behavioral Biometrics for Remote Access Trojan Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for electronic devices are inadequate in detecting and preventing Remote Access Trojan (RAT) attacks, which allow attackers to bypass authentication and access sensitive data, using techniques like Silent VNC and Poison Ivy, with existing methods failing to differentiate between genuine users and remote attackers effectively.

Innovation Solution

The system employs Behavioral Biometrics, monitoring user interactions through mouse and keyboard interfaces, using Invisible Challenge-Response mechanisms and a RAT catcher module to detect and prevent RAT attacks by analyzing user-specific features such as mouse movement patterns and introducing perturbations to distinguish between local users and remote attackers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (username/password) are used, then users can access electronic devices and services, but security is inadequate against RAT attacks that bypass authentication

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical authentication systems (username/password entry) with a behavioral biometric system that monitors and analyzes user interaction patterns through software-based tracking of mouse movements, keyboard typing patterns, and touchscreen gestures. This substitution enables detection of RAT attacks by comparing behavioral signatures against established user profiles, achieving enhanced security without requiring hardware modifications.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary behavioral analysis module that sits between the user interface and the authentication system. This module continuously monitors user interactions, extracts behavioral features, and compares them against stored profiles before granting or denying access. The intermediary layer enables sophisticated security checks without disrupting the user experience or requiring changes to existing authentication infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If behavioral biometrics are implemented to detect RAT attacks, then detection accuracy reaches 100% with zero false positives, but the system complexity increases due to monitoring and analysis requirements

Engineering Contradiction:
Improvedetection accuracyVSAvoidmonitoring system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts specific behavioral features from continuous user interaction streams, focusing only on the most discriminative characteristics such as mouse movement velocity, acceleration patterns, keyboard typing rhythm, and touchscreen pressure dynamics. By extracting and analyzing only these key features rather than processing all raw interaction data, the system achieves high detection accuracy with reduced computational overhead and simplified system architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms raw behavioral data into standardized parameters with specific statistical properties, such as converting mouse movement trajectories into velocity and acceleration vectors, or transforming keyboard timing data into inter-key-interval distributions. These parameter transformations normalize the data and highlight discriminative features, enabling accurate detection with simpler comparison logic and reducing false positives.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If user interactions are monitored through input units, then genuine users and remote attackers can be differentiated, but the system requires additional processing of interaction data

Engineering Contradiction:
Improveuser differentiationVSAvoiddata processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary processing of behavioral data during normal user interactions, continuously updating statistical profiles and baseline characteristics without interrupting user workflow. Behavioral features are extracted and stored in optimized formats during routine operations, so that during authentication or anomaly detection events, the system can quickly compare against pre-computed profiles rather than analyzing raw data from scratch, significantly reducing processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a multi-stage filtering approach where obvious patterns are quickly identified and processed through simplified pathways. For example, if behavioral parameters fall within expected ranges, the system skips detailed analysis and grants rapid approval. Only when parameters deviate from norms does the system engage in comprehensive analysis, thereby reducing average processing time while maintaining high detection accuracy for suspicious activities.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS9621567B2Device, system, and method of detecting hardware components
Publication Date: 2017.04.11 BIOCATCH
  • US9621567B2 patent drawing
  • US9621567B2 patent drawing
  • US9621567B2 patent drawing

AI summary

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting a possible attacker. The methods include monitoring of user-side input-unit interactions, in general and in response to an interference introduced to user-interface elements. The monitored interactions are used for detecting an attacker that utilizes a remote access channel; for detecting a malicious automatic script, as well as malicious code injection; to identify a particular hardware assembly; to perform user segmentation or user characterization; to enable a visual login process with implicit two-factor authentication; to enable stochastic cryptography; and to detect that multiple users are utilizing the same subscription account.