Fraud Detection via Cursor Biometric Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security measures fail to detect unauthorized access when user credentials are compromised, as they rely on emulable device characteristics and cannot differentiate between authorized and unauthorized users, especially in cases of physical or remote control of an authorized user's computer.
Innovation Solution
A method that correlates user behavior biometric data, such as cursor movement, with other data sources like log data to predict fraud, using machine learning models to analyze and generate results that cannot be easily emulated by fraudsters, and improves accuracy by generalizing patterns in small datasets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security measures compare device characteristics (IP address, device identifier) to historical records, then access control can be implemented, but unauthorized users can emulate these characteristics to evade detection
Solution Approach 1:
The patent replaces mechanical/emulable security characteristics (IP addresses, device identifiers) with behavioral biometric analysis of cursor movements. This substitution transforms the security mechanism from comparing static device properties to analyzing dynamic human behavior patterns that are difficult to emulate, thereby resolving the contradiction between reliability and emulation capability.
Solution Approach 2:
The patent changes the parameters used for security verification from device characteristics (IP address, MAC address) to behavioral parameters (cursor movement patterns, velocity, acceleration). This parameter change makes the security system resistant to emulation while maintaining reliable fraud detection, as behavioral patterns are intrinsic to the user rather than the device.
2Reliability
If conventional techniques restrict access based on device characteristics mismatch, then unauthorized access can be prevented in some cases, but legitimate users with modified devices or shared computers cannot access services
Solution Approach 1:
The patent replaces device-based authentication with behavior-based authentication. This allows legitimate users to access services from different devices or modified devices as long as their behavioral patterns match, while still preventing unauthorized access. The system focuses on the user's behavior rather than the device, resolving the contradiction between security and accessibility.
3Reliability
If behavior biometric analysis is performed alone, then fraud detection capability is improved, but prediction accuracy may be insufficient without additional data sources
Solution Approach 1:
The patent merges behavior biometric analysis with traditional log data analysis (IP address, device identifier) to create a comprehensive fraud detection system. This combination leverages the strengths of both approaches: behavioral patterns provide difficulty-to-emulate detection while log data provides additional verification layers, thereby improving prediction accuracy while maintaining fraud detection capability.
Solution Approach 2:
The patent creates a composite security assessment by combining multiple data sources (cursor movement data, log data, device characteristics). This composite approach integrates diverse information types to achieve higher prediction accuracy than any single data source could provide alone, while maintaining the unique advantage of behavioral biometric analysis.
Data Source
AI summary
One embodiment of the present invention sets forth a technique for predicting fraud by correlating user behavior biometric data with one or more other types of data. The technique includes receiving cursor movement data generated via a client device and analyzing the cursor movement data based on a model to generate a result. The model may be generated based on cursor movement data associated with a first group of one or more users. The technique further includes receiving log data generated via the client device and determining, based on the result and the log data, that a user of the client device is not a member of the first group.


