Online Transaction Security via Virtualized Risk Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for securing online transactions are inadequate in addressing the risks of malware interception and user experience burden, as they often fail to detect new malware variants and can compromise user privacy, leading to unintended transactions and data exposure.
Innovation Solution
A system comprising a computing hardware with a processor, data storage, and input/output devices, including a network interface and graphical user interface, with an operating system and modules for detecting online transactions, applying protection to input sequences, assessing vulnerabilities, and adjusting protection levels based on risk, to ensure secure data transfer and user preferences.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing antivirus technologies (signature-based or heuristic checks) are used to detect malicious programs, then many known malware variants can be detected, but new malware variants deployed frequently cannot be determined
Solution Approach 1:
The system performs preliminary actions by proactively monitoring system state changes, file operations, and process behaviors before malware can execute harmful actions. Virtual machine technology creates a safe environment to pre-test and detect malware patterns, enabling the system to identify new variants before they can compromise the actual system.
Solution Approach 2:
The patent introduces virtual machine technology as an intermediary layer between the user system and malware. This virtual environment acts as a mediator that isolates malicious activities, allowing the system to analyze and detect new malware variants without directly exposing the host system to risks.
2Reliability
If protected input devices (keyboard encoding or virtual keyboard) are used to counter data interception, then data input security is improved, but the solution can be compromised by interceptors that capture data before encoding or through screenshotting
Solution Approach 1:
The patent introduces a protected input interface as an intermediary component that mediates between the physical input device and the application. This intermediary layer virtualizes the input process, capturing input data in a secure environment before it reaches the application, thereby preventing interception by malware running at the application level.
Solution Approach 2:
The solution moves the input protection mechanism from the application layer to a system-level virtualized environment. By adding this dimensional layer between hardware and software, the system creates a protected zone where input data can be securely captured and processed, making it inaccessible to traditional interception methods.
3Reliability
If multiple protection mechanisms are enabled simultaneously to ensure security, then transaction safety is improved, but computing resources are burdened and user experience is degraded
Solution Approach 1:
The patent merges multiple protection mechanisms into a unified virtualized security layer. Instead of running separate protection programs that each consume resources, the system consolidates malware detection, input protection, and transaction monitoring into an integrated virtual machine environment, reducing overall resource overhead while maintaining comprehensive security.
Solution Approach 2:
The virtualized security platform performs multiple security functions simultaneously - malware detection, input interception prevention, network traffic monitoring, and transaction verification - through a single integrated system. This multi-functional approach eliminates the need for multiple separate protection programs, optimizing resource utilization.
4Reliability
If comprehensive security monitoring is implemented to detect all malware activities, then security coverage is improved, but system performance and user experience are degraded
Solution Approach 1:
The system applies comprehensive security monitoring selectively to critical areas such as input devices, network transactions, and sensitive file operations, rather than uniformly across all system activities. This localized approach ensures high security coverage where needed while minimizing performance impact on routine operations.
Solution Approach 2:
The security monitoring operates periodically and event-driven rather than continuously. The system activates intensive monitoring when suspicious activities are detected or when high-risk operations occur, and reduces monitoring intensity during normal operations, thereby maintaining security coverage while optimizing system performance.
Data Source
AI summary
Online transaction security is improved by detecting a start of an online financial transaction between a user-controlled online transaction application and a remote payment service. A protected data input module, a protected environment module, and a safe data transfer module each provides a corresponding set of protection operations. A risk level of conducting the financial transaction is assessed based on a vulnerability assessment and on present condition of the local computing system. An initial degree of protection for each of the modules is set, and subsequently adjusted based on the risk level.


