Proxy Server Detection via Interaction Pattern Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures fail to effectively distinguish between legitimate human users and cyber-attackers accessing remote servers, particularly when proxy servers are used for indirect access, leading to potential unauthorized access and fraudulent activities.

Innovation Solution

A system and method that detect whether a user or electronic device is accessing a remote server directly or through a proxy server by analyzing user-specific characteristics, interaction patterns, and introducing intentional anomalies to elicit corrective actions, utilizing a combination of hardware and software components distributed across multiple devices, including client-server architecture and web-browser plugins, to determine the likelihood of a proxy server's presence and the authenticity of user interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If proxy servers are used for indirect access to remote servers, then user anonymity and access flexibility are improved, but security differentiation between legitimate users and cyber-attackers deteriorates

Engineering Contradiction:
Improveaccess flexibilityVSAvoidsecurity differentiation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary analysis of user interaction patterns, device characteristics, and behavior sequences before granting access or triggering security responses. By establishing baseline profiles of legitimate user behavior in advance, the system can differentiate between genuine users and attackers even when proxy servers mask their identities, thus maintaining security differentiation while allowing proxy-based access flexibility.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If advanced pattern recognition and anomaly analysis are implemented to detect proxy servers, then security accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The detection system is segmented into multiple independent analysis modules, each responsible for specific aspects such as interaction pattern analysis, device fingerprinting, behavior sequence validation, and anomaly detection. This modular segmentation allows the system to achieve high detection accuracy through comprehensive analysis while managing complexity by distributing functions across separate, specialized components that can be independently developed and maintained.

Inventive Principle:
Principle #1Segmentation

3Reliability

If user-specific characteristics and interaction patterns are analyzed, then authentication reliability is improved, but processing time increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements partial analysis by initially evaluating only the most discriminative and easily computable features such as device fingerprints and basic interaction patterns. For users exhibiting clearly legitimate or clearly malicious behavior, the analysis is stopped early, avoiding unnecessary processing time. Only when behavior falls into ambiguous zones does the system perform more comprehensive analysis of additional user-specific characteristics, thus balancing authentication reliability with processing efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11323451B2System, device, and method for detection of proxy server
Publication Date: 2022.05.03 BIOCATCH
  • US11323451B2 patent drawing
  • US11323451B2 patent drawing
  • US11323451B2 patent drawing

AI summary

Devices, systems, and methods of detecting whether an electronic device or computerized device or computer, is communicating with a computerized service or a trusted server directly and without an intermediary web-proxy, or indirectly by utilizing a proxy server or web-proxy. The system searches for particular characteristics or attributes, that characterize a proxy-based communication session or channel and that do not characterize a direct non-proxy-based communication session or channel; or conversely, the system searches for particular characteristics or attributes, that characterize a direct non-proxy-based communication session or channel and that do not characterize a proxy-based communication session or channel; and based on these characteristics, determines whether or not a proxy server exists and operates.