Bot Detection via Input Gesture Discrepancy Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems fail to effectively distinguish between human users and automated cyber-attacks or malware that simulate human interactions, leading to false positives and negatives in detecting fraudulent activities on electronic devices.

Innovation Solution

A system that monitors user interactions on electronic devices, using passive and active detection methods to identify discrepancies in input-unit gestures and content, injects anomalies to elicit corrective actions from human users, and employs contextual mapping to assess risk levels of UI elements, thereby differentiating between legitimate human users and automated scripts or malware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated detection systems are used to identify fraudulent activities, then detection speed and productivity are improved, but false positive and false negative rates increase

Engineering Contradiction:
Improvedetection speedVSAvoidfalse positive and false negative rates
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system continuously monitors user interactions and uses the results to refine its detection algorithms. By implementing feedback loops where detection outcomes are fed back into the system for learning and adjustment, the system improves both detection speed and accuracy over time, reducing false positives and negatives while maintaining high productivity

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system dynamically adjusts detection parameters such as sensitivity thresholds, monitoring intervals, and anomaly criteria based on learned patterns from actual user behavior. This allows the system to optimize its detection parameters for different contexts and user types, improving reliability without sacrificing detection speed

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If complex monitoring and analysis systems are implemented to accurately distinguish human users from automated scripts, then detection precision is improved, but device complexity increases

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The detection system is divided into multiple independent modules: input monitoring module, interaction analysis module, pattern recognition module, and decision module. Each module handles a specific aspect of the detection process, making the overall complex system manageable and maintainable while achieving high detection precision through specialized function distribution

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces intermediary components such as behavior profiles, interaction models, and anomaly scores that mediate between raw input data and final detection decisions. These intermediaries simplify the complexity by providing structured representations of complex phenomena, making the system more manageable while maintaining high detection precision

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple detection methods are employed to reduce false positives and negatives, then reliability is improved, but device complexity and ease of operation worsen

Engineering Contradiction:
Improvefalse positive and false negative ratesVSAvoidnumber of detection methods
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges multiple detection methods into a unified detection framework that processes various input types (keystrokes, mouse movements, touchscreen gestures, camera data) through a common analysis pipeline. This integration reduces the apparent complexity by providing a single cohesive system rather than separate independent methods, while maintaining high reliability through the combined strength of multiple detection approaches

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9848009B2Identification of computerized bots and automated cyber-attack modules
Publication Date: 2017.12.19 BIOCATCH
  • US9848009B2 patent drawing
  • US9848009B2 patent drawing
  • US9848009B2 patent drawing

AI summary

Devices, systems, and methods of detecting whether an electronic device or computerized device or computer, is being controlled by a legitimate human user, or by an automated cyber-attack unit or malware or automatic script. The system monitors interactions performed via one or more input units of the electronic device. The system searches for abnormal input-user interactions; or for an abnormal discrepancy between: the input-unit gestures that were actually registered by the input unit, and the content that the electronic device reports as allegedly entered via such input units. A discrepancy or abnormality indicates that more-possibly, or necessarily or certainly, a malware or automated script is controlling the electronic device, rather than a legitimate human user. Optionally, an input-output aberration or interference is injected, in order to check for manual corrective actions that only a human user, and not an automated script, is able to perform.