Bot Detection via Input Gesture Discrepancy Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems fail to effectively distinguish between human users and automated cyber-attacks or malware that simulate human interactions, leading to false positives and negatives in detecting fraudulent activities on electronic devices.
Innovation Solution
A system that monitors user interactions on electronic devices, using passive and active detection methods to identify discrepancies in input-unit gestures and content, injects anomalies to elicit corrective actions from human users, and employs contextual mapping to assess risk levels of UI elements, thereby differentiating between legitimate human users and automated scripts or malware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated detection systems are used to identify fraudulent activities, then detection speed and productivity are improved, but false positive and false negative rates increase
Solution Approach 1:
The system continuously monitors user interactions and uses the results to refine its detection algorithms. By implementing feedback loops where detection outcomes are fed back into the system for learning and adjustment, the system improves both detection speed and accuracy over time, reducing false positives and negatives while maintaining high productivity
Solution Approach 2:
The system dynamically adjusts detection parameters such as sensitivity thresholds, monitoring intervals, and anomaly criteria based on learned patterns from actual user behavior. This allows the system to optimize its detection parameters for different contexts and user types, improving reliability without sacrificing detection speed
2Measurement precision
If complex monitoring and analysis systems are implemented to accurately distinguish human users from automated scripts, then detection precision is improved, but device complexity increases
Solution Approach 1:
The detection system is divided into multiple independent modules: input monitoring module, interaction analysis module, pattern recognition module, and decision module. Each module handles a specific aspect of the detection process, making the overall complex system manageable and maintainable while achieving high detection precision through specialized function distribution
Solution Approach 2:
The system introduces intermediary components such as behavior profiles, interaction models, and anomaly scores that mediate between raw input data and final detection decisions. These intermediaries simplify the complexity by providing structured representations of complex phenomena, making the system more manageable while maintaining high detection precision
3Reliability
If multiple detection methods are employed to reduce false positives and negatives, then reliability is improved, but device complexity and ease of operation worsen
Solution Approach 1:
The system merges multiple detection methods into a unified detection framework that processes various input types (keystrokes, mouse movements, touchscreen gestures, camera data) through a common analysis pipeline. This integration reduces the apparent complexity by providing a single cohesive system rather than separate independent methods, while maintaining high reliability through the combined strength of multiple detection approaches
Data Source
AI summary
Devices, systems, and methods of detecting whether an electronic device or computerized device or computer, is being controlled by a legitimate human user, or by an automated cyber-attack unit or malware or automatic script. The system monitors interactions performed via one or more input units of the electronic device. The system searches for abnormal input-user interactions; or for an abnormal discrepancy between: the input-unit gestures that were actually registered by the input unit, and the content that the electronic device reports as allegedly entered via such input units. A discrepancy or abnormality indicates that more-possibly, or necessarily or certainly, a malware or automated script is controlling the electronic device, rather than a legitimate human user. Optionally, an input-output aberration or interference is injected, in order to check for manual corrective actions that only a human user, and not an automated script, is able to perform.


