Cloud Security Service for Banking Hacking Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current banking systems lack effective means to detect hacking activities during user interactions, particularly in online and mobile banking, where vulnerabilities such as phishing and malicious software can compromise user authentication, making it difficult to identify and counter hacking attempts.
Innovation Solution
A cloud-based security service uses a trained semantic model to categorize web pages and analyze user interactions, identifying attributes like user actions, resource identifiers, and device information to detect hacking activities by comparing them with known hacking patterns, employing techniques like TF-IDF for word significance and lexeme analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If digital fingerprinting information is used to identify user devices, then device recognition capability is improved, but the ability to detect hacking activity remains insufficient because no counteracting means (such as antivirus modules) are installed on user devices
Solution Approach 1:
The patent introduces a cloud-based security service as an intermediary between the user's device and the banking server. This intermediary receives interaction data from the user's device, analyzes it for hacking patterns, and provides security decisions without requiring antivirus software to be installed on the user's device. The cloud service acts as a mediator that enables hacking detection while respecting the limitation that no counteracting means are present on the user's device.
Solution Approach 2:
The patent replaces the mechanical approach of installing antivirus software and security tools directly on user devices with a cloud-based analysis system. Instead of relying on local security mechanisms that are often absent or insufficient, the system substitutes a remote intelligence-based detection mechanism that analyzes interaction patterns through the cloud, eliminating the need for physical software installation on diverse user devices.
2Ease of operation
If users interact with banking services through browsers without specialized banking applications, then ease of operation is improved, but hacking detection capability deteriorates because banking applications contain additional security tools
Solution Approach 1:
The patent makes the cloud-based security service universal by deploying it across all browser-based banking interactions regardless of the specific bank or service provider. The system analyzes interaction data from any browser-based banking access point using the same security model, enabling consistent hacking detection across diverse banking interfaces without requiring bank-specific security tools or applications.
Solution Approach 2:
The cloud security service serves as an intermediary layer that bridges the gap between simple browser-based access and sophisticated security analysis. It receives interaction data from the browser, performs comprehensive hacking pattern analysis, and provides security decisions, thereby enabling secure detection despite the simplicity of the browser interface and the absence of specialized banking applications.
3Object-affected harmful factors
If phishing sites and malicious software are used by hackers, then hacking success rate is improved, but detection capability remains insufficient because traditional security measures cannot identify these activities
Solution Approach 1:
The patent applies preliminary action by analyzing interaction patterns before hacking activities can succeed. The system continuously monitors user interactions with banking services and compares them against known hacking patterns in real-time. By detecting suspicious behavior patterns early in the interaction sequence, the system can prevent hacking activities from completing before they cause damage, rather than reacting after harm has occurred.
Solution Approach 2:
The system implements feedback by continuously comparing observed interaction patterns against a database of known hacking activities and providing real-time security decisions. The cloud service receives interaction data, analyzes it against current hacking patterns, and provides feedback to the banking server about potential compromises. This feedback loop enables dynamic adaptation to evolving hacking techniques and maintains high detection capability despite the effectiveness of phishing and malicious software.
Data Source
AI summary
An example of a method for detecting hacking activities includes categorizing a plurality of web pages of a web site providing bank services using a trained semantic model. The trained semantic model uses at least one resource identifier of a web page as an input and generates a web page category as an output. One or more attributes of an interaction between a user and bank services are identified. The one or more identified attributes are analyzed by comparing the one or more identified attributes with attributes known to belong to hacking interactions based on a corresponding web page category. Hacking activity is identified based on the results of the analysis.


