Behavioral Analysis for Fake User Interaction Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions for mobile and wireless devices are inadequate in detecting and preventing non-benign software applications that degrade performance and security, as they often rely on resource-intensive scanning engines and fail to address complex interactions contributing to device degradation.

Innovation Solution

A behavior-based security system that analyzes raw data from user input devices and operating systems to differentiate between authentic and fake user interaction events, using machine learning techniques and classifier models to classify software application activities as benign or non-benign, thereby preventing performance degradation and security breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If resource-intensive scanning engines are used to detect malware, then detection capability is improved, but device performance and resource consumption worsen

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddevice resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent replaces traditional mechanical scanning engines with a behavior-based detection system that analyzes user interaction patterns. Instead of using resource-intensive signature matching and scanning, the system substitutes behavioral analysis that compares actual user interactions against learned normal patterns, achieving malware detection with significantly lower resource consumption.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the detection parameters from static signature matching to dynamic behavioral parameters. By monitoring interaction sequences, timing patterns, and user behavior metrics, the system detects malware based on behavioral anomalies rather than requiring intensive scanning operations, thereby reducing resource usage while maintaining detection reliability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional security scanning is performed, then malware detection is improved, but device performance degradation worsens

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoiddevice performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent substitutes traditional mechanical scanning processes with behavioral analysis mechanisms. The system continuously monitors user interaction patterns and compares them against established baselines, enabling security detection without the performance overhead of traditional scanning engines that block or slow down device operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs security detection continuously in the background by analyzing user interaction streams in real-time. Instead of periodic scanning that interrupts device performance, the behavioral analysis operates continuously with minimal impact, maintaining security monitoring while preserving device productivity and user experience.

Inventive Principle:
Principle #20Continuity of useful action

3Measurement precision

If comprehensive user interaction analysis is performed, then fake interaction detection is improved, but processing complexity worsens

Engineering Contradiction:
Improvefake interaction detection accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the user interaction analysis into distinct components: interaction capture, pattern extraction, baseline comparison, and anomaly detection. By dividing the comprehensive analysis into modular segments, the system achieves high detection precision while managing processing complexity through organized, manageable analysis stages rather than monolithic complex processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial analysis by focusing on key interaction parameters and patterns most indicative of fake interactions. Rather than analyzing every aspect of user behavior in equal detail, the system identifies and monitors critical behavioral markers, achieving effective fake interaction detection without the excessive complexity of comprehensive全方位 analysis.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9875357B2Methods and systems for detecting fake user interactions with a mobile device for improved malware protection
Publication Date: 2018.01.23 QUALCOMM INC
  • US9875357B2 patent drawing
  • US9875357B2 patent drawing
  • US9875357B2 patent drawing

AI summary

A computing device processor may be configured with processor-executable instructions to implement methods of detecting and responding to fake user interaction (UI) events. The processor may determine whether a user interaction event is a fake user interaction event by analyzing raw data generated by one or more hardware drivers in conjunction with user interaction event information generated or received by the high-level operating system. In addition, the processor may be configured with processor-executable instructions to implement methods of using behavioral analysis and machine learning techniques to identify, prevent, correct, or otherwise respond to malicious or performance-degrading behaviors of the computing device based on whether a detected user interaction event is an authentic or fake user interaction event.