Browser Mode Detection Using Collector Timing Data for Biometrics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional authentication methods relying on passcodes are ineffective against malware and privacy breaches, and behavioral biometrics can be inhibited by browser privacy modes or data aggregators, leading to false positives and compromised security.
Innovation Solution
A system and method using collector code to collect and analyze self-timing data from user interactions, employing statistical methods to detect and categorize browsing session manipulations caused by privacy modes, malware, or aggregators, and send alerts to prevent false positives.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If behavioral biometrics is used to enhance authentication security, then authentication accuracy is improved, but the system becomes vulnerable to false positives when privacy modes or malware manipulate timing data
Solution Approach 1:
The patent introduces a detector module as an intermediary component that sits between the data collection system and the behavioral biometrics analysis system. This detector collects timing data from the browser environment and analyzes it for signs of manipulation (privacy modes, malware, aggregators) before the data is used for authentication decisions, thereby preventing false positives while maintaining security
Solution Approach 2:
The system implements feedback by continuously monitoring timing data characteristics and comparing them against established patterns. When manipulation is detected, the system provides feedback to adjust or block authentication attempts, creating a closed-loop system that adapts to manipulated conditions and prevents erroneous authentication decisions
2Object-affected harmful factors
If browser privacy mode is enabled to block trackers and mask identifiers, then user privacy is improved, but behavioral biometrics accuracy deteriorates due to manipulated timing data
Solution Approach 1:
The patent converts the harmful effect of privacy mode manipulation into a beneficial detection opportunity. By analyzing the specific timing patterns introduced by privacy modes (such as consistent delays or altered interaction rhythms), the system identifies these manipulations and adjusts authentication decisions accordingly, turning the privacy feature's side effect into a detectable signal for preventing false positives
3Measurement precision
If collector code continuously monitors timing data to detect manipulation, then detection accuracy is improved, but system complexity and data processing requirements increase
Solution Approach 1:
The patent segments the detection system into distinct functional modules: a data collection phase (capturing timing events), a detection phase (analyzing patterns for manipulation), and a response phase (blocking or adjusting authentication). This segmentation allows each module to be optimized independently and simplifies the overall architecture by dividing complex monitoring tasks into manageable functional units
Data Source
AI summary
The systems and methods are provided that can enable the detection of certain modes of online interactions carried out by a user's computing device, for example, when an online app or webpage of an enterprise is accessed by the user's computing device. Certain exemplary implementations may utilize collector code that resides in the app or webpage opened by users accessing the enterprise service to measure and collect timing data to detect whether the user's computing device or associated browsing session is subjected to modes of manipulation such as the user browser's privacy mode being engaged, malware interacting with the browsing session, and/or some type of aggregator interacting with the browsing session. Such modes of manipulation can impact the utility and accuracy of certain forms of behavioral biometric algorithms, particularly those that utilize users' typing, timing, keystroke dwell, etc.


