Bot Detection via Input Gesture Analysis and Anomaly Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems fail to effectively distinguish between human users and automated cyber-attacks or malware that simulate human interactions, leading to false positives and negatives in detecting fraudulent activities on electronic devices.

Innovation Solution

A system that monitors user interactions on electronic devices, detects abnormalities in input-unit gestures and discrepancies between reported and actual input, and injects on-screen anomalies to differentiate between human and automated control, using contextual analysis and machine learning to classify user behavior and generate a fraud risk score.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If the system monitors all user interactions to detect fraud, then detection accuracy improves, but system complexity and processing overhead increase

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments fraud detection into multiple independent analysis modules: input gesture analysis, output verification, temporal pattern analysis, and anomaly detection. Each module processes specific aspects of user interaction separately, improving detection accuracy while maintaining manageable system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces intermediary verification layers between input detection and fraud determination. These intermediaries include buffer zones for temporal analysis, verification queues for cross-checking gestures, and intermediate scoring mechanisms that aggregate evidence before final fraud classification, reducing processing overhead while maintaining accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system uses multiple verification methods to distinguish human from automated control, then reliability improves, but processing time increases

Engineering Contradiction:
Improvehuman vs automated detection reliabilityVSAvoidverification processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of input gestures immediately upon reception, pre-calculating temporal patterns, gesture complexity metrics, and preliminary anomaly scores. This preliminary processing prepares data for faster subsequent verification stages, maintaining high reliability while reducing overall processing time through advance preparation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements periodic verification intervals where full multi-method verification is performed at scheduled checkpoints rather than continuously. Between checkpoints, lighter-weight monitoring occurs, allowing the system to maintain reliability through periodic thorough verification while reducing average processing time through intermittent intensive analysis.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9626677B2Identification of computerized bots, and identification of automated cyber-attack modules
Publication Date: 2017.04.18 BIOCATCH
  • US9626677B2 patent drawing
  • US9626677B2 patent drawing
  • US9626677B2 patent drawing

AI summary

Devices, systems, and methods of detecting whether an electronic device or computerized device or computer, is being controlled by a legitimate human user, or by an automated cyber-attack unit or malware or automatic script. The system monitors interactions performed via one or more input units of the electronic device. The system searches for abnormal input-user interactions; or for an abnormal discrepancy between: the input-unit gestures that were actually registered by the input unit, and the content that the electronic device reports as allegedly entered via such input units. A discrepancy or abnormality indicates that more-possibly a malware or automated script is controlling the electronic device, rather than a legitimate human user. Optionally, an input-output aberration or interference is injected, in order to check for manual corrective actions that only a human user, and not an automated script, is able to perform.