Dynamic Turing Test Generation for Cybersecurity Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer security systems are inadequate in preventing targeted cyber-attacks and automated evasion of public Turing tests, as they rely on static tests that can be studied and bypassed by malicious algorithms, failing to provide robust protection against unauthorized access and information security threats.

Innovation Solution

A system and method that assess the danger level of tasks performed on a computing device, generating dynamic automated tests based on threat levels, requiring user interaction to determine access rights, and continuously retrain models and adjust test rules to enhance security, thereby preventing unauthorized access and targeted cyber-attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If static public Turing tests are used to determine user authenticity, then the system can automatically block automated tasks, but the tests become vulnerable to automated algorithms that study and bypass them

Engineering Contradiction:
Improveautomated task blockingVSAvoidtest security
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent applies dynamics by transforming static Turing tests into dynamic, adaptive tests. The test content automatically changes based on detected task characteristics and user behavior patterns. Each test is uniquely generated according to the specific task being performed, making it impossible for automated algorithms to study and memorize test patterns. This dynamic adaptation resolves the contradiction by maintaining automated blocking capability while eliminating the vulnerability to automated bypasses.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes key parameters of the Turing test system: test content parameters are dynamically adjusted based on task type, user profile, and contextual information. Instead of using fixed test questions, the system varies test parameters (such as image manipulation complexity, text generation requirements, or pattern recognition difficulty) according to the specific security risk level of each task. This parameter transformation ensures that the same automated algorithm cannot pass multiple tests with different parameters.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If automated public Turing tests are used for security control, then unauthorized access can be blocked, but the tests can be passed by malicious algorithms designed to evade detection

Engineering Contradiction:
Improveunauthorized access blockingVSAvoidautomated evasion algorithms
Core Design Contradiction:
Object-affected harmful factorsVSObject-generated harmful factors

Solution Approach 1:

The patent implements feedback mechanisms where the system continuously monitors user interaction patterns, test performance, and behavioral characteristics. This feedback is used to adjust test difficulty and content in real-time. When automated algorithms attempt to pass tests, their characteristic rapid, pattern-based responses are detected through feedback analysis, causing the system to adapt the test accordingly. This feedback loop prevents automated evasion algorithms from succeeding while maintaining effective blocking of unauthorized access.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary action by performing security assessments and risk analyses before allowing tasks to execute. The system pre-evaluates task characteristics, user profiles, and contextual information to determine the appropriate security level and test requirements in advance. This preliminary action ensures that tests are designed specifically to counter anticipated evasion techniques before they can be applied, rather than reacting after attacks occur.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If user expertise is required for security correction, then targeted cyber-attacks can be detected, but the process becomes manual and time-consuming

Engineering Contradiction:
Improvecyber-attack detectionVSAvoidmanual security review time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies self-service by enabling the security system to automatically perform security corrections and adjustments without requiring manual user intervention. The system autonomously analyzes security risks, generates appropriate tests, adjusts access rights, and modifies task parameters based on detected threats. This self-service capability maintains high reliability in cyber-attack detection while eliminating the time-consuming manual review process, as the system handles security corrections automatically based on its risk assessment algorithms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3694176B1System and method for performing a task based on access rights determined from a danger level of the task
Publication Date: 2024.03.20 AO KASPERSKY LAB
  • EP3694176B1 patent drawingFigure 1
  • EP3694176B1 patent drawingFigure 2
  • EP3694176B1 patent drawingFigure 3

AI summary

Disclosed herein are systems and methods for performing a task on a computing device based on access rights determined from a danger level of the task. In one aspect, an exemplary method comprises gathering data characterizing the task for control of the computing device, determining a task danger level using a model for determining the task danger level based on the gathered data, wherein the task danger level characterizes a threat level of the task to an information security of the computing device if the task is performed, generating an automated test, wherein the automated test depends on the determined task danger level and is based on test generating rules, receiving a result of the automated test having being performed by the user, analyzing the received results, and determining access rights for the task in accordance with the analysis, and performing the task in accordance with the determined access rights.