Screen Capture Interception for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security techniques fail to effectively detect and deceive malicious entities that capture screenshots to access private data from computing devices, as they struggle to identify and counter unauthorized access and data usage.
Innovation Solution
A system that intercepts requests for screen captures, determines if they are from authorized sources, and embeds deception data, such as fake credentials, into the responses to mislead attackers, using a deception component and content modification to provide modified screenshots with misleading information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional deception techniques are used to detect malware, then detection capability is improved, but device complexity and customization requirements increase
Solution Approach 1:
The patent implements a universal deception framework that works across different host systems without requiring scenario-specific customization. The system uses a standardized approach where fake credentials and deception data are injected into screen captures uniformly, eliminating the need for tailored changes per host scenario while maintaining effective malware detection
Solution Approach 2:
The system creates deceptive copies of legitimate screen capture content by embedding fake credentials and deception data into the visual output. Instead of modifying the host system or creating customized deception scenarios, the patent generates counterfeit screen content that mimics legitimate interfaces, allowing malware to interact with fake data while the real system remains protected
2Object-affected harmful factors
If screen capture interception is implemented to deceive attackers, then data protection is improved, but processing overhead increases
Solution Approach 1:
The patent extracts the deception function from the core screen capture process by implementing it as a separate overlay layer. The system captures the legitimate screen content, then selectively injects deception data only in the portions where fake credentials need to appear, rather than processing and modifying the entire screen capture. This extraction approach minimizes processing overhead while maintaining effective data protection
Solution Approach 2:
The deception data is injected locally into specific regions of the screen capture where fake credentials are needed, rather than uniformly processing the entire screen content. The system applies deception only to the necessary portions of the visual output, reducing overall processing requirements while maintaining effective protection against data theft
Data Source
AI summary
Multiple deception techniques utilized to mislead malicious entities that attempt to gather information associated with a computing device are implemented by changing a single result. In one aspect, requests for screen captures are intercepted and it is determined whether the requests are triggered due to user interaction (e.g., pressing a button and/or key) and/or received from an authorized application/device. If determined that the requests are not triggered due to user interaction and/or are received from an unauthorized application/device, a response comprising one of several pre-prepared or dynamically generated screen captures that are embedded (and/or appended) with misleading information (e.g., fake credentials, fake documents marked as important/hidden, etc.) is generated. Applications that attempt to utilize the misleading information can be flagged as malware.


