Fraud Detection via Cursor Biometric Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security measures fail to detect unauthorized access when user credentials are compromised, as they rely on emulable device characteristics and cannot differentiate between authorized and unauthorized users, especially in cases of physical or remote control of an authorized user's computer.

Innovation Solution

A method that correlates user behavior biometric data, such as cursor movement, with other data sources like log data to predict fraud, using machine learning models to analyze and generate results that cannot be easily emulated by fraudsters, and improves accuracy by generalizing patterns in small datasets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security measures compare device characteristics (IP address, device identifier) to historical records, then access control can be implemented, but unauthorized users can emulate these characteristics to evade detection

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidemulation capability of fraudsters
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces mechanical/emulable security characteristics (IP addresses, device identifiers) with behavioral biometric analysis of cursor movements. This substitution transforms the security mechanism from comparing static device properties to analyzing dynamic human behavior patterns that are difficult to emulate, thereby resolving the contradiction between reliability and emulation capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the parameters used for security verification from device characteristics (IP address, MAC address) to behavioral parameters (cursor movement patterns, velocity, acceleration). This parameter change makes the security system resistant to emulation while maintaining reliable fraud detection, as behavioral patterns are intrinsic to the user rather than the device.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If conventional techniques restrict access based on device characteristics mismatch, then unauthorized access can be prevented in some cases, but legitimate users with modified devices or shared computers cannot access services

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidlegitimate user access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces device-based authentication with behavior-based authentication. This allows legitimate users to access services from different devices or modified devices as long as their behavioral patterns match, while still preventing unauthorized access. The system focuses on the user's behavior rather than the device, resolving the contradiction between security and accessibility.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If behavior biometric analysis is performed alone, then fraud detection capability is improved, but prediction accuracy may be insufficient without additional data sources

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidprediction accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent merges behavior biometric analysis with traditional log data analysis (IP address, device identifier) to create a comprehensive fraud detection system. This combination leverages the strengths of both approaches: behavioral patterns provide difficulty-to-emulate detection while log data provides additional verification layers, thereby improving prediction accuracy while maintaining fraud detection capability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a composite security assessment by combining multiple data sources (cursor movement data, log data, device characteristics). This composite approach integrates diverse information types to achieve higher prediction accuracy than any single data source could provide alone, while maintaining the unique advantage of behavioral biometric analysis.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS11811805B1Detecting fraud by correlating user behavior biometrics with other data sources
Publication Date: 2023.11.07 CISCO TECHNOLOGY INC
  • US11811805B1 patent drawing
  • US11811805B1 patent drawing
  • US11811805B1 patent drawing

AI summary

One embodiment of the present invention sets forth a technique for predicting fraud by correlating user behavior biometric data with one or more other types of data. The technique includes receiving cursor movement data generated via a client device and analyzing the cursor movement data based on a model to generate a result. The model may be generated based on cursor movement data associated with a first group of one or more users. The technique further includes receiving log data generated via the client device and determining, based on the result and the log data, that a user of the client device is not a member of the first group.