Communications Security Interception Detection via User Behavior Profiling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data communication security measures fail to effectively detect fraudulent interceptions, such as phishing attacks and malware-induced session hijacking, which allow fraudsters to access secure facilities like online banking or shopping sites, by monitoring deviations from user behavior profiles.
Innovation Solution
A method and apparatus that monitor communications sessions to capture and analyze user behavior patterns over time, generating profiles to detect deviations indicative of interception, using an acquisition engine to capture data and an analytics engine to process and compare metrics for alert generation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security measures are used to protect communications sessions, then basic security is provided, but fraudulent interceptions cannot be detected
Solution Approach 1:
The system performs preliminary actions by monitoring communications sessions and generating user behavior profiles during normal operations. These profiles capture timing patterns, transaction types, and communication characteristics before any potential interception occurs, enabling later detection of deviations without adding complexity to the core security protocol
Solution Approach 2:
The system introduces an intermediary detection layer that operates in parallel to traditional security measures. This intermediary component analyzes communications sessions and compares actual behavior against established profiles, providing enhanced detection capability while maintaining independence from and compatibility with existing security infrastructure
2Measurement precision
If detailed monitoring of communications sessions is performed to detect interceptions, then detection accuracy improves, but processing time and computational resources increase
Solution Approach 1:
The system extracts only the most relevant and discriminating features from communications sessions for profile generation and comparison, such as timing intervals between messages, transaction type frequencies, and communication pattern characteristics. By focusing on these key features rather than analyzing every detail of each session, the system achieves high detection accuracy while minimizing processing time and computational overhead
3Reliability
If user behavior profiles are generated and monitored to detect deviations, then interception detection capability is enhanced, but data processing requirements increase
Solution Approach 1:
The system transforms raw communications data into standardized behavioral parameters and metrics that can be efficiently stored, compared, and analyzed. By converting diverse communication patterns into consistent parameter formats (such as timing distributions, transaction frequencies, and pattern match scores), the system enhances interception detection capability while improving data processing efficiency through standardized operations
Data Source
AI summary
A method is provided for detecting an interception of a communications session established by a user over a network, comprising the steps of: (i) monitoring communications sessions by the user over a profile time period to capture information identifying distinct communications to one or more identified network addresses and their timing over the profile time period; (ii) monitoring communications sessions within the profile time period to capture information characterising the content of transactions initiated in respect of said one or more network addresses; (iii) using the captured information to generate a profile characterising communications sessions established in respect of said one or more network addresses over the profile time period; and (iv) monitoring communications sessions with said one or more network addresses within a configurable detection time period to determine one or more measures of deviation from the profile generated at step (iii) thereby to detect the presence of an interception occurring within the detection time period.


