Behavioral Interference for Human-Bot Differentiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for electronic devices and systems are inadequate in distinguishing between human users and automated scripts or bots, particularly in preventing Application DDoS attacks and ensuring authentic user identity, as existing methods often fail to differentiate effectively and can be overwhelmed by fraudulent login attempts.

Innovation Solution

The introduction of a system that generates and analyzes user interactions by injecting generic interferences, such as irregularities in the user interface, to differentiate between human users and automated scripts, using binary-value parameters to determine unique user responses and adapt interference strategies based on population uniqueness, thereby preventing fraudulent access and mitigating DDoS attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional security measures are used for authentication, then the system is easy to operate, but it cannot effectively distinguish between human users and automated scripts

Engineering Contradiction:
Improveuser identification accuracyVSAvoidsecurity system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system automatically analyzes user interactions and generates fraud scores without requiring manual intervention or complex configuration. The fraud detection module self-adjusts by learning from interaction patterns, eliminating the need for manual rule-setting while maintaining high accuracy in distinguishing human users from bots.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces traditional mechanical authentication methods (passwords, CAPTCHAs) with an automated analysis system that processes user interactions through software-based behavioral analysis. This substitution enables precise identification of automated scripts through pattern recognition algorithms rather than manual security checks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual security verification methods are implemented, then fraud detection accuracy improves, but the system becomes vulnerable to Application DDoS attacks

Engineering Contradiction:
Improvefraud detection reliabilityVSAvoidsystem throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary analysis of user interactions during the login process itself, evaluating behavioral patterns before granting access. By analyzing interaction sequences, mouse movements, and typing patterns during authentication, the system identifies fraudulent attempts in real-time without requiring additional verification steps that would reduce system throughput.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The fraud detection module continuously monitors user interactions and provides real-time feedback through fraud scoring. The system adjusts its detection thresholds based on learned patterns from multiple users, improving reliability while maintaining high throughput by automatically adapting to new fraud techniques without manual intervention.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If generic interferences are injected into user interface, then differentiation between human and automated users improves, but user experience may be degraded

Engineering Contradiction:
Improveuser behavior analysis accuracyVSAvoiduser interface usability
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system applies generic interferences selectively rather than to all users. By analyzing interaction patterns and applying interference only when fraud risk is detected or during initial authentication, the system maintains high measurement precision while minimizing impact on user experience for legitimate users.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system dynamically adjusts interference parameters based on user behavior analysis. By modifying the type, frequency, and intensity of interferences according to detected fraud patterns, the system achieves accurate differentiation between human and automated users while adapting the user interface to maintain usability for legitimate users.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9712558B2Method, system, and device of protecting a computerized service
Publication Date: 2017.07.18 BIOCATCH
  • US9712558B2 patent drawing
  • US9712558B2 patent drawing
  • US9712558B2 patent drawing

AI summary

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting a cyber-attacker. An end-user device (a desktop computer, a laptop computer, a smartphone, a tablet, or the like) interacts and communicates with a server of a computerized server (a banking website, an electronic commerce website, or the like). The interactions are monitored, tracked and logged. User Interface (UI) interferences or irregularities are intentionally introduced to the communication session; and the system tracks the response or the reaction of the end-user to such communication interferences. The system determines whether the user is a legitimate human user, or a cyber-attacker or automated script posing as the legitimate human user. The system further detects click-fraud, and prevents or mitigates Application Distributed Denial-of-Service attacks.