Confirmation Interceptor for Networked Application Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for networked application client software lack assurance of explicit human consent for transactions, making them vulnerable to malicious usage and unauthorized access, as they cannot distinguish between human and automated inputs effectively.

Innovation Solution

A system and method that intercepts service requests and requires explicit human confirmation through dialogues, using techniques that are difficult for software to automate, ensuring that only legitimate user actions proceed with network-accessible services, thereby preventing malicious or unauthorized usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If human interactive proofs are used to gather human input with high assurance, then the reliability of detecting malicious usage is improved, but the complexity of implementing human confirmation in existing application workflows increases

Engineering Contradiction:
Improvedetection of malicious usageVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a confirmation agent as an intermediary component that sits between the networked application client software and the network services. This agent intercepts service requests, presents confirmation dialogues to users, and controls whether requests are allowed through. The confirmation agent implements human interactive proofs without requiring modifications to the core application workflows, thus improving detection reliability while managing implementation complexity through a dedicated intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network firewalls act as proxies for TCP connections to control service requests, then the security control is improved, but the user experience and ease of operation deteriorates due to frequent dialogues

Engineering Contradiction:
Improvesecurity controlVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The confirmation agent is designed to operate transparently in the background, automatically intercepting and managing service requests without requiring active user intervention for routine operations. It presents confirmation dialogues only when necessary, and uses techniques to make automation detection difficult, thereby maintaining security control while minimizing disruption to user experience. The system serves itself by handling most security checks autonomously.

Inventive Principle:
Principle #25Self-service

3Reliability

If dialogue techniques are used to notify users of software attempting to traverse the firewall, then the security awareness is improved, but the susceptibility to automated responses increases

Engineering Contradiction:
Improvesecurity awarenessVSAvoidautomated response susceptibility
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The confirmation agent employs techniques that change the parameters of the confirmation dialogue to make automation detection difficult. This includes using unpredictable confirmation patterns, timing variations, and other characteristics that are difficult for automated software to replicate. The system maintains security awareness through explicit user confirmation while reducing susceptibility to automated responses by making the confirmation process inherently resistant to automation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20130246517A1Method and system for containment of networked application client software by explicit human input
Publication Date: 2013.09.19 MCAFEE LLC
  • US20130246517A1 patent drawing
  • US20130246517A1 patent drawing
  • US20130246517A1 patent drawing

AI summary

Method and system for containing networked application client software in order to perform specified transactions only given explicit consent of a legitimate user. In one embodiment, a confirmation interceptor intercepts a service request message, queries the user of the request for a confirmation, and then either passes the service request message onto server application software or drops the request, depending on the user's confirmation response. In soliciting and processing the confirmation response, query is formulated so that the required response cannot be automatically generated by software that attempts to automate and simulate the user's actions.